Security Roundup: PAN-OS Zero-Day, RubyGems Supply Chain Attack, SHADOW-EARTH-053 Espionage — Week of May 14, 2026
Weekly briefing: PAN-OS auth portal buffer overflow (root RCE), RubyGems 500+ malicious packages, and SHADOW-EARTH-053 espionage.
An active week: a Palo Alto zero-day that was being exploited for a month before CISA stepped in, a coordinated supply chain attack that forced RubyGems to shut down new registrations, a fresh Ivanti EPMM RCE (their third this year), a newly disclosed Chinese espionage campaign targeting Asian governments and one NATO member, and a Linux kernel privilege escalation now confirmed in the wild. Here is the full picture.
Palo Alto PAN-OS CVE-2026-0300: Unauthenticated Root RCE (CVSS 9.3)
A buffer overflow in PAN-OS's User-ID Authentication Portal (Captive Portal) allows an unauthenticated attacker to execute arbitrary code as root on PA-Series and VM-Series firewalls. Exploitation requires only network access to the portal endpoint. Palo Alto confirmed active exploitation after unsuccessful attempts were observed as early as April 9 — a 27-day gap before CISA added it to KEV on May 6 with a federal remediation deadline of May 9.
Attackers send a specially crafted oversized payload to /php/login.php, overflowing the stack and injecting shellcode into an nginx worker process. Observed post-exploitation includes reverse shells and credential harvesting from the management plane. CVSS is 9.3 if the portal is exposed to the internet and 8.7 if restricted to trusted IPs — but neither score is safe without patching.
Patches released starting May 13: PAN-OS 10.1.14-h6, 10.2.11-h4, 11.0.6-h1, 11.1.5. If patching is not immediate, restrict or disable the Authentication Portal.
What to do
Upgrade to the relevant fixed PAN-OS version now. If patching must wait, restrict the User-ID Authentication Portal to trusted internal IP addresses only, or disable it if unused. Check for IOCs (known scanning IPs: 45.141.87.204, 91.92.243.115, 185.220.101.47). Monitor for shellcode injection indicators in nginx worker logs.
RubyGems Supply Chain Attack: 500+ Malicious Packages, Signups Suspended
RubyGems halted new account registration on May 8 after a coordinated attack pushed more than 500 malicious packages to the registry. Two distinct campaigns were active simultaneously. BufferZoneCorp uploaded sleeper packages that modify GitHub Actions workflows to exfiltrate CI secrets (GITHUB_TOKEN, AWS keys, NPM tokens) and add SSH persistence keys to runner hosts. A separate campaign named GemStuffer used 150+ gems as a data-exfiltration channel to scrape UK local government council portal pages and publish the data back to RubyGems via hardcoded API keys.
The BufferZoneCorp packages target developer environments: once installed, they inject an outbound curl call into existing .github/workflows/*.yml files that fires on every subsequent CI run, base64-encoding all environment variables and sending them to an attacker-controlled collection endpoint.
What to do
Run `bundle audit check --update` immediately. Review .github/workflows/ for injected steps (look for unexpected curl/wget/base64 combos). Rotate all CI secrets that may have been exposed. Check authorized_keys on CI runners for unknown SSH entries. Enable RubyGems MFA if you haven't already.
Ivanti EPMM CVE-2026-6973: RCE with Admin Access (CVSS 7.2)
Ivanti disclosed a third EPMM remote code execution vulnerability this year. CVE-2026-6973 — improper input validation in the device action API — allows an authenticated admin to execute arbitrary code on the EPMM server. CISA added it to KEV on May 7 with a May 10 federal deadline. Ivanti confirmed limited active exploitation, consistent with targeted nation-state actor activity that has characterised both prior EPMM RCEs (CVE-2026-1281, CVE-2026-1340).
The attack chain follows a now-familiar pattern: credential stuffing or lateral movement yields admin access to the EPMM portal, the attacker exploits the RCE to establish persistence on the MDM server, and from there can push malicious MDM profiles to every enrolled mobile device in the organization — an extremely high-impact pivot.
What to do
Update to EPMM 12.6.1.1, 12.7.0.1, or 12.8.0.1. Rotate all EPMM admin credentials immediately — especially if you were affected by the January 2026 EPMM vulnerabilities and did not rotate then. Restrict the EPMM admin portal to known IP ranges. Audit recent MDM configuration profile pushes for unauthorized changes.
SHADOW-EARTH-053: China APT Targeting Asian Governments and NATO Member
Researchers disclosed details of a sophisticated, multi-year China-nexus espionage campaign targeting government and defense sectors across South, East, and Southeast Asia, plus one European NATO-member government. The group (SHADOW-EARTH-053) gains initial access by exploiting N-day vulnerabilities in internet-facing Exchange and IIS servers, then deploys Godzilla web shells for persistent access. ShadowPad — China's most widely shared espionage backdoor — is staged via DLL sideloading of AnyDesk and other legitimate signed executables.
For C2 and lateral movement, the group uses a stack of legitimate tunneling tools: IOX, GOST (Go Simple Tunnel), and Wstunnel over WebSocket/TLS to blend with normal HTTPS traffic. Privilege escalation uses Mimikatz; lateral movement uses a custom C# SMBExec implementation (Sharp-SMBExec) that evades Impacket-based detections. Nearly half of SHADOW-EARTH-053's targets overlap with a related cluster, SHADOW-EARTH-054, indicating shared target lists between Chinese intelligence teams.
What to do
Patch Exchange and IIS immediately using Microsoft's ExchangeHealthChecker script. Hunt for Godzilla web shells (ASPX/PHP files in wwwroot containing eval/base64_decode). Validate DLL load order for AnyDesk and similar signed binaries. Enable Credential Guard to block Mimikatz pass-the-hash. Block outbound WebSocket connections to non-allowlisted destinations.
Linux LPE CVE-2026-31431: Root Access via Netfilter UAF (CVSS 7.8)
CISA added CVE-2026-31431 to KEV this week, confirming active exploitation of a use-after-free vulnerability in the Linux kernel's nf_tables netfilter subsystem. An unprivileged local user can exploit the UAF to overwrite kernel memory and escalate to root. Critically, the vulnerability is reachable from unprivileged user namespaces — the default on most modern Linux distributions — making container escape a real concern in cloud and Kubernetes environments where pods run as non-root but exploit a web application vulnerability for initial code execution.
Affected: Linux kernel 5.15 through 6.8.x. Patched in upstream 6.8.11, 6.6.32, 6.1.93, and 5.15.162, as well as in distribution updates for Ubuntu (USN-7089-1), Debian (DSA-5702-1), RHEL 8/9 (RHSA-2026:3441/3442), and Amazon Linux 2023 (ALAS-2026-2318).
What to do
Update your kernel and reboot. If immediate reboot is impossible, disable unprivileged user namespaces via sysctl: `sysctl -w kernel.unprivileged_userns_clone=0` — note this may affect some container workflows. Validate the workaround persists across reboots by adding it to /etc/sysctl.d/.
Deep Dives
Full technical breakdowns, attack chain walkthroughs, IOCs, and remediation commands for each story:
CVE-2026-0300: PAN-OS Unauthenticated RCE — Root Access via Authentication Portal Buffer Overflow
RubyGems Supply Chain Attack: BufferZoneCorp, GemStuffer, and 500+ Malicious Packages
CVE-2026-6973: Ivanti EPMM RCE — Admin-Level Access and MDM Infrastructure Compromise
CVE-2026-31431: Linux Kernel LPE — Root Access via Netfilter UAF, Active Exploitation Confirmed