Skip to content
All resources
Cybersecurity Intel · № 10 · 11 – 24 May 2026

When the defences are the target: security tools exploited, a supply-chain worm, and the patching gap

Two security products actively exploited in the same week. A self-replicating npm worm rips through GitHub and a major observability vendor. A municipal health system loses 1.8 million people's biometrics through a third party. And the DBIR confirms it: exploitation has overtaken stolen credentials as the number-one way in.

Published 25 May 2026 By Blacklight Threat Intelligence Classification TLP:CLEAR · Public
31%
Of breaches now start with vulnerability exploitation, the DBIR's first-ever #1 (Verizon DBIR 2026)
1.8M
People whose medical and biometric data was stolen via a health system's third party
26%
Of KEV vulnerabilities fully remediated by organisations in 2025, down from 38%
0
Zero-days in May's Patch Tuesday (120 flaws), the first clean month in ~2 years

Executive summary

  • The security stack itself was exploited. CISA confirmed in-the-wild exploitation of flaws in two endpoint-protection products in the same week, with hands-on-keyboard attackers chaining one to SYSTEM in live incidents.
  • Supply-chain compromise went wormable. A self-replicating npm worm stole CI/CD credentials and auto-published infected packages, cascading into source-code theft at GitHub (3,800 internal repositories) and a major observability vendor.
  • The data confirmed the shift. The Verizon DBIR 2026, published in-window, recorded vulnerability exploitation overtaking stolen credentials as the top breach entry point for the first time in 19 years, while KEV remediation rates fell to 26% and median patch time stretched to 43 days.

Key findings

20 – 21 May 2026 KEV · security tooling

Microsoft Defender and Trend Micro Apex One flaws actively exploited

CISA added two Microsoft Defender flaws (privilege escalation and denial of service) and a Trend Micro Apex One directory-traversal zero-day to KEV in the same week. Incident responders reported hands-on-keyboard actors abusing the Defender chain to reach SYSTEM in multiple live cases. When the endpoint protection layer is the exploited surface, defence needs telemetry the endpoint agent does not own.

16 – 21 May 2026 ATT&CK T1195.002

'Mini Shai-Hulud' npm worm cascades into GitHub and Grafana source-code theft

A self-replicating supply-chain worm seeded via a compromised npm package stole CI/CD credentials and used them to publish further infected packages automatically. Fallout confirmed in the window: 3,800 GitHub internal repositories compromised, and Grafana Labs' code downloaded via a stolen token, with the vendor publicly refusing the ransom demand.

18 May 2026 ATT&CK T1199

1.8 million people's medical records and biometrics stolen via a health system's third party

The largest US municipal health system confirmed attackers had months of access via an unnamed third-party vendor, copying diagnoses, billing data, identity documents, precise geolocation and fingerprint and palm-print biometrics, credentials that can never be reissued.

11 – 12 May 2026 Ransomware · OT-adjacent

Ransomware disrupts a critical injectable-medicine component maker

A supplier of stoppers, seals and syringe components for injectable drugs filed a material-incident disclosure after attackers stole data and encrypted systems, temporarily disrupting manufacturing and shipping across its global sites. Pharmaceutical supply chains inherit the cyber posture of their component makers.

20 May 2026 SaaS misconfiguration

Franchise-owner data leaked after a misconfigured Salesforce instance is mined

A global convenience-store chain confirmed criminals accessed franchisee documents, with the extortion crew claiming over 600,000 CRM records taken through a misconfigured customer-community instance found with an open-source auditing tool. When payment was refused, a 9.4 GB archive was published.

The broader pattern

  • Exploitation is now the front door, and the patching gap is the widest it has been. The DBIR's 43-day median patch time collides with KEV deadlines measured in days.
  • Your security tooling deserves its own threat model. Two exploited endpoint-protection products in one week means single-vendor visibility is a single point of failure.
  • Third parties carried the worst losses again. A vendor breach exposed biometrics; a package registry carried a worm into blue-chip engineering orgs. DBIR data shows third-party involvement in breaches up 60% year on year.

Sector lens

Healthcare
Biometric and clinical data lost through a vendor is unrecoverable in a way passwords are not. Vendor-risk reviews should explicitly cover which third parties hold biometrics and imaging.
Pharma & life sciences
The component-maker disruption shows drug supply chains fail at their least glamorous link. Map cyber exposure of critical suppliers, not just your own estate.
Retail & franchise
Franchisee and partner data in CRM communities is a soft target; misconfigured sharing settings are being scanned for with automated tooling.
Technology & software
If your CI/CD tokens can publish packages, a worm can too. Scope and rotate automation credentials, and monitor publish events like production changes.

Suggested priorities to consider

Based on this fortnight's public reporting, these are the areas we would review first. Weigh each against your own environment and risk profile.

01

Patch the exploited Defender and Apex One flaws and hunt for SYSTEM-escalation chains. Both are on KEV with federal deadlines; assume adversaries read the same list.

02

Rotate CI/CD and package-registry tokens; alert on unexpected publish events. The fortnight's worm spread on stolen automation credentials, not human logins.

03

Ask your critical vendors which third parties hold your regulated data. The biggest healthcare loss of the fortnight travelled through an unnamed vendor.

04

Scan your own SaaS communities and portals for misconfigured sharing. Attackers used an open-source auditor to find exposed CRM instances; run it before they do.

05

Benchmark your median patch time against the DBIR's 43 days, then halve it for KEV entries. Exploitation is now the #1 entry point; KEV-listed flaws are the priority queue.

These suggestions are general commentary based on publicly reported events, provided for information only. They are not tailored security advice and may not suit your environment; validate against your own risk assessment and change-control processes before acting.

How Blacklight handles this

Blacklight does not depend on the endpoint agent being trustworthy: it correlates identity, SaaS, network and cloud telemetry independently, so an exploited security tool, a token quietly publishing packages, or a vendor account touching data it never touches gets investigated on behaviour. KEV entries are matched to your estate the day they land, closing the gap the DBIR says attackers now walk through.

Book a Demo

Sources & methodology

Primary public sources this issue: Verizon Data Breach Investigations Report 2026 · CISA Known Exploited Vulnerabilities catalog and alerts (20 and 21 May 2026) · Microsoft May 2026 Patch Tuesday release notes · public disclosures and filings (West Pharmaceutical Services 8-K, Grafana Labs, NYC Health + Hospitals, 7-Eleven) · Help Net Security, The Record, TechCrunch, BleepingComputer and Krebs on Security reporting · MITRE ATT&CK v15 for technique mapping. Attacker-claimed figures are labelled as claims.

Methodology. Findings are compiled from public reporting and Blacklight Threat Intelligence monitoring for the stated window, mapped to MITRE ATT&CK where applicable. Aggregate platform observations, where cited, are anonymised across the Blacklight customer base and never identify a customer environment. Corrections: intel@blacklightai.com.

Related reading

Blacklight AI · Cybersecurity Intel · № 10 TLP:CLEAR
Get started

See what truly predictive
security looks like.

Sixty minutes, under your control. See the platform run on a pre-loaded, anonymised environment, watch one real incident handled end to end, and map it to your sector, without connecting a single data source.

A typical demo
  • 01 A live tour on a pre-loaded, anonymised environment, running from minute one, not slides.
  • 02 One real incident, detected, investigated and contained, written up as a regulator-ready report.
  • 03 Mapped to your world: your sources, your sector's threats and your regulators.
  • 04 The questions your board will ask: deployment, residency, security, integrations and TCO.

No connectors or data required from you. A proof-of-value on your own telemetry is the next step, never the ask on a first call.