securityaffairs.com 5/24/2026, 12:32:28 PM · external

Drupal SQL Injection Bug Exploited Live, Extortion Tactics Surge

Drupal SQL Injection Bug Exploited Live, Extortion Tactics Surge

Drupal SQL Injection Bug Exploited Live, Extortion Tactics Surge

The Security Affairs newsletter Round 578, authored by Pierluigi Paganini, highlights significant Cybersecurity incidents and threats. Key points include a critical SQL injection flaw in Drupal (CVE-2026-9082) currently under attack, the rise of pure extortion in cybercrime over traditional ransomware, and arrests related to the Kimwolf botnet. The…

First seen 2026-05-21T11:01:15.622Z · Last seen 2026-05-24T12:32:28.252Z

CyberSIXT Evidence Panel
Primary Source drupal.org
CISA KEV Listed in KEV
Patch Patch Status Unknown

THE Security Affairs newsletter Round 578, authored by Pierluigi Paganini, highlights significant Cybersecurity incidents and threats. Key points include a critical SQL injection flaw in Drupal (CVE-2026-9082) currently under attack, the rise of pure extortion in cybercrime over traditional ransomware, and arrests related to the Kimwolf botnet. The newsletter also discusses the U.S.

CISA's addition of vulnerabilities from Trend Micro and Microsoft to its catalog, various exploits affecting SonicWall and NGINX, and ongoing operations against cybercriminal infrastructures, notably in the MENA region. Overall, it underscores the evolving landscape of cybersecurity threats and the importance of timely updates and awareness.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline