Sustained Exploitation Activity and KEV Updates Marked This Week’s Threat Landscape
Executive Summary
Sustained Exploitation Activity and KEV Updates Marked This Week’s Threat Landscape
Executive Summary
The past week witnessed notable developments in the cybersecurity landscape, with increased exploitation activity and critical updates from security agencies and industry researchers. The Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including three impacting multiple products from Apple Inc., along with individual vulnerabilities affecting Langflow, Laravel, and Craft CMS. These additions reflected continued real-world exploitation across both enterprise platforms and modern development tools. In parallel, researchers reported a significant supply chain attack targeting Trivy, an open-so urce vulnerability scanner widely used in CI/CD pipelines, involving the exploitation of a vulnerability in Aqua Security’s Trivy, attributed to the threat group TeamPCP and first observed on March 19, 2026. Additionally, Google revealed that the DarkSword exploit chain was actively leveraged by multiple threat actors to compromise iOS devices across various regions through coordinated multi-vulnerability attacks.
1. Trending / Critical Vulnerabilities
This week’s threat landscape saw multiple vulnerabilities added to the CISA KEV catalog, highlighting active exploitation across AI platforms, web frameworks, and enterprise ecosystems. These included CVE-2026–33017 in Langflow, a code injection vulnerability enabling unauthenticated remote code execution via a publicly exposed API endpoint, and CVE-2025–54068 in Laravel Livewire, allowing server-side command execution through insecure deserialization of component data. Additionally, CVE-2025–32432 in Craft CMS exposed systems to unauthenticated code execution through improper input validation in image transformation functionality. Three vulnerabilities affecting multiple products from Apple Inc. CVE-2025–31277, CVE-2025–43510, and CVE-2025–43520 were identified as part of the DarkSword exploit chain, enabling memory corruption, sandbox escape, and kernel-level privilege escalation. Collectively, these developments highlighted continued attacker focus on code injection, memory corruption, and multi-stage exploitation techniques, reinforcing the urgency of rapid patching and strengthened security controls.
2. Exploit Activity and Mass Scanning Observed on Cytellite Sensors
Cytellite telemetry this week revealed sustained scanning and exploitation activity targeting network appliances, enterprise platforms, and internet-facing services, highlighting continued adversary focus on high-impact infrastructure. Confirmed in-the-wild exploitation included CVE-2025–31324 in SAP NetWeaver enabling unrestricted file upload, CVE-2024–4577 in PHP CGI allowing command injection and remote code execution, and CVE-2023–4966 in NetScaler ADC and Gateway exposing sensitive information. Additional exploited vulnerabilities included CVE-2024–47176 in CUPS and CVE-2024–3721 in TBK DVR devices, both enabling remote code execution, along with CVE-2023–38646 in Metabase and CVE-2023–26801 in LB-LINK routers. Further risks were identified in CVE-2024–8503 in VICIdial and CVE-2023–1020 in WP Live Chat Shoutbox involving SQL injection, and CVE-2023–49103 in ownCloud GraphAPI leading to sensitive data exposure. Collectively, these findings underscored continued attacker focus on command injection, file upload vulnerabilities, and access control weaknesses, reinforcing the need for timely patching and continuous monitoring.
3. Vulnerabilities Abused by Malware
This week’s threat intelligence highlighted large-scale supply chain compromise and sophisticated multi-stage exploitation campaigns impacting development ecosystems and end-user platforms. According to Sysdig, a widespread supply chain attack by TeamPCP targeted Trivy, exploiting CVE-2026–33634, an embedded malicious code vulnerability, to distribute backdoored components across CI/CD pipelines. The attackers leveraged compromised credentials to overwrite trusted GitHub Action tags and propagated malicious packages, deploying tools such as PCP InfoStealer and CanisterWorm to exfiltrate sensitive data and establish persistence across thousands of repositories. In parallel, Google disclosed the DarkSword exploit chain leveraged by threat actors UNC6748, PARS Defense, and UNC6353 to compromise iOS devices across multiple regions. The campaign utilized multiple vulnerabilities, including CVE-2025–31277, CVE-2026–20700, CVE-2025–43529, CVE-2025–14174, CVE-2025–43510, and CVE-2025–43520, to achieve full-chain exploitation spanning remote code execution, sandbox escape, and privilege escalation. Attackers deployed payloads such as GHOSTKNIFE, GHOSTSABER, and GHOSTBLADE through watering hole campaigns to enable data exfiltration, highlighting the increasing sophistication and coordination of modern threat actors.
4. OSS Trending vulnerabilities observed this week
This week’s open-source threat activity revealed multiple vulnerabilities across widely used development ecosystems, highlighting continued risks within software supply chains. Notable issues included CVE-2026–2256 in MS-Agent (PyPI), enabling command injection, and CVE-2026–25253 in OpenClaw WebSocket (npm), exposing token exfiltration risks. Additionally, CVE-2026–26118 in Azure MCP Server (NuGet) introduced server-side request forgery (SSRF) vulnerabilities, allowing attackers to manipulate outbound requests. Further vulnerabilities included CVE-2026–33001 in Jenkins (Maven), involving link-following issues that could lead to unauthorized access, and CVE-2024–32650 in rustls (crates.io), enabling denial-of-service conditions. Collectively, these vulnerabilities highlighted persistent weaknesses in input validation, credential handling, and request control across open-source ecosystems, reinforcing the need for continuous dependency monitoring and secure coding practices.
5. Pre-NVDs vulnerabilities observed this week
This week’s early vulnerability disclosures revealed multiple security issues across software applications and infrastructure tools, highlighting emerging risks in widely used technologies. Notable findings included CVE-2026–4150 in GIMP, enabling remote code execution, and CVE-2026–4385 in LiveHelperChat, exposing server-side request forgery (SSRF) risks. Additionally, CVE-2026–15518 in TP-Link Wireless Routers introduced command injection vulnerabilities, allowing attackers to execute arbitrary commands on affected devices. Further exposures included CVE-2026–33442 in Kysely, enabling SQL injection attacks, and CVE-2026–33481 in Syft, involving improper temporary file cleanup that could lead to security risks. Collectively, these disclosures emphasized persistent weaknesses in input validation, request handling, and execution control, reinforcing the need for proactive vulnerability management and secure development practices.
Conclusion
Overall, the week highlighted continued exploitation across widely used technologies, including Apple Inc., Laravel, Craft CMS, Langflow, and supply chain risks involving Trivy. These developments emphasized the need for real-time visibility and prioritization of actively exploited vulnerabilities beyond just patch availability. Organizations relying on delayed remediation remained exposed to evolving threats and coordinated attack campaigns. Leveraging platforms like Loginsoft Vulnerability Intelligence (LOVI) enabled proactive defense through timely intelligence, risk prioritization, and faster response.
For more details, check out the full report.
메타데이터
- post_id
- ffec96a8bcbb
- slug
- sustained-exploitation-activity-and-kev-updates-marked-this-weeks-threat-landscape-ffec96a8bcbb
- url
- https://medium.com/@Loginsoft/sustained-exploitation-activity-and-kev-updates-marked-this-weeks-threat-landscape-ffec96a8bcbb
- canonical_url
- https://medium.com/@Loginsoft/sustained-exploitation-activity-and-kev-updates-marked-this-weeks-threat-landscape-ffec96a8bcbb
- author_url
- https://medium.com/@Loginsoft
- status
- ok
- fetched_at
- 2026-06-20 20:29:01