May Threat Rundown
BLOG

May Threat Rundown: AI-Generated Zero-Days, Supply Chain Worms, and Mass Exploits

PUBLISHED JUN 3, 2026 BY Rubrik Zero Labs

Rubrik Zero Labs presents insights from late April through late May 2026, highlighting critical shifts in the cybersecurity landscape.

Major Stories of the Month

1. First Confirmed AI-Generated Zero-Day Exploit Discovered in the Wild

  • The Google Threat Intelligence Group confirmed the first instance of an AI-developed zero-day exploit deployed in the wild, marking a fundamental shift in automated vulnerability discovery and weaponization.
  • The exploit targeted an open-source web-based system administration tool, utilizing a semantic logic error to completely bypass two-factor authentication (2FA) enforcement.
  • Pro-Russian cybercrime actors attempted to use this AI-generated Python exploit in a planned mass exploitation campaign, demonstrating how attackers are actively using LLM-assisted analysis to compress exploit development timelines from weeks to hours.

2. Instructure/Canvas LMS Massive Breach Impacts 275 Million Users

  • Education technology giant Instructure, the creator of the Canvas learning management system, suffered a catastrophic data breach affecting 275 million students and staff across 9,000 institutions globally.
  • The threat actor ShinyHunters claimed responsibility for the 3.65TB data theft and mass extortion campaign, defacing school login portals with a strict ransom deadline.
  • The incident represents the largest educational data breach in history, ultimately ending when the threat actors reportedly reached an "agreement" (suspected ransom payment) with the vendor.

3. TeamPCP's "Shai-Hulud" Supply Chain Worm Compromises 640+ Packages

  • Threat actor TeamPCP expanded an unprecedented supply chain worm campaign by hijacking maintainer accounts via expired domains and stolen credentials to compromise over 640 npm and PyPI packages.
  • The attack infected massive foundational libraries, including the @antv visualization ecosystem (over 16 million weekly downloads) and Microsoft's durabletask PyPI package.
  • This industrialized malware targets Linux CI/CD environments to harvest highly sensitive cloud credentials from sources including GitHub Actions, AWS, Azure, GCP, Kubernetes, Vault and autonomously self-propagates by stealing tokens to infect newly detected repositories.

Top Ransomware Groups

Note: The ransomware ecosystem continues to consolidate around dominant groups. Threat actors this month heavily leveraged the "Fox Tempest" Malware-Signing-as-a-Service operation, which allowed groups to bypass Windows security controls using over 1,000 fraudulent code-signing certificates before it was disrupted by Microsoft and Europol.

  1. Qilin was the most prolific actor this period, with more than 26 confirmed victims across global healthcare, architecture, legal, and manufacturing sectors. The group exploited fraudulent certificates to distribute malware and consistently disrupt critical global operations and enterprise networks.
  2. The Gentlemen added nearly 20 new victims this month globally, implementing multi-platform lockers targeting Windows, Linux, NAS, BSD, and ESXi environments with advanced EDR evasion techniques.
  3. Nitrogen executed a highly disruptive attack against Foxconn's North American manufacturing facilities. It claimed the theft of 8TB of data spanning 11 million files, explicitly compromising sensitive project documents belonging to Apple, Nvidia, Google, Dell, and Intel.
  4. INC Ransom maintained high-volume aggressive targeting, prominently affecting the technology sector. It successfully exfiltrated 52GB of corporate data from Nothing Tech Taiwan and widely abused the Fox Tempest fraudulent signing certificates for initial access.
  5. VECT 2.0 is a critical impact ransomware targeting enterprise assets, VM disks, and backups across Windows, Linux, and ESXi platforms. Operating as an accidental data wiper due to a severe encryption implementation flaw, it permanently destroys files larger than 128KB making data recovery mathematically impossible even if the ransom is paid.

Linux / Cloud / Identity Attacks: Top Threats

These threats are prioritized based on their critical severity (CVSS scores), immediate widespread impact, and observed mass exploitation in enterprise environments.

1. Cisco SD-WAN Controller Authentication Bypass (CVE-2026-20182)

  • Type: Network Infrastructure / Identity
  • Impact: A critical authentication bypass vulnerability allowing unauthenticated remote attackers to easily escalate privileges to administrator-level access on Cisco Catalyst SD-WAN vManage and vSmart platforms.
  • CVSS 10.0 / Statistics: This flaw carries the maximum severity score and  active exploitation has been confirmed in the wild, prompting CISA to issue an Emergency Directive (26-03) mandating federal civilian agencies to immediately patch or disconnect systems. It is the sixth actively exploited Cisco SD-WAN vulnerability patched in 2026.

2. cPanel/WHM Authentication Bypass (CVE-2026-41940)

  • Type: Cloud Infrastructure / Web Management
  • Impact: An unauthenticated CRLF injection flaw allows attackers to manipulate session cookies, bypassing all authentication to gain complete root administrative access to cPanel and WHM web hosting control panels.
  • CVSS 9.8 / Statistics: Threat actors actively exploited this as a zero-day for 66 days before a patch was deployed. It has resulted in the mass compromise of over 40,000 servers globally, where attackers subsequently deployed "Sorry" ransomware. There are approximately 1.5 million exposed instances worldwide.

3. Linux "CopyFail" Privilege Escalation (CVE-2026-31431)

  • Type: Linux Operating System
  • Impact: This vulnerability exploits a page cache overwrite flaw in the AF_ALG crypto API, allowing any local user to deterministically achieve root access. It affects cloud instances, containers, and embedded systems.
  • CVSS Critical / Statistics: CopyFail affects all major Linux distributions (Ubuntu, Debian, Red Hat, Fedora, SUSE, Arch) shipped since 2017. Added to the CISA KEV catalog for active exploitation, a trivial 732-byte Python script is all that is required for complete local-to-root system compromise.

Insights from Rubrik Zero Labs LLM Powered Advanced Analysis Systems

Top Threats Inside Backups: Our advanced analysis systems identify top and trending threats seen in the wild and compare that data with backup telemetry to detect stealthy malware. In this section we present the data for this month.

Beyond the Front Line

The latest data shows 20.4% of prevalent threats are identified with high confidence as having bypassed front-line defenses. Behind that cohort stands a small set of named adversaries—each with a distinct catalogue of tooling—accounting for the activity that bypassed prevention layers and accumulated evidence in environments where successfully-contained threats do not leave a trail. Nearly three quarters (74.0%) of named campaigns tied to the bypass cohort carry adversary attribution. The footprint concentrates in Technology and Healthcare, but the tradecraft spans sectors, involving credential stealing, lateral movement, and defense evasion primitives.

Lazarus Group:

IndustryShare of cohort footprint
Healthcare50%
Media & Entertainment50%

 

Lazarus Group is a North Korean state-sponsored operator known for financially-motivated campaigns targeting cryptocurrency exchanges, financial institutions, and technology firms. The group operates under the TraderTraitor campaign banner. During this period, Lazarus deployed INVISIBLEFERRET, a cross-platform malware written in Python with capabilities spanning fingerprinting, command and control, and keylogging.

UNC6692:

UNC6692:
IndustryShare of cohort footprint
Professional services100%

 

UNC6692 is a financially-motivated operator known for campaigns targeting cloud infrastructure and supply-chain access. The actor has been observed leveraging browser-based persistence mechanisms to maintain access across session boundaries. During this period, the actor deployed SNOWBELT, a browser extension-based backdoor written in JavaScript that facilitates communication with Amazon Web Services S3 bucket-hosted command infrastructure. 

MuddyWater:

MuddyWater:
IndustryShare of cohort footprint
Cybersecurity100%

 

MuddyWater is an Iranian state-sponsored actor with a history of espionage operations targeting government, telecommunications, and defense sectors across the Middle East, Europe, and North America. The actor maintains a catalogue of custom backdoors designed for persistent access and lateral movement. This period, MuddyWater deployed two tools PROTONGLOW—also tracked as muddywater ulise, and ulise—is a C-based backdoor that provides remote control capabilities including file transfer and command execution. LIGHTPHOENIX  is a C++ backdoor capable of writing files and executing CMD commands.

MuddyWater impact by industry
<em>Sector composition of the high-confidence bypass cohort, shown as share of cohort-wide environment footprint</em>

Ransomware

Ransomware families made up 8.6% of identified threats this period, surfacing four distinct ransomware families across the dataset. Lockbit dominated the chart with around 60% overall concentration in this period. The Technology sector bore 78% of the period's ransomware footprint, a concentration reflecting both the sector's attack surface and the economic calculus of ransomware operators targeting environments where operational disruption translates to immediate revenue pressure. Media & Entertainment accounted for 10% of ransomware exposure, while environments without industry classification represented 7%

Ransomware activity by cohort alert
<em>Lockbit was the most active ransomware family during the period studied by Rubrik Zero Labs</em>

 

Sectors impacted by ransomware
<em>Technology led ransomware activity by sector</em>

Top Threats Analyzed/Flagged by Our Advanced Malware Analysis Systems

See the full hash list on GitHub

LATEST BLOGS