Three active exploitations hit our desks overnight. That's not normal. Let me frame where we are.
LiteSpeed cPanel plugin — CVE-2026-48172 — is a confirmed zero-day being exploited right now. Any authenticated cPanel user gets root through lsws.redisAble. On shared hosting, that's one compromised tenant owning the entire server. Millions of accounts sit on this infrastructure.
Drupal core SQLi — CVE-2026-9082 — just landed on the CISA KEV catalog with a May 27 remediation deadline. DefusedCyber is already seeing recon probes against /jsonapi/node/* endpoints. We're in the 48-72 hour window before this goes mass-exploitation.
And then CISA flagged two Microsoft Defender zero-days being actively exploited. Your security tool is the attack vector. Think about that for a second.
Those three demand the bulk of our airtime. But we also need to cover Ghostwriter's new campaign against Ukraine — fresh OYSTER malware family, Prometheus lures, multi-stage kill chain — and ShinyHunters claiming 42 million Charter Communications records with a May 27 deadline that's four days away.
On Ubiquiti — we covered this yesterday. There's a delta: CVE-34910 is a third CVSS 10.0, command injection. We'll do a quick firmware matrix update, not a full re-discussion.
Alex, Lena, James — I'm starting with you on the three active exploitations. Stand by.