EPISODE · May 14, 2026 · 29 MIN
2026-05-14: Microsoft patched 138 vulnerabilities including critical RCE flaws in DNS and Netlogon
from Cyber Threat Brief
Show Notes - 2026-05-14 Stories Covered: - May 14, 2026 - Today: - Windows BitLocker Zero-Day Bypasses Encryption (YellowKey) (https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/) - Windows Privilege Escalation Zero-Day (GreenPlasma) (https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/) - Critical Outlook Zero-Click RCE (CVE-2026-40361) (https://www.securityweek.com/microsoft-patches-critical-zero-click-outlook-vulnerability-threatening-enterprises/) - The Gentlemen RaaS Internal Database Leaked (https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/) - Foxconn Confirms Nitrogen Ransomware Attack (https://www.bleepingcomputer.com/news/security/electronics-giant-foxconn-confirms-cyberattack-on-north-american-factories/) - Device Code Phishing Campaigns Surge (https://www.proofpoint.com/us/blog/threat-insight/device-code-phishing-evolution-identity-takeover) - Iranian APT Targets South Korean Electronics Manufacturer (https://www.bleepingcomputer.com/news/security/iranian-hackers-targeted-major-south-korean-electronics-maker/) - China-Linked FamousSparrow Targets Azerbaijani Energy Sector (https://www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-apt-south-caucasus-energy-firm) - Microsoft May 2026 Patch Tuesday: 138 Vulnerabilities (https://thehackernews.com/2026/05/microsoft-patches-138-vulnerabilities.html) - Microsoft Fixes BitLocker Recovery Issue on Windows 11 Only (https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bitlocker-recovery-issue-only-for-windows-11-users/) - Fragnesia Linux Kernel Privilege Escalation (CVE-2026-46300) (https://www.bleepingcomputer.com/news/security/new-fragnesia-linux-flaw-lets-attackers-gain-root-privileges/) - Critical Exim Mail Server RCE (CVE-2026-45185) (https://www.bleepingcomputer.com/news/security/new-critical-exim-mailer-flaw-allows-remote-code-execution/) - Google Pixel 10 Zero-Click Exploit Chain (https://projectzero.google/2026/05/pixel-10-exploit.html) - RubyGems Abused as Data Dead Drop (https://www.darkreading.com/application-security/attackers-weaponize-rubygems-data-dead-drops) - Healthcare Lab Fined for Security Failures Before Cyberattack (https://databreaches.net/2026/05/13/nl-dutch-watchdog-says-healthcare-lab-failed-data-security-rules-before-cyberattack-affecting-850000/) - UK Regulator Fines Water Company for Cybersecurity Failures (https://databreaches.net/2026/05/13/uk-regulator-fines-water-company-almost-1m-for-cybersecurity-failures/) CVEs Referenced: CVE-2015-6172, CVE-2024-55591, CVE-2025-32433, CVE-2025-33073, CVE-2025-54957, CVE-2026-33109, CVE-2026-33825, CVE-2026-40361, CVE-2026-40402, CVE-2026-41089, CVE-2026-41096, CVE-2026-42826, CVE-2026-42898, CVE-2026-43284, CVE-2026-43500, CVE-2026-45185, CVE-2026-46300 Full brief: https://carolinacleartech.com/brief/2026-05-14/
Embed this episode
What this episode covers
Show Notes - 2026-05-14 Stories Covered: - May 14, 2026 - Today: - Windows BitLocker Zero-Day Bypasses Encryption (YellowKey) (https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/) - Windows Privilege Escalation Zero-Day (GreenPlas
NOW PLAYING
2026-05-14: Microsoft patched 138 vulnerabilities including critical RCE flaws in DNS and Netlogon
No transcript for this episode yet
Similar Episodes
No similar episodes found.