EPISODE · May 21, 2026 · 27 MIN
2026-05-21: Microsoft patched two actively exploited Defender zero-days that CISA added to KEV with a June 3
from Cyber Threat Brief
Show Notes - 2026-05-21 Stories Covered: - 2026-05-21 - Today: - Microsoft Defender Zero-Days (CVE-2026-41091, CVE-2026-45498) (https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/) - RaaS Ecosystem Tradecraft Analysis (https://www.huntress.com/blog/raas-ecosystem-ransomware-tradecraft) - Microsoft Disrupts Fox Tempest Malware-Signing Service (https://thehackernews.com/2026/05/microsoft-takes-down-malware-signing.html) - Mini Shai-Hulud npm Supply Chain Attack (https://www.microsoft.com/en-us/security/blog/2026/05/20/mini-shai-hulud-compromised-antv-npm-packages-enable-ci-cd-credential-theft/) - SonicWall VPN MFA Bypass via CVE-2024-12802 (https://www.bleepingcomputer.com/news/security/hackers-bypass-sonicwall-vpn-mfa-due-to-incomplete-patching/) - TamperedChef Trojanized Productivity Software (https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/) - Typosquatting Embedded in Third-Party Scripts (https://thehackernews.com/2026/05/typosquatting-is-no-longer-user-problem.html) - AI Coding Agents and Credential Leakage (https://www.securityweek.com/1password-teams-with-openai-to-stop-ai-coding-agents-from-leaking-credentials/) - CISA Exposed GitHub Repo with Secrets (https://www.theregister.com/security/2026/05/19/americas-top-cyber-defense-agency-left-a-github-repo-open-with-passwords-keys-tokens-and-incredibly-obvious-filenames/5242915) - 9-Year-Old Linux Kernel Privilege Escalation (CVE-2026-46333) (https://thehackernews.com/2026/05/9-year-old-linux-kernel-flaw-enables.html) - PinTheft Linux Privilege Escalation (Arch Linux) (https://www.bleepingcomputer.com/news/linux/exploit-released-for-new-pintheft-arch-linux-root-escalation-flaw/) - Identity and Device Security Integration (https://www.bleepingcomputer.com/news/security/identity-alone-isnt-enough-why-device-security-has-to-share-the-load/) - Supply Chain Vulnerability Crisis (https://www.securityweek.com/supply-chain-security-crisis-too-many-vulnerabilities-too-little-visibility/) - Drupal Core SQL Injection (CVE-2026-9082) (https://thehackernews.com/2026/05/highly-critical-drupal-core-flaw.html) - Memcached SASL Timing Side Channel (CVE-2026-47784) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47784) - DNS Software Vulnerabilities (Multiple CVEs) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32792) - Rsync Vulnerabilities (CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-29518, CVE-2026-45232) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43619) - GitHub CLI Terminal Escape Sequence Injection (CVE-2026-45803) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45803) - Cowboy SPDY Decompression Bomb (CVE-2026-43970) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43970) - WebSocket Uninitialized Memory Disclosure (CVE-2026-45736) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45736) CVEs Referenced: CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249, CVE-2010-0806, CVE-2024-12802, CVE-2026-29518, CVE-2026-32792, CVE-2026-33278, CVE-2026-40622, CVE-2026-41091, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42944, CVE-2026-42959, CVE-2026-42960, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-43970, CVE-2026-44390, CVE-2026-44608, CVE-2026-45232, CVE-2026-45498, CVE-2026-45736, CVE-2026-45803, CVE-2026-46333, CVE-2026-47784, CVE-2026-9082 Full brief: https://carolinacleartech.com/brief/2026-05-21/
Embed this episode
What this episode covers
Show Notes - 2026-05-21 Stories Covered: - 2026-05-21 - Today: - Microsoft Defender Zero-Days (CVE-2026-41091, CVE-2026-45498) (https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/) - RaaS Ecosystem Tradecraft Analysis (https://www.huntress.com/blog/raas-
NOW PLAYING
2026-05-21: Microsoft patched two actively exploited Defender zero-days that CISA added to KEV with a June 3
No transcript for this episode yet
Similar Episodes
No similar episodes found.