May 2026 Cyber Threat Analysis by Cynet

This material is based on Cynet’s report, “May 2026 Cyber Threat Intelligence Report: The Underworld Turns on Itself (Again),” which highlights the key cyber threats of May 2026. It covers ransomware activity, attacks on software supply chains, critical vulnerabilities, data breaches, and changes in the cybercriminal ecosystem. You can download the full version of the report via this link.

Last month, the trusted foundations of modern software — including package registries, source-code platforms, and open-source supply chains — became the environments attackers most aggressively tried to control. Supply-chain compromise was turned into a prize-driven game. A hacker group stole thousands of private GitHub repositories. A self-replicating worm was distributed free of charge. In an ironic turn, even one of the ransomware ecosystem’s seemingly most disciplined operations was breached. May 2026 centered on one dominant theme: the open-source ecosystem was becoming a playground for cybercrime, while defenders were forced to operate in a threat landscape where the rules continue to shift.

May at a Glance

The TeamPCP group launched an organized “Supply Chain Competition” on BreachForums. The group offered $1,000 in Monero to whoever could poison the most widely downloaded packages using Shai-Hulud. Scoring was based on download counts, effectively encouraging attacks against the most popular libraries. A few days later, the group compromised the device of a GitHub employee through a malicious VS Code extension. It then exfiltrated roughly 3,800 internal GitHub repositories and listed them for sale at more than $50,000.

Outside the supply chain, the Russian state-sponsored group Sandworm continued shifting its focus from IT networks toward critical operational technology. Data showed that defenders had 43 days of warning indicators before lateral movement began. On the vulnerability side, researchers disclosed Copy Fail (CVE-2026-31431), described as a severe Linux privilege-escalation flaw. CISA added it to the KEV catalog almost immediately. Ransomware reporting continued at a relentless pace, with 704 claimed victims during the month.

Ransomware Landscape Snapshot

Across all active ransomware groups, May brought a total of 704 claimed victims. The United States remained the most frequently targeted country, while Business Services became the most targeted sector. This marked a shift from previous months, when manufacturing had been a preferred target. Qilin led by a significant margin, while The Gentlemen ranked second. That position was especially notable because, by the end of the month, The Gentlemen would experience a highly public breach of its own, described in more detail below.

Top 10 Groups by Claimed Victims:
  • Qilin – 110
  • The Gentlemen – 77
  • DragonForce – 55
  • Akira – 31
  • IncRansom – 29
  • Nova – 25
  • FulcrumSec – 23
  • SafePay – 22
  • Genesis – 21
  • CmdOrganization – 16

Notable Incidents This Month

Foxconn Ransomware Attack.

The world’s largest electronics manufacturer confirmed a cyberattack that temporarily disrupted operations at several facilities in North America. The Nitrogen ransomware gang claimed responsibility. It stated that it had exfiltrated 8 terabytes of data from more than 11 million files, including confidential technical drawings and schematics connected to major customers such as Apple, Nvidia, Intel, and Google. Nitrogen has been active since 2023 and operates using leaked Conti 2 source code. The group is using the stolen data for double extortion.

Zara Data Breach.

Fashion retailer Zara experienced a breach that exposed the personal information of 197,400 customers. The exposed information included email addresses, geographic locations, purchase data, and customer support tickets. The breach was carried out by the ShinyHunters extortion group as part of a broader campaign. That campaign exploited compromised authentication tokens from the Anodot analytics platform to access cloud data belonging to multiple companies. ShinyHunters gave Inditex an April deadline to make contact and threatened to publish the data if no agreement was reached. After the deadline passed, the data was released. Inditex confirmed that the compromised databases did not include names, phone numbers, physical addresses, passwords, or payment information.

CISA Contractor Exposes AWS GovCloud Keys.

A Nightwing contractor maintained a public GitHub repository named “Private-CISA” for six months. The repository contained AWS GovCloud keys, plaintext passwords, and internal CISA credentials. A GitGuardian researcher discovered it on May 14. The repository included files describing how CISA internally builds, tests, and deploys software. The contractor had disabled GitHub’s default setting that prevents users from publishing SSH keys or other secrets in public repositories. After being notified, CISA took the repository offline. The agency stated that there is currently no evidence of active exploitation and noted that additional safeguards are being implemented. The exposed credentials reportedly remained valid for another 48 hours after the repository was removed.

The “fast16” Reveal.

A historical analysis brought “fast16” to light, a Lua-based malware strain from 2005 that predates Stuxnet. It was purpose-built to covertly interfere with nuclear weapons testing. The malware manipulated high-explosive detonation simulations and used more than 100 rules to remain functional after software updates. Fast16 represents the first known operation of its kind. Its discovery forces a reassessment of how long state-backed cyber sabotage against physical targets has been operational.

The underground turns on itself, again.

The Gentlemen, a rapidly growing RaaS group that appeared in the top 10 list of the most active threat actor groups throughout 2026, suffered a breach of its own backend in May. Internal chat logs, affiliate rosters, and negotiation records were dumped across underground forums for both rivals and defenders to analyze. The leak revealed an operation that was far smaller and more fragile than its reputation implied. It also showed that such groups are not immune to the same careless practices they attempt to exploit in others. In April, a similar scenario unfolded with Kybit and 0APT, as rival crews burned each other’s infrastructure and exposed each other’s secrets. Growing instability within cybercrime is becoming a defining feature of the threat landscape. Ego, money, and power are fracturing collectives that were already volatile and fragmented. For defenders, each of these feuds creates a rare intelligence windfall and a welcome dose of schadenfreude.

Critical Vulnerabilities Requiring Immediate Action

  • CVE-2026-0300: Palo Alto PAN-OS — Unauthenticated RCE with root privileges via the User-ID Authentication Portal. CVSS 9.8. Upgrade or restrict portal access.
  • CVE-2026-9082: Drupal — SQL injection affecting PostgreSQL-backed sites. CVSS 9.8. Update to the patched releases for Drupal 10/11.

Lessons Learned

May reinforced several themes that have continued to unfold throughout 2026. First, trust in the software supply chain is being actively monetized. Attackers are building economies around poisoning the packages and platforms that many organizations rely on. Second, “routine” alerts are not routine at all. Sandworm remained on compromised OT-adjacent systems that generated high-confidence alerts for an average of 43 days before lateral movement began. Third, the criminal underground is becoming increasingly unstable. When even a well-run RaaS operation can be exposed from the inside, it serves as a reminder that the same security hygiene failures exploited by attackers will eventually catch up with them as well.

This overview covers only part of the full picture. The complete May 2026 Cyber Threat Intelligence Report includes full incident analysis, all critical CVEs, the complete ransomware breakdown, in-depth technical analysis of Copy Fail and M3RX ransomware, and the inside story of The Gentlemen.

If you would like to test the Cynet XDR platform free of charge, please submit your contact details using the form below.

Get Cynet trial



    Subscribe to news