2026-05-21: Microsoft patched two actively exploited Defender zero-days that CISA added to KEV with a June 3 episode artwork

EPISODE · May 21, 2026 · 27 MIN

2026-05-21: Microsoft patched two actively exploited Defender zero-days that CISA added to KEV with a June 3

from Cyber Threat Brief

Show Notes - 2026-05-21 Stories Covered: - 2026-05-21 - Today: - Microsoft Defender Zero-Days (CVE-2026-41091, CVE-2026-45498) (https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/) - RaaS Ecosystem Tradecraft Analysis (https://www.huntress.com/blog/raas-ecosystem-ransomware-tradecraft) - Microsoft Disrupts Fox Tempest Malware-Signing Service (https://thehackernews.com/2026/05/microsoft-takes-down-malware-signing.html) - Mini Shai-Hulud npm Supply Chain Attack (https://www.microsoft.com/en-us/security/blog/2026/05/20/mini-shai-hulud-compromised-antv-npm-packages-enable-ci-cd-credential-theft/) - SonicWall VPN MFA Bypass via CVE-2024-12802 (https://www.bleepingcomputer.com/news/security/hackers-bypass-sonicwall-vpn-mfa-due-to-incomplete-patching/) - TamperedChef Trojanized Productivity Software (https://unit42.paloaltonetworks.com/tracking-tampered-chef-clusters/) - Typosquatting Embedded in Third-Party Scripts (https://thehackernews.com/2026/05/typosquatting-is-no-longer-user-problem.html) - AI Coding Agents and Credential Leakage (https://www.securityweek.com/1password-teams-with-openai-to-stop-ai-coding-agents-from-leaking-credentials/) - CISA Exposed GitHub Repo with Secrets (https://www.theregister.com/security/2026/05/19/americas-top-cyber-defense-agency-left-a-github-repo-open-with-passwords-keys-tokens-and-incredibly-obvious-filenames/5242915) - 9-Year-Old Linux Kernel Privilege Escalation (CVE-2026-46333) (https://thehackernews.com/2026/05/9-year-old-linux-kernel-flaw-enables.html) - PinTheft Linux Privilege Escalation (Arch Linux) (https://www.bleepingcomputer.com/news/linux/exploit-released-for-new-pintheft-arch-linux-root-escalation-flaw/) - Identity and Device Security Integration (https://www.bleepingcomputer.com/news/security/identity-alone-isnt-enough-why-device-security-has-to-share-the-load/) - Supply Chain Vulnerability Crisis (https://www.securityweek.com/supply-chain-security-crisis-too-many-vulnerabilities-too-little-visibility/) - Drupal Core SQL Injection (CVE-2026-9082) (https://thehackernews.com/2026/05/highly-critical-drupal-core-flaw.html) - Memcached SASL Timing Side Channel (CVE-2026-47784) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47784) - DNS Software Vulnerabilities (Multiple CVEs) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32792) - Rsync Vulnerabilities (CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-29518, CVE-2026-45232) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43619) - GitHub CLI Terminal Escape Sequence Injection (CVE-2026-45803) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45803) - Cowboy SPDY Decompression Bomb (CVE-2026-43970) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43970) - WebSocket Uninitialized Memory Disclosure (CVE-2026-45736) (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45736) CVEs Referenced: CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249, CVE-2010-0806, CVE-2024-12802, CVE-2026-29518, CVE-2026-32792, CVE-2026-33278, CVE-2026-40622, CVE-2026-41091, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42944, CVE-2026-42959, CVE-2026-42960, CVE-2026-43617, CVE-2026-43618, CVE-2026-43619, CVE-2026-43620, CVE-2026-43970, CVE-2026-44390, CVE-2026-44608, CVE-2026-45232, CVE-2026-45498, CVE-2026-45736, CVE-2026-45803, CVE-2026-46333, CVE-2026-47784, CVE-2026-9082 Full brief: https://carolinacleartech.com/brief/2026-05-21/

Episode metadata supplied by the publisher feed · Published May 21, 2026

Embed this episode

Show Notes - 2026-05-21 Stories Covered: - 2026-05-21 - Today: - Microsoft Defender Zero-Days (CVE-2026-41091, CVE-2026-45498) (https://www.securityweek.com/microsoft-patches-exploited-undefend-and-redsun-defender-zero-days/) - RaaS Ecosystem Tradecraft Analysis (https://www.huntress.com/blog/raas-

Distinct summary based on available episode metadata or transcript content.

NOW PLAYING

2026-05-21: Microsoft patched two actively exploited Defender zero-days that CISA added to KEV with a June 3

0:00 27:38

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Cyber Threat Brief?

This episode is 27 minutes long.

When was this Cyber Threat Brief episode published?

This episode was published on May 21, 2026.

Can I download this Cyber Threat Brief episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!