EPISODE · May 22, 2026 · 28 MIN
2026-05-22: Microsoft patched two actively exploited Defender zero-days with CISA deadline June 3
from Cyber Threat Brief
Show Notes - 2026-05-22 Stories Covered: - 2026-05-22 - Today: - Microsoft Defender Actively Exploited Zero-Days (CVE-2026-41091, CVE-2026-45498) (https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html) - Trend Micro Apex One Zero-Day Exploitation (CVE-2026-34926) (https://www.securityweek.com/trendai-patches-apex-one-zero-day-exploited-in-the-wild/) - Drupal Highly Critical SQL Injection (CVE-2026-9082) (https://www.securityweek.com/drupal-patches-highly-critical-vulnerability-exposing-websites-to-hacking/) - Langflow Code Execution Vulnerability Exploited by MuddyWater (CVE-2025-34291) (https://thehackernews.com/2026/05/cisa-adds-exploited-langflow-and-trend.html) - CISA Adds Legacy Microsoft Vulnerabilities to KEV (https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html) - The Gentlemen Ransomware Defense Evasion TTPs (https://www.huntress.com/blog/the-gentlemen-ransomware-defense-evasion-ttps) - First VPN Cybercrime Service Dismantled (https://www.bleepingcomputer.com/news/security/police-seize-first-vpn-service-used-in-ransomware-data-theft-attacks/) - Cloud Atlas APT Returns with New Tools and SSH Tunnels (https://securelist.com/cloud-atlas-2026/119895/) - GitHub Breached via Compromised VS Code Extension (https://news.risky.biz/risky-bulletin-microsoft-ends-sms-mfa-for-personal-accounts/) - Cross-Platform NPM Stealer Targets Windows, macOS, Linux (https://isc.sans.edu/diary/rss/33006) - ABB Industrial Control Systems Vulnerabilities (https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-03) - Hitachi Energy GMS600 OpenSSL Timing Attack (CVE-2022-4304) (https://www.cisa.gov/news-events/ics-advisories/icsa-26-141-01) - Microsoft Linux Kernel CVEs in MSRC Update Guide (https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26944) - Pwn2Own Berlin 2026: 47 Zero-Days Exploited (https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html) - Microsoft Ends SMS MFA for Personal Accounts (https://news.risky.biz/risky-bulletin-microsoft-ends-sms-mfa-for-personal-accounts/) - UK NCSC Issues Agentic AI Security Guidance (https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html) - Poland Urges Officials to Switch from Signal to mSzyfr (https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html) - Dutch Police Unmasked 74 Fraud Suspects via Game Over?! Campaign (https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html) - Trump Postpones AI Security Executive Order (https://cyberscoop.com/trump-postpones-executive-order-focused-on-ai-security/) - US-China Cyber Espionage Acknowledgment (https://thehackernews.com/2026/05/threatsday-bulletin-linux-rootkits.html) CVEs Referenced: CVE-2008-4250, CVE-2009-1537, CVE-2009-3459, CVE-2010-0249, CVE-2010-0806, CVE-2018-0802, CVE-2022-35737, CVE-2022-4304, CVE-2023-7104, CVE-2024-26944, CVE-2024-55591, CVE-2025-10504, CVE-2025-12142, CVE-2025-12143, CVE-2025-3277, CVE-2025-34291, CVE-2025-6965, CVE-2026-0968, CVE-2026-33825, CVE-2026-34926, CVE-2026-41091, CVE-2026-43303, CVE-2026-43331, CVE-2026-43465, CVE-2026-43494, CVE-2026-43495, CVE-2026-43496, CVE-2026-43497, CVE-2026-43499, CVE-2026-43501, CVE-2026-43502, CVE-2026-45498, CVE-2026-45584, CVE-2026-9082 Indicators of Compromise: Hashes: 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9 Full brief: https://carolinacleartech.com/brief/2026-05-22/
Embed this episode
What this episode covers
Show Notes - 2026-05-22 Stories Covered: - 2026-05-22 - Today: - Microsoft Defender Actively Exploited Zero-Days (CVE-2026-41091, CVE-2026-45498) (https://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html) - Trend Micro Apex One Zero-Day Exploitation (CVE-2026-34926) (https://www.secur
NOW PLAYING
2026-05-22: Microsoft patched two actively exploited Defender zero-days with CISA deadline June 3
No transcript for this episode yet
Similar Episodes
No similar episodes found.