What Business Owners Need to Know This Week
Week 23 (24–31 May 2026) was dominated by edge-device mass exploitation and confirmed SA breaches. Palo Alto’s PAN-OS GlobalProtect authentication bypass (CVE-2026-0257, CVSS 9.3) escalated from limited probing to confirmed mass exploitation, with Rapid7 MDR documenting two distinct attack waves — CISA added it to the KEV catalogue on 29 May with a 19 June deadline. Pick n Pay confirmed on 27–28 May that 2022-vintage customer data from the decommissioned Bottles platform is being trafficked on dark-web markets, triggering POPIA section 22 notification to the Information Regulator and SAPS. ESET published evidence that Webworm (China-aligned) infiltrated a South African university using Discord-based EchoCreep and Microsoft Graph-based GraphWorm backdoors — the first publicly documented China-APT compromise of a SA academic institution. Meanwhile the Exchange OWA (CVE-2026-42897) KEV deadline of 29 May passed with no permanent patch, and CISA added a supply chain triple (DAEMON Tools, @tanstack npm, Nx Console) in a single 27 May batch.
The Bottom Line: The flat ransomware count (111) again masks real escalation — a new RaaS group (0day Syndicate) launched its leak site and immediately listed an SA HR/logistics firm (XL Africa Group). W23 marks the first confirmed China-APT compromise of a SA academic institution and the first confirmed SA retail data disclosure of the period. The dominant operational threat is the PAN-OS GlobalProtect mass-exploit window: every SA organisation with a Palo Alto edge device must treat this as an active emergency — PAN-OS is deployed across SA banking, telco, and public sector edge infrastructure.
The Week in Numbers
- 111 cumulative SA ransomware victims — FLAT for the third consecutive week; no new ransomware.live listings in W23.
- 1 new leak site with an SA victim — 0day Syndicate debuted, listing XL Africa Group (HR/logistics).
- CVSS 9.3 — PAN-OS GlobalProtect CVE-2026-0257, now in confirmed mass exploitation; KEV deadline 19 June.
- 7 PAN-OS versions affected — 10.2, 11.0, 11.1, 11.2, 12.0, 12.1, and Prisma Access.
- 1 confirmed SA data breach — Pick n Pay/Bottles; IR and SAPS notified 28 May under POPIA s.22.
- First China-APT compromise of a SA academic institution — Webworm, confirmed by ESET 29 May.
- ~8 new CISA KEV entries including the 27 May supply chain triple (DAEMON Tools, @tanstack npm, Nx Console) — deadline 10 June.
- CVSS 10.0 — Oracle REST Data Services CVE-2026-46840 unauthenticated RCE, patched 28 May in Oracle’s inaugural monthly CSPU.
- 17+ targets — #OpSouthAfrica hacktivist campaign continues to expand against SA government systems.
Major Incidents: Who Was Hit and How
PAN-OS GlobalProtect — CVE-2026-0257 Moves to Mass Exploitation
Palo Alto’s authentication bypass vulnerability escalated from limited probing to confirmed mass exploitation across multiple SA-relevant managed-services customers. Rapid7 MDR documented two distinct attack waves originating from Vultr and Dromatics Systems hosting, with exploitation observed from 17 May. CISA added the CVE to the KEV catalogue on 29 May with a 19 June deadline. Affected versions: PAN-OS 10.2, 11.0, 11.1, 11.2, 12.0, 12.1, and Prisma Access. Patch to fixed versions immediately or disable the authentication override feature. SA relevance is CRITICAL — PAN-OS is deployed across SA banking, telco, and public sector edge infrastructure.
Pick n Pay / Bottles — Breach Confirmed, POPIA s.22 Triggered
Pick n Pay confirmed on 27–28 May that 2022-vintage customer data from the decommissioned Bottles delivery platform is being trafficked on dark-web markets. POPIA section 22 notification was triggered, with the Information Regulator and SAPS notified on 28 May. This is the first confirmed SA retail data disclosure of the period — customers of the legacy platform should treat phishing and account-takeover attempts referencing historical orders as an elevated risk.
Webworm (China APT) — First Confirmed Compromise of a SA University
ESET published evidence on 29 May confirming that Webworm (China-aligned) infiltrated an unnamed South African university using the Discord-based EchoCreep and Microsoft Graph-based GraphWorm backdoors, with data exfiltration to a compromised AWS S3 bucket. This is the first publicly documented China-APT compromise of a SA academic institution. Universities and research institutions should hunt for anomalous Discord and Microsoft Graph API traffic from server infrastructure.
Exchange OWA — KEV Deadline Passed With No Permanent Patch
The Exchange OWA CVE-2026-42897 (CVSS 8.1) KEV deadline of 29 May passed with no permanent patch available — only EEMS Mitigation ID M2 protects on-prem Exchange. The permanent fix is expected at Patch Tuesday on 9 June. Validate M2 is active on all Exchange 2016/2019/SE servers using the Exchange Health Checker, and pre-stage the 9 June change window.
Supply Chain Triple + Oracle ORDS CVSS 10.0
CISA added a supply chain triple in a single 27 May batch — DAEMON Tools, the @tanstack npm ecosystem, and Nx Console (VS Marketplace) — with a 10 June deadline. Oracle simultaneously released a fix for a CVSS 10.0 unauthenticated RCE in Oracle REST Data Services (CVE-2026-46840) in its inaugural monthly Critical Security Patch Update on 28 May. Development teams should audit dependency provenance and CI/CD tokens; database teams should apply the ORDS fix immediately.
POPIA and Regulatory
The Pick n Pay/Bottles confirmation is the week’s headline regulatory event — POPIA section 22 notification to the Information Regulator and SAPS was made on 28 May, putting legacy-platform data retention squarely in the compliance spotlight: decommissioned systems still holding customer data remain a POPIA liability. The #OpSouthAfrica hacktivist campaign expanded to 17+ SA government targets, adding to the public-sector notification burden. Key deadlines ahead: Trend Micro Apex One KEV remediation by 4 June, the supply chain triple by 10 June, and PAN-OS GlobalProtect by 19 June.
Full Intelligence Report
The complete Week 23 technical report covers the PAN-OS GlobalProtect exploitation timeline and IOC set, the Pick n Pay/Bottles disclosure analysis, the Webworm EchoCreep/GraphWorm campaign profile, Exchange OWA EEMS M2 validation guidance, the supply chain triple and Oracle ORDS advisories, the 0day Syndicate leak-site debut, and structured hunt missions with full IOC tables.
What Your Business Should Do Right Now
- PAN-OS GlobalProtect emergency patch: Audit all PAN-OS edge devices running versions 10.2, 11.0, 11.1, 11.2, 12.0, 12.1, or Prisma Access. Identify any use of the authentication override feature and deploy fixed versions immediately — mass exploitation has been confirmed since 17 May and the KEV deadline is 19 June. Hunt indicators from Vultr and Dromatics Systems source IPs. This is the single highest-priority action for any SA organisation with Palo Alto edge infrastructure.
- Hold Exchange OWA M2 mitigation and prepare for Patch Tuesday 9 June: Validate EEMS Mitigation ID M2 is active on all on-prem Exchange 2016/2019/SE servers (run Exchange Health Checker). The 29 May KEV deadline has passed with no permanent patch. Pre-stage the 9 June change window where the permanent fix is expected.
- Patch Trend Micro Apex One before 4 June: KEV-listed 26 May (CVSS 8.4). Directory traversal in the on-prem Apex One server lets an admin-credentialed attacker poison the AV update channel — endpoint protection becomes endpoint compromise. Patch the management server, verify update-channel signing integrity, and audit recent agent updates for anomalies.
- Audit the supply chain triple (deadline 10 June): Check developer workstations for DAEMON Tools, audit package-lock files for compromised @tanstack npm versions, and review Nx Console installs from the VS Marketplace. Rotate any CI/CD tokens that touched affected registries.
- Apply the Oracle ORDS fix (CVE-2026-46840, CVSS 10.0): Unauthenticated RCE in Oracle REST Data Services, patched 28 May. Any internet-reachable ORDS instance should be patched immediately and reviewed for signs of prior compromise.
- Universities: hunt Webworm IOCs: Look for anomalous Discord traffic (EchoCreep C2) and unexpected Microsoft Graph API activity (GraphWorm) from server infrastructure, plus outbound transfers to unfamiliar AWS S3 buckets.