Cyber Threat Brief
SHOW NOTES - 2026-05-20 STORIES COVERED * May 20, 2026 * Today: * YellowKey BitLocker Bypass (CVE-2026-45585) [Critical Alerts] * Action: [https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday] [Critical Alerts] * Drupal Core Security Release Tonight [Critical Alerts] * Action: [https://thehackernews.com/2026/05/drupal-to-release-urgent-core-security.html] [Critical Alerts] * CISA Credentials Exposed in Public GitHub Repository [Critical Alerts] * Action: [https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo/] [Critical Alerts] * GreenPlasma Windows Privilege Escalation [Windows / AD Security] * Action: [https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday] [Windows / AD Security] * MiniPlasma: Six-Year-Old Vulnerability Still Exploitable [Windows / AD Security] * Action: [https://www.darkreading.com/cyberattacks-data-breaches/windows-zero-day-barrage-continues-after-patch-tuesday] [Windows / AD Security] * Microsoft Teams macOS Location Prompt Issue [Windows / AD Security] * Action: [https://www.bleepingcomputer.com/news/microsoft/microsoft-blames-undismissible-teams-location-prompts-on-macos-update/] [Windows / AD Security] * ABB CoreSense Path Traversal (CVE-2025-3465) [Vulnerability Disclosures] * Action: [https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-06] [Vulnerability Disclosures] * Kieback & Peter DDC Building Controllers XSS (CVE-2026-4293) [Vulnerability Disclosures] * Action: [https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-05] [Vulnerability Disclosures] * ZKTeco CCTV Cameras Authentication Bypass (CVE-2026-8598) [Vulnerability Disclosures] * Action: [https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-04] [Vulnerability Disclosures] * ExifTool macOS Vulnerability (CVE-2026-3102) [Vulnerability Disclosures] * Action: [https://securelist.com/exiftool-compromise-mac/119866/] [Vulnerability Disclosures] * Microsoft CVE Disclosures [Vulnerability Disclosures] * Action: [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-43493] [Vulnerability Disclosures] * Sophos Firewall Update Bricking Devices [Business & Infrastructure Threats] * Action: [https://www.bleepingcomputer.com/news/security/sophos-pulls-buggy-firewall-update-bricking-devices-with-boot-loop/] [Business & Infrastructure Threats] * PAN-OS GlobalProtect Portal Command Injection (CVE-2026-47612) [Business & Infrastructure Threats] * Action: [https://www.bleepingcomputer.com/news/security/palo-alto-networks-warns-of-pan-os-globalprotect-portal-bug/] [Business & Infrastructure Threats] * Ivanti Endpoint Manager Mobile (EPMM) Critical Vulnerabilities [Business & Infrastructure Threats] * Action: [https://www.bleepingcomputer.com/news/security/ivanti-fixes-new-critical-endpoint-manager-mobile-flaws/] [Business & Infrastructure Threats] * Adobe ColdFusion Patches Critical Pre-Auth RCE [Business & Infrastructure Threats] * Action: [https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-coldfusion-rce-flaw-exploited-in-the-wild/] [Business & Infrastructure Threats] * AI Vulnerability Discovery Accelerates [https://www.recordedfuture.com/blog/ai-vulnerability-playbook] [General Security News] * SentinelOne Announces Prompt Security for Agentic AI [https://www.sentinelone.com/blog/prompt-security-for-agentic-ai/] [General Security News] * Ransomware Tracker API Disruptions [General Security News] CVES REFERENCED CVE-2020-17103, CVE-2025-3465, CVE-2026-3102, CVE-2026-4293, CVE-2026-43491, CVE-2026-43492, CVE-2026-43493, CVE-2026-45585, CVE-2026-47612, CVE-2026-8598 INDICATORS OF COMPROMISE IP Addresses: 1.4.1.12 Read the full brief [https://carolinacleartech.com/brief/2026-05-20/]
90 episodios
Comentarios
0Sé la primera persona en comentar
¡Regístrate ahora y únete a la comunidad de Cyber Threat Brief!