Skip to content
Cisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more… – SWN #581

Cisco, Canvas, Microsoft, Exchange 0-Days, NPM Backdoors, GPT-5.5 and more… – SWN #581

Scworld May 15, 2026

Cisco Catalyst, Canvas, Exchange 0-Days, BitLocker Bypass, Mini Shai Hulud, Node IPC, Patch Tuesday, GPT-5.5, Supply Chain Attacks, and More on the Security Weekly News

A max-severity authentication bypass (CVE-2026-20182) lets unauthenticated attackers gain admin on Cisco Catalyst SD-WAN Controllers. CISA added it to the KEV catalog this week. Patch now — exploitation is in the wild.

ShinyHunters defaced the Canvas LMS login page with a ransom demand, claiming 275M records across roughly 9,000 schools and universities. Instructure took the platform offline mid-semester, disrupting finals nationwide.

An XSS flaw in on-prem Exchange is being weaponized by simply sending crafted email; arbitrary JavaScript executes inside Outlook Web Access for any recipient who opens the message. On-prem Exchange admins should patch immediately and audit OWA sessions.

An anonymous researcher dropped two unpatched Windows zero-days: YellowKey bypasses BitLocker via the Recovery Environment (effectively a backdoor on encrypted drives), and GreenPlasma escalates privileges through CTFMON. No fix in this month's Patch Tuesday.

Two OpenAI employee laptops were compromised through a malicious TanStack package update — the latest in the Shai-Hulud-family npm attacks. Limited internal credentials were exposed; no production systems or user data were touched. Reinforces that dev workstations are now front-line targets.

Three poisoned versions of the popular npm package node-ipc contain obfuscated stealer/backdoor code that fingerprints hosts, walks the filesystem, and exfiltrates developer tokens, cloud keys, and browser data across 90 secret categories. Pin versions and audit lockfiles.

Microsoft shipped fixes for 118 vulnerabilities including 16 critical, and for the first time in nearly two years issued no out-of-band emergency zero-day patches. Krebs notes AI-assisted vulnerability discovery is now flagging issues across vendors at scale.

A missing-authentication flaw in the PraisonAI agent framework drew exploitation attempts within four hours of public disclosure, giving attackers unauthenticated access to protected API endpoints. Time-to-exploit on AI infrastructure is now effectively zero.

TeamPCP's full offensive framework — the same code family behind a wave of npm supply-chain compromises — was briefly published on GitHub before takedown, and a code-teardown is now circulating. Defenders gain rare visibility into TTPs, but proliferation risk to copycats is high.

The UK AI Security Institute concluded that publicly available GPT-5.5, and even smaller open models, match a frontier closed model on vulnerability discovery benchmarks. Schneier's takeaway: the offense-defense gap is no longer gated by access to a single lab's top model — the implications run from code into tax law and any rule-bound system.