How attackers turn new CVEs into working exploits ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
Zero Trust Weekly

This week in Zero Trust

Reduce opportunity before attackers exploit it

Estimated reading time: 4–5 minutes

 

In this issue:

  • How attackers use patches to figure out how vulnerabilities work
  • What happens after a pipeline is compromised?
  • How to spot and prevent phishing attacks
  • Threats: Malicious npm package poses as bug-bounty; cPanel flaw lets hosting account take full server control
View in browser

Manage preferences

From the CEO

The basics matter more than ever

 

"The FBI is out with a report that says we should not let AI security concerns distract from using basic cybersecurity hygiene. I agree, and it's a conversation I've had with many customers over the last few months. The basics matter more than ever. It doesn't matter if malware was created by a person or AI, it executes the same, and allowlisting stops both." - Danny Jenkins

From the ThreatLocker blog

 

The patching window is also the attack window

When a vulnerability is disclosed, defenders are not the only ones paying attention.

 

Weaponization of a CVE often follows a recognizable pattern. Attackers monitor new disclosures, compare vulnerable and patched code, and attempt to reproduce flaws before organizations can finish patching. In some cases, the patch itself can provide clues about how the vulnerability works.

 

Patching is essential, but it can't be relied upon alone. 

How to close the gap before patching

CI/CD pipelines: What are attackers really after?

How compromising one pipeline can open multiple paths to sensitive systems

 

CI/CD pipelines connect source code, build systems, credentials, cloud infrastructure, and production environments, making pipelines a valuable target for attackers. A compromised pipeline can expose deployment credentials and source code or provide a path into production.

 

From there, attackers may be able to modify code, inject malware into builds, distribute compromised packages downstream, or establish persistence.

Zero Trust tips for securing CI/CD pipelines

Phishing remains the leading initial access vector

And AI is giving attackers more ways to make it work

 

Phishing is so much more than emails. Attackers now use malicious QR codes, text messages, SEO poisoning, and deepfake voices and videos to trick users. Despite years of awareness training and expensive security tooling, phishing remains effective because it targets people rather than software vulnerabilities.

 

Defenders can't eliminate every phishing attempt, making prevention and containment critical. 

How you can plan for the click
ThreatLocker Webinars

Debunking the cybersecurity myths that leave you exposed

Sept. 29, 11 a.m. EDT 

  • Why MFA alone can't stop credential theft

  • Where EDR and patching leave security gaps
  • Which "best practices" deserve a second look
Save your seat

Privilege escalation: The attack path most security tools overlook

Oct. 27, 11 a.m. EDT 

  • How attackers use horizontal and vertical escalation to expand access

  • Why application-level elevation is safer than persistent admin rights
  • How time-bound elevation can limit privilege abuse
Save your seat

Threats you need to know

 

Malicious npm package poses as Twilio bug-bounty probe

The package was first published in August with 11 versions published in quick succession

  • What's happening: Researchers discovered a malicious npm package, tw-pkgprobe-7731, posing as an authorized Twilio bug-bounty research tool. Certain versions targeted Twilio developer environments, collected system information and environment variables, and could exfiltrate Twilio account SIDs and authentication tokens, potentially giving attackers access to victim accounts.

  • What defenders need to know: Organizations should scrutinize third-party packages before use, restrict access to secrets and environment variables, and rotate credentials if a potentially malicious package has been executed.

cPanel fixes three newly disclosed vulnerabilities

A hosting account could be enough to escalate to root

  • What's happening: cPanel disclosed CVE-2026-87899 which allows an authenticated hosting account to execute code as root and potentially take full control of a shared server. They disclosed two additional flaws affecting the WP Toolkit and WHM version 120 or later that could allow users to modify databases belonging to other accounts or access other users’ calendar and contact data. cPanel has released fixes for all three vulnerabilities.

  • What defenders need to know: Organizations using cPanel should update cPanel & WHM and WP Toolkit to patched versions as soon as possible. Because the most severe flaw only requires access to a hosting account, a compromised customer credential could potentially become a path to root-level control of the entire server. 

Meet ThreatLocker near you next week

 

Dublin · Orlando · London · Denver · Manchester · Vancouver

See all upcoming events
ThreatLocker: Zero Trust Platform | Zero Trust Weekly

ThreatLocker, 1901 Summit Tower Blvd, Orlando, Florida 32810, United States

Manage preferences

Connect with us

                             

©2026 ThreatLocker Inc., All Rights Reserved