EPISODE · May 20, 2026 · 19 MIN
2026-05-20: Microsoft faces a sixth zero-day disclosure in six weeks as researcher "Nightmare Eclipse" releases
from Cyber Threat Brief
Show Notes - 2026-05-20 Stories Covered: - May 20, 2026 - Today: - YellowKey BitLocker Bypass (CVE-2026-45585) - Action: (https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday) - Drupal Core Security Release Tonight - Action: (https://thehackernews.com/2026/05/drupal-to-release-urgent-core-security.html) - CISA Credentials Exposed in Public GitHub Repository - Action: (https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo/) - GreenPlasma Windows Privilege Escalation - Action: (https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday) - MiniPlasma: Six-Year-Old Vulnerability Still Exploitable - Action: (https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday) - Microsoft Teams macOS Location Prompt Issue - Action: (https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-undismissible-teams-location-prompts-on-macos-update/) - ABB CoreSense Path Traversal (CVE-2025-3465) - Action: (https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-06) - Kieback & Peter DDC Building Controllers XSS (CVE-2026-4293) - Action: (https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-05) - ZKTeco CCTV Cameras Authentication Bypass (CVE-2026-8598) - Action: (https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-04) - ExifTool macOS Vulnerability (CVE-2026-3102) - Action: (https://securelist.com/exiftool-compromise-mac/119866/) - Microsoft CVE Disclosures - Action: (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43493) - Sophos Firewall Update Bricking Devices - Action: (https://www.bleepingcomputer.com/news/security/sophos-pulls-buggy-firewall-update-bricking-devices-with-boot-loop/) - PAN-OS GlobalProtect Portal Command Injection (CVE-2026-47612) - Action: (https://www.bleepingcomputer.com/news/security/palo-alto-networks-warns-of-pan-os-globalprotect-portal-bug/) - Ivanti Endpoint Manager Mobile (EPMM) Critical Vulnerabilities - Action: (https://www.bleepingcomputer.com/news/security/ivanti-fixes-new-critical-endpoint-manager-mobile-flaws/) - Adobe ColdFusion Patches Critical Pre-Auth RCE - Action: (https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-coldfusion-rce-flaw-exploited-in-the-wild/) - AI Vulnerability Discovery Accelerates (https://www.recordedfuture.com/blog/ai-vulnerability-playbook) - SentinelOne Announces Prompt Security for Agentic AI (https://www.sentinelone.com/blog/prompt-security-for-agentic-ai/) - Ransomware Tracker API Disruptions CVEs Referenced: CVE-2020-17103, CVE-2025-3465, CVE-2026-3102, CVE-2026-4293, CVE-2026-43491, CVE-2026-43492, CVE-2026-43493, CVE-2026-45585, CVE-2026-47612, CVE-2026-8598 Indicators of Compromise: IPs: 1.4.1.12 Full brief: https://carolinacleartech.com/brief/2026-05-20/
Embed this episode
What this episode covers
Show Notes - 2026-05-20 Stories Covered: - May 20, 2026 - Today: - YellowKey BitLocker Bypass (CVE-2026-45585) - Action: (https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday) - Drupal Core Security Release Tonight - Action: (https://thehacke
NOW PLAYING
2026-05-20: Microsoft faces a sixth zero-day disclosure in six weeks as researcher "Nightmare Eclipse" releases
No transcript for this episode yet
Similar Episodes
No similar episodes found.