← Carolina Clear Tech

Cyber Threat Brief

2026-05-14

Listen to this brief (29:01)

Download MP3
Show Notes

Show Notes - 2026-05-14

Stories Covered

CVEs Referenced

CVE-2015-6172, CVE-2024-55591, CVE-2025-32433, CVE-2025-33073, CVE-2025-54957, CVE-2026-33109, CVE-2026-33825, CVE-2026-40361, CVE-2026-40402, CVE-2026-41089, CVE-2026-41096, CVE-2026-42826, CVE-2026-42898, CVE-2026-43284, CVE-2026-43500, CVE-2026-45185, CVE-2026-46300

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

May 14, 2026

Today: Microsoft patched 138 vulnerabilities including critical RCE flaws in DNS and Netlogon, but two Windows zero-days already have public exploits. YellowKey bypasses BitLocker encryption even on systems with TPM and PIN protection, while GreenPlasma escalates privileges to System level. The Gentlemen ransomware gang leaked internal data exposing their operations, affiliate model, and toolsets used against 332 victims this year.


Critical Alerts

Windows BitLocker Zero-Day Bypasses Encryption (YellowKey)

A publicly disclosed zero-day named YellowKey allows attackers with physical access to bypass BitLocker encryption on Windows 11 and Windows Server 2022/2025 systems. The vulnerability exploits a component present only in the Windows Recovery Environment (WinRE) that processes specially crafted FsTx files, triggering NTFS transaction replays that delete critical recovery files and spawn a command shell with access to encrypted volumes. Security researcher Chaotic Eclipse published proof-of-concept code demonstrating the attack, which works by placing malicious files on a USB drive or the EFI partition, rebooting into WinRE, and holding CTRL to spawn a shell. Multiple independent researchers including Kevin Beaumont and Will Dormann confirmed the exploit works on recent Windows 11 builds. The researcher claims the vulnerability also works on systems configured with TPM and PIN protection, but withheld that proof-of-concept code. This is tracked as CVE-2026-33825 and was added to CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of May 6. EPSS score is 0.049 (90th percentile).

Windows Privilege Escalation Zero-Day (GreenPlasma)

The same researcher disclosed a second zero-day named GreenPlasma that allows attackers to escalate privileges to System level on Windows systems. The vulnerability involves manipulating Windows services including kernel-mode drivers through arbitrary memory section object creation in directories writable by System. While the researcher published only a limited proof-of-concept that strips full System shell functionality, security researchers warn the code provides sufficient foundation for attackers to develop weaponized exploits. Full exploitation could enable attackers to disable endpoint protections, manipulate trusted processes, deploy malware with System privileges, or use compromised machines as pivot points for lateral movement across enterprise networks.

Critical Outlook Zero-Click RCE (CVE-2026-40361)

Microsoft patched a critical zero-click use-after-free vulnerability in Outlook that allows remote code execution without user interaction. The flaw resides in a DLL used heavily by both Word and Outlook, affecting Outlook's email rendering engine. Exploitation occurs automatically when a victim reads or previews a malicious email, requiring no clicks on links or attachments. Security researcher Haifei Li, who discovered the vulnerability, compared it to the 2015 BadWinmail vulnerability (CVE-2015-6172) that he previously dubbed an "enterprise killer" because it allowed anyone to compromise executives simply by sending an email. The attack perfectly bypasses enterprise firewalls and is delivered directly to the inbox. EPSS score is 0.001 (18th percentile), but Microsoft assigned an "exploitation more likely" rating.


Ransomware Claims (Last 48h)

No structured ransomware victim claims data available in today's collection.


Ransomware & Extortion

The Gentlemen RaaS Internal Database Leaked

The Gentlemen ransomware-as-a-service operation suffered a security breach that exposed internal communications, toolsets, and operational details after compromising approximately 332 organizations in the first five months of 2026. On May 4, the group's administrator acknowledged that an internal backend database had been leaked, with anonymous attackers now selling over 16GB of internal data for $10,000 in Bitcoin. The leaked material includes conversations between the RaaS administrator (zeta88, also known as hastalamuerte) and affiliates detailing initial access methods, division of roles, shared toolsets, and active tracking of CVEs including CVE-2024-55591 (CISA KEV, EPSS 0.941), CVE-2025-32433 (CISA KEV due June 30, EPSS 0.471), and CVE-2025-33073 (CISA KEV due November 10, EPSS 0.453). The leak reveals the group's generous affiliate payment model where zeta88 takes 10% and affiliates split the remaining 90%, explaining the operation's rapid growth to become the second most productive RaaS program in 2026. Internal chats show a successful negotiation where the group received $190,000 after demanding $250,000, and evidence of dual-pressure tactics where stolen data from a UK software consultancy was reused to attack a Turkish company.

Foxconn Confirms Nitrogen Ransomware Attack

Foxconn, the world's largest electronics manufacturer with over 900,000 employees and $260 billion in 2025 revenues, confirmed that some North American factories were hit by a cyberattack claimed by the Nitrogen ransomware gang. The threat actors claim to have stolen 8TB of data representing over 11 million documents, including confidential instructions, projects, and drawings from major customers including Apple, Intel, Google, Nvidia, and AMD. The company's cybersecurity team activated response mechanisms and implemented operational measures to ensure production continuity, with affected factories currently resuming normal operations. This marks the fourth major ransomware incident for Foxconn in recent years, following attacks by LockBit (January 2024 and May 2022) and DoppelPaymer (December 2020, which demanded $34 million after allegedly encrypting up to 1,400 servers).

Device Code Phishing Campaigns Surge

Credential phishing has evolved beyond traditional MFA bypass techniques to device code phishing, which exploded across the threat landscape following the release of criminal toolkits in fall 2025 and the emergence of multiple phishing-as-a-service offerings including EvilTokens and Tycoon. Proofpoint researchers report that most identified activity uses "vibe coded" techniques, with threat actors either copying and modifying publicly known tools or using similar LLM prompts to generate nearly identical attack flows. The attacks abuse the OAuth 2.0 device authorization grant flow to compromise Microsoft 365 accounts by tricking users into approving access for attacker-controlled applications. Current implementations generate codes dynamically when users click phishing links, solving the previous limitation of 15-minute code expiration windows. Campaigns frequently leverage account takeover jumping, where attackers compromise an initial email account and use it to send phishing links to a wide set of contacts. Successful attacks lead to full account takeover, sensitive data theft, business email compromise, lateral movement, and ransomware deployment.


Business & Infrastructure Threats

Iranian APT Targets South Korean Electronics Manufacturer

The Iran-linked MuddyWater threat group (also known as Seedworm, Static Kitten) conducted a cyber-espionage campaign that spent a week inside the network of a major South Korean electronics manufacturer in February 2026. The campaign targeted at least nine high-profile organizations across multiple sectors and countries, including government agencies, an international airport in the Middle East, industrial manufacturers in Asia, and educational institutions. Symantec researchers assess the attacker's motivation as intelligence-driven, focusing on industrial and intellectual property theft, government espionage, and access to downstream customers or corporate networks. The attack relied heavily on DLL sideloading using legitimate signed software including Foremedia's fmapp.exe audio utility and SentinelOne's sentinelmemoryscanner.exe. Malicious DLLs loaded ChromElevator, a commodity post-exploitation tool that steals data from Chrome-based browsers. PowerShell was still heavily used but controlled through Node.js loaders rather than directly. The attackers maintained 90-second beaconing intervals, leveraged sendit.sh for data exfiltration to blend with normal traffic, and stole credentials via fake Windows prompts, registry hive theft (SAM/SECURITY/SYSTEM), and Kerberos ticket abuse.

China-Linked FamousSparrow Targets Azerbaijani Energy Sector

The China-linked FamousSparrow APT group targeted an Azerbaijani oil and gas company in the South Caucasus region between late December 2025 and the end of February 2026, marking the first time China-aligned threat actors have been discovered in Azerbaijanian industries. Bitdefender researchers observed the group using a unique two-stage DLL sideloading technique that gates payloads behind specific execution paths, allowing malware to run only if applications follow expected instruction sequences. This makes analysis and sandbox detection more difficult, as individual components show no malicious behavior when examined separately. The attackers installed an improved version of the Deed RAT remote access tool. While operational technology (OT) networks were not affected, the targeting represents China-aligned APTs pushing into Russia's traditional sphere of influence. The South Caucasus region has become an increasingly important energy corridor for the European Union, serving 16 nations with gas exports that have grown 56% over the past five years.


Windows / AD Security

Microsoft May 2026 Patch Tuesday: 138 Vulnerabilities

Microsoft released patches for 138 security vulnerabilities spanning its product portfolio, with 30 rated Critical, 104 rated Important, three rated Moderate, and one rated Low severity. None of the vulnerabilities are listed as publicly known or under active attack at the time of release. The patches include 61 privilege escalation bugs, 32 remote code execution flaws, 15 information disclosure issues, 14 spoofing vulnerabilities, eight denial-of-service bugs, six security feature bypass issues, and two tampering flaws. Key Critical vulnerabilities include CVE-2026-41096 (CVSS 9.8), a heap-based buffer overflow in Windows DNS that allows unauthenticated remote code execution via specially crafted DNS responses; CVE-2026-41089 (CVSS 9.8), a stack-based buffer overflow in Windows Netlogon that allows unauthenticated RCE by sending a specially crafted network request to a domain controller; CVE-2026-42826 (CVSS 10.0), an information disclosure in Azure DevOps requiring no customer action; CVE-2026-33109 (CVSS 9.9), improper access control in Azure Managed Instance for Apache Cassandra; CVE-2026-42898 (CVSS 9.9), code injection in Microsoft Dynamics 365 on-premises; and CVE-2026-40402 (CVSS 9.3), a use-after-free in Windows Hyper-V allowing SYSTEM privilege escalation and access to the Hyper-V host environment.

Microsoft Fixes BitLocker Recovery Issue on Windows 11 Only

Microsoft addressed a known issue causing some Windows 11 systems to boot into BitLocker recovery after installing the April 2026 security updates (KB5083769). The issue affects systems with an "unrecommended" BitLocker Group Policy configuration, specifically those using the "Configure TPM platform validation profile for native UEFI firmware configurations" policy with invalid PCR7 (Platform Configuration Register 7) settings. Microsoft released a permanent fix only for Windows 11 25H2 via the KB5089549 cumulative update. Windows 10 and Windows Server customers must wait for a future update. Until fixes are available, Windows administrators should remove the problematic Group Policy configuration before deploying April 2026 updates and ensure BitLocker bindings use the PCR7 profile correctly. This marks the fifth significant BitLocker recovery issue since August 2022, following similar problems in August 2024 and May 2025 that required out-of-band emergency updates.


Vulnerability Disclosures

Fragnesia Linux Kernel Privilege Escalation (CVE-2026-46300)

Linux distributions are rolling out patches for a new high-severity kernel privilege escalation vulnerability named Fragnesia (CVE-2026-46300) that allows unprivileged local attackers to gain root privileges by writing arbitrary bytes to the kernel page cache of read-only files. The vulnerability stems from a logic bug in the Linux XFRM ESP-in-TCP subsystem and affects all Linux kernels released before May 13, 2026. Security researcher William Bowling of Zellic disclosed the flaw along with a proof-of-concept exploit that achieves a memory-write primitive in the kernel, used to corrupt the page cache memory of the /usr/bin/su binary to obtain a root shell. Fragnesia belongs to the Dirty Frag vulnerability class disclosed last week, which chains two separate kernel flaws (CVE-2026-43284 xfrm-ESP and CVE-2026-43500 RxRPC) to achieve privilege escalation. Unlike Dirty Frag's race condition requirements, Fragnesia abuses a logic bug without requiring any race condition, making exploitation more reliable.

Critical Exim Mail Server RCE (CVE-2026-45185)

A critical vulnerability in the Exim open-source mail transfer agent allows unauthenticated remote code execution on certain configurations using the default GNU Transport Layer Security (GnuTLS) library. CVE-2026-45185 is a use-after-free flaw triggered during TLS shutdown while handling BDAT chunked SMTP traffic. Exim frees a TLS transfer buffer but continues using stale callback references that write data into freed memory, leading to unauthenticated RCE. The vulnerability impacts Exim versions 4.97 through 4.99.2 on builds compiled with GnuTLS that have STARTTLS and CHUNKING advertised. OpenSSL-based builds are not affected. Attackers exploiting the vulnerability could execute commands on the server, access Exim data and emails, and potentially pivot into the environment. XBOW researcher Federico Kirschbaum discovered and reported the vulnerability on May 1, with a fix released in Exim version 4.99.3. XBOW documented an interesting development race where their autonomous AI system (XBOW Native) created a working exploit for a simplified target without ASLR, and an LLM-assisted human researcher won the race for a production target with ASLR enabled. EPSS score is 0.001 (18th percentile).

Google Pixel 10 Zero-Click Exploit Chain

Google Project Zero researchers published a zero-click root exploit chain for the Google Pixel 10, demonstrating it is possible to achieve root access on Android from a zero-click context using just two exploits. The chain updates a previous Pixel 9 exploit that used the Dolby zero-click vulnerability (CVE-2025-54957, patched January 2026) combined with a local privilege escalation in the BigWave driver. For Pixel 10, the researchers ported the Dolby exploit by updating offsets and adapting to RET PAC protections that replaced stack protector checks. However, the BigWave driver does not ship on Pixel 10. Working with Jann Horn, the researchers audited the new VPU driver at /dev/vpu used for the Chips and Media Wave677DV silicon on the Tensor G5 chip and discovered an exceptional vulnerability in just 2 hours. The VPU driver directly exposes the chip's hardware interface to userspace, including letting userspace map the chip's MMIO register interface. A flaw in the vpu_mmap handler allows unbounded physical memory mapping, enabling attackers to map the entire kernel image (including .text and .data regions) into userland and overwrite any kernel function to gain kernel code execution. EPSS score for CVE-2025-54957 is 0.000 (8th percentile).


General Security News

RubyGems Abused as Data Dead Drop

Security researchers at Socket discovered a campaign dubbed "GemStuffer" where threat actors published over 100 malicious packages to the RubyGems registry, abusing it as a data dead drop rather than for malware distribution. The packages contain scrapers targeting public-facing UK government servers in the Lambeth, Wandsworth, and Southwark districts of London, collecting council calendar pages, agenda listings, and committee links. Scraped data is embedded into .gem archives and pushed back to RubyGems using hardcoded API keys, with attackers later downloading packages to extract the data. No command-and-control infrastructure is needed. The packages received few or no downloads and contain payloads that are repetitive, noisy, and unusually self-contained. Some samples create temporary RubyGems credentials under /tmp, override HOME, build a gem locally, and push it to rubygems.org, while other variants skip the gem CLI and POST archives directly to the RubyGems API. The campaign coincided with an apparent coordinated spam-publishing campaign against RubyGems, though Socket did not directly link the two activities. The threat actor's motivation remains unclear, as the scrapers target public data and show worm potential without attempting to infect other systems or distribute malware.

Healthcare Lab Fined for Security Failures Before Cyberattack

The Dutch data protection watchdog ruled that healthcare research agency Bevolkingsonderzoek Nederland failed to meet data security requirements before a cyberattack in August 2025 that affected 850,000 women who underwent cervical cancer screening. The agency paid the Nova ransomware gang's initial ransom demand, which Nova confirmed receiving, but the criminals then demanded additional payment after learning the lab had contacted police. The regulatory finding establishes that organizations can face penalties not only for data breaches but also for inadequate security measures in place before attacks occur.

UK Regulator Fines Water Company for Cybersecurity Failures

The UK Information Commissioner's Office (ICO) fined utility company South Staffordshire Water £963,900 after a cyberattack that ran from September 2020 to July 2022, resulting in users' personal information being extracted and published on the dark web. The fine was issued on May 7, establishing a precedent for critical infrastructure operators failing to maintain adequate cybersecurity controls over extended periods.


Patch Priority


Trends & Context

Today's brief highlights a concerning trend of weaponized zero-day disclosures from adversarial researchers, with YellowKey and GreenPlasma joining recent Windows exploits that were publicly disclosed before patches were available. The researcher has explicitly threatened to continue releasing zero-days, indicating organizations should expect additional unpatched vulnerabilities on future Patch Tuesdays. Meanwhile, ransomware operations continue to demonstrate organizational maturity, with The Gentlemen's internal leak revealing sophisticated affiliate models, CVE tracking, and dual-pressure negotiation tactics that helped them become the second most productive RaaS program in 2026. The convergence of public exploit code, AI-assisted exploit development, and increasingly sophisticated ransomware operations is compressing the window between vulnerability disclosure and active exploitation to hours rather than weeks.