Security Roundup: Megalodon GitHub Attack, Ghost CMS Exploitation, MiniPlasma & YellowKey Windows 0-Days, DirtyDecrypt LPE — Week of May 28, 2026

Weekly briefing: Megalodon backdoors 5,500 GitHub repos, Ghost CMS SQLi hijacks 700 sites for ClickFix, and MiniPlasma Windows 0-day.

Security Roundup: Megalodon GitHub Attack, Ghost CMS Exploitation, MiniPlasma & YellowKey Windows 0-Days, DirtyDecrypt LPE — Week of May 28, 2026

A week dominated by supply chain attacks and local privilege escalation primitives: an automated campaign compromised over 5,500 GitHub repositories in six hours using infostealer-sourced credentials; Ghost CMS's SQL injection flaw has now been weaponised against 700+ live sites; two new Windows zero-days leave fully-patched machines exposed to SYSTEM takeover and BitLocker bypass; and a fourth Linux kernel page cache write primitive joins the Copy Fail family with a public PoC.


Megalodon GitHub CI/CD Supply Chain Attack — 5,561 Repos Backdoored in 6 Hours

On May 18, the automated Megalodon campaign pushed 5,718 malicious commits to 5,561 GitHub repositories in six hours using throwaway accounts with forged CI author identities (build-bot, auto-ci, ci-bot, pipeline-bot). Each commit injected a Base64-encoded bash payload into GitHub Actions workflows. If merged, the workflow executes in CI runners and exfiltrates AWS/GCP/Azure credentials, SSH keys, OIDC tokens, GITHUB_TOKENs, Vault tokens, Terraform creds, and over 30 secret pattern matches to a C2 at 216.126.225[.]129:8443.

Hudson Rock confirmed on May 23 that the attack was exclusively sourced from infostealer-compromised developer credentials — over 33% of affected accounts directly matched known infostealer logs. npm responded by burning all bypass-2FA write tokens platform-wide and urging adoption of Trusted Publishing.

What to do: Rotate all GitHub PATs and CI secrets for any repos that received unreviewed commits around May 18. Audit .github/workflows/ for unexpected files. Block the C2 IP. Enforce mandatory reviewer approval on workflow file changes.

→ Deep Dive: Megalodon — Attack Chain, IOCs, and CI/CD Hardening


CVE-2026-26980: Ghost CMS SQL Injection Exploited at Scale for ClickFix Attacks

CVE-2026-26980 (CVSS 9.4) is an unauthenticated SQL injection in Ghost CMS's Content API, patched in version 6.19.1 in February 2026. Attackers began exploiting it on May 7 and by May 25 had compromised over 700 websites — including universities, blockchain companies, and security research firms. The attack flow: exploit the Content API to extract the Admin API key, then use the Admin API to bulk-inject a JavaScript loader into every article. The loader fingerprints visitors and serves real targets a fake CAPTCHA page that triggers a ClickFix attack leading to malware installation.

IOCs: clo4shara[.]xyz (payload C2), web-telegram[.]ug (persistence C2). The vulnerability was originally discovered by Anthropic's Claude Mythos AI system.

What to do: Upgrade to Ghost 6.19.1 immediately. Rotate all API keys. Audit published posts for injected <script> tags. Notify users who may have visited your site during the compromise window.

→ Deep Dive: CVE-2026-26980 — Ghost CMS Attack Chain, IOCs, and Remediation


MiniPlasma Windows 0-Day — SYSTEM Shell on Fully-Patched Windows 11, No Patch Available

Researcher Chaotic Eclipse released a weaponised PoC called MiniPlasma (May 18) exploiting a race condition in cldflt.sys (Cloud Files Mini Filter Driver) — specifically in the HsmOsBlockPlaceholderAccess routine. The original flaw was reported to Microsoft by Google Project Zero in 2020 and was supposedly fixed via CVE-2020-17103, but the underlying issue was never actually remediated. The exploit reliably spawns a cmd.exe with SYSTEM privileges on Windows 11 running the May 2026 Patch Tuesday update. No CVE is currently assigned to this variant, and there is no patch.

What to do: If Cloud Files / OneDrive Files On-Demand is not required, disable cldflt.sys: sc stop cldflt && sc config cldflt start= disabled. Monitor for SYSTEM-level process spawns from non-elevated user sessions (Event ID 4688).

→ Deep Dive: MiniPlasma — cldflt.sys Race Condition and SYSTEM Escalation Analysis


CVE-2026-45585 (YellowKey) — BitLocker Bypass via USB + WinRE, Physical Access Only

CVE-2026-45585 (CVSS 6.8), dubbed YellowKey by researcher Chaotic Eclipse, bypasses BitLocker Device Encryption using only a USB drive and brief physical access — no credentials, software installation, or network access required. The attack places crafted FsTx files on a USB drive, which autofstx.exe in the Windows Recovery Environment processes via the BootExecute registry key. Cross-volume TxF transaction replay deletes winpeshl.ini, allowing the attacker to spawn an unrestricted shell with full access to the decrypted volume by holding CTRL during boot.

Microsoft released a mitigation on May 20. A May 22 LevelBlue analysis confirmed YellowKey chains naturally with MiniPlasma for a complete physical-access-to-SYSTEM attack path.

Affected: Windows 11 (24H2, 25H2, 26H1) and Windows Server 2025. Mitigation: Remove autofstx.exe from WinRE BootExecute; switch BitLocker from TPM-only to TPM+PIN.

→ Deep Dive: CVE-2026-45585 YellowKey — BitLocker Bypass Mechanics and Mitigation Steps


DirtyDecrypt PoC (CVE-2026-31635) — Linux Kernel LPE via rxgk Missing COW Guard

CVE-2026-31635 (CVSS 7.5), dubbed DirtyDecrypt, is a local privilege escalation in the Linux kernel's rxgk_decrypt_skb() function. A missing copy-on-write guard allows an attacker to write decrypted data directly to shared page cache memory, enabling modification of privileged files (/etc/shadow, /etc/sudoers, SUID binaries) to achieve root access. A public PoC has been released by Zellic and V12 Security.

The vulnerability only affects kernels compiled with CONFIG_RXGK=y — meaning Fedora, Arch Linux, and openSUSE Tumbleweed. Ubuntu, Debian, and RHEL-based distributions are not affected. DirtyDecrypt is the fourth member of the 2026 Linux page cache write primitive family alongside Copy Fail (CVE-2026-31431), Dirty Frag, and Fragnesia.

What to do: Apply kernel updates. If patches aren't yet available: echo "install rxgk /bin/true" >> /etc/modprobe.d/disable-rxgk.conf && update-initramfs -u

→ Deep Dive: CVE-2026-31635 DirtyDecrypt — rxgk COW Guard Bypass and Root Escalation


Deep Dives

Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther