CVE-2024-4367, CVE-2024-54017, CVE-2025-12659, CVE-2025-22871, CVE-2025-40833, CVE-2025-40949, CVE-2025-48804, CVE-2026-20122, CVE-2026-20127, CVE-2026-20128, CVE-2026-20133, CVE-2026-20182, CVE-2026-25786, CVE-2026-25787, CVE-2026-25789, CVE-2026-27446, CVE-2026-33825, CVE-2026-33862, CVE-2026-33893, CVE-2026-40175, CVE-2026-41551, CVE-2026-42010, CVE-2026-42011, CVE-2026-42304, CVE-2026-42897, CVE-2026-44411, CVE-2026-44412, CVE-2026-46300
Get tomorrow's brief in your inbox
Today: Cisco SD-WAN faces its sixth exploited zero-day of 2026 with CVE-2026-20182 granting attackers administrative access. Windows 11 BitLocker completely defeated by a zero-day exploit requiring only a USB drive and physical access. Microsoft Exchange servers under active attack via CVE-2026-42897, a spoofing flaw exploitable through malicious emails.
Cisco Catalyst SD-WAN Controller Authentication Bypass (CVE-2026-20182)
Cisco SD-WAN Controller and Manager contain a critical authentication bypass vulnerability (CVSS 10.0) actively exploited in zero-day attacks. The flaw allows unauthenticated remote attackers to gain administrative privileges by exploiting a broken peering authentication mechanism. Threat actor UAT-8616 exploited this flaw in May 2026, using the access to add SSH keys, modify NETCONF configurations, and escalate to root privileges. This is the sixth SD-WAN zero-day exploited in 2026. CVE-2026-20182 was discovered by Rapid7 during analysis of CVE-2026-20127, a similar authentication bypass previously exploited by the same actor. CISA added CVE-2026-20182 to KEV with a May 17, 2026 remediation deadline. CISA KEV due 2026-05-17.
Windows Zero-Day BitLocker Bypass (YellowKey)
A zero-day exploit named YellowKey completely defeats default Windows 11 BitLocker protections using a custom-crafted FsTx folder on a USB drive. The exploit requires physical access but works reliably within seconds. An attacker copies a specially crafted FsTx directory to a USB drive, boots the target Windows 11 or Windows Server 2022/2025 system into Windows Recovery Environment while holding CTRL, and receives a command prompt with full access to the encrypted drive. BitLocker recovery keys are bypassed entirely. TPM+PIN configurations do not mitigate the issue. The flaw involves Transactional NTFS, where a System Volume Information\FsTx directory on one volume can modify contents of another volume when replayed. Security researcher Will Dormann confirmed exploitation. The researcher (Nightmare-Eclipse) released the exploit publicly after dissatisfaction with Microsoft's handling of previous vulnerability disclosures. CVE-2025-48804 EPSS 0.005 (64th percentile). CVE-2026-33825 is CISA KEV due 2026-05-06, EPSS 0.056 (90th percentile).
Microsoft Exchange Zero-Day (CVE-2026-42897)
Microsoft Exchange Server 2016, 2019, and Subscription Edition face active exploitation via CVE-2026-42897 (CVSS 8.1), a cross-site scripting spoofing vulnerability. Attackers send a specially crafted email that, when opened in Outlook Web Access under specific interaction conditions, executes arbitrary JavaScript in the browser context. Microsoft is providing temporary mitigation through the Exchange Emergency Mitigation Service (EEMS), which applies automatically via URL rewrite configuration. Patches are in development. Exchange Online is not affected. For air-gapped environments, Microsoft provides the Exchange on-premises Mitigation Tool (EOMT). Run via elevated Exchange Management Shell: single server: .\EOMT.ps1 -CVE "CVE-2026-42897" or all servers: Get-ExchangeServer | Where-Object { $_.ServerRole -ne "Edge" } | .\EOMT.ps1 -CVE "CVE-2026-42897".
Foxconn North American Facilities Hit by Nitrogen Ransomware
Foxconn confirmed a cyberattack disrupted operations at several North American facilities this week. Nitrogen ransomware group claimed responsibility, alleging exfiltration of 11 million files totaling 8TB of data. The stolen data includes confidential instructions, internal project documentation, and technical drawings related to projects involving Intel, Apple, Google, Dell, and Nvidia. Sample files allegedly include Foxconn financial records, engineering schematics, motherboard and PCB diagrams, server platform documentation, and manufacturing process documents. The exposed materials also reference confidential technical documentation from JPMorgan Chase, Google, Intel, NVIDIA, AMD, ASPEED, Renesas, Hewlett Packard Enterprise, and Tencent. Foxconn has not confirmed a ransom payment. The company remains listed on Nitrogen's leak site, suggesting negotiations are ongoing or the company has decided not to pay. Foxconn stated affected factories are resuming normal production. This attack is one of 600 ransomware hits on manufacturing companies in 2026, with median ransom payments at $400,000.
KongTuke Pivots to Microsoft Teams for Social Engineering
Initial access broker KongTuke has shifted to Microsoft Teams for social engineering attacks, reducing time from first contact to persistent access to under five minutes. The threat actor tricks users into pasting a PowerShell command that deploys ModeloRAT malware. KongTuke has been active since at least April 2026, rotating through five Microsoft 365 tenants to evade blocking. The attacker uses Unicode whitespace tricks to make display names appear legitimate, impersonating internal IT support staff. The PowerShell command downloads a ZIP archive from Dropbox containing a portable WinPython environment that launches ModeloRAT (Pmanager.py). The malware has evolved with a five-server C2 pool with automatic failover, randomized URL paths, self-update capability, multiple independent access paths (primary RAT, reverse shell, TCP backdoor), and expanded persistence mechanisms using Run keys, Startup shortcuts, VBScript launchers, and SYSTEM-level scheduled tasks. The scheduled task persists through the implant's self-destruct routine and system reboots.
Widespread Cisco SD-WAN Exploitation by Multiple Threat Clusters
Ten distinct threat clusters have exploited CVE-2026-20133, CVE-2026-20128, and CVE-2026-20122 beginning March 2026 to deploy web shells, cryptocurrency miners, credential stealers, and backdoors. The vast majority of exploitation used ZeroZenX Labs' proof-of-concept code and accompanying JSP-based web shell tracked as "XenShell." Observed post-compromise activity includes: Cluster 1 deploying Godzilla web shell (active since March 6), Cluster 2 deploying Behinder web shell (March 10), Cluster 3 deploying XenShell and Behinder variant (March 4), Cluster 4 deploying Godzilla variant (March 3), Cluster 5 deploying AdaptixC2 malware agent (March 13), Cluster 6 deploying Sliver C2 framework (March 5), Cluster 7 deploying XMRig miner (March 25), Cluster 8 deploying KScan asset mapping tool and Nim-based backdoor likely based on NimPlant (March 10), Cluster 9 deploying XMRig miner and gsocket proxying tool (March 17), and Cluster 10 deploying credential stealer targeting admin hashdumps, JWT key chunks, and AWS credentials (March 13). These three vulnerabilities, when chained, allow remote unauthenticated attackers to gain access to devices. Cisco released patches in February 2026. CVE-2026-20133 CISA KEV due 2026-04-23, EPSS 0.014 (80th percentile). CVE-2026-20122 CISA KEV due 2026-04-23, EPSS 0.012 (79th percentile). CVE-2026-20128 CISA KEV due 2026-04-23, EPSS 0.000 (15th percentile).
OpenAI Supply Chain Breach via TanStack Attack
OpenAI confirmed two employees' devices were breached in the Mini Shai-Hulud supply chain campaign by TeamPCP extortion gang. The attack compromised hundreds of npm and PyPI packages through malicious updates to TanStack, Mistral AI, UiPath, Guardrails AI, and OpenSearch packages. Attackers abused weaknesses in GitHub Actions workflows and CI/CD configurations to extract tokens from memory and publish malicious packages through legitimate release pipelines. The malware targeted developer and cloud credentials including GitHub tokens, npm publish tokens, AWS credentials, Kubernetes secrets, SSH keys, and .env files. It established persistence by modifying Claude Code hooks and VS Code auto-run tasks, surviving package removal. Limited credentials were stolen from OpenAI internal source code repositories. Code signing certificates for OpenAI products on macOS, Windows, iOS, and Android were exposed but no evidence of abuse was detected. OpenAI is rotating the certificates as a precaution. macOS users must update OpenAI desktop applications before June 12, 2026, as applications signed with older certificates may not launch or receive updates due to Apple's notarization process. Microsoft Threat Intelligence reported the malware also launched a Linux information-stealing tool targeting Russian-language software and a destructive sabotage component that would randomly execute recursive wipe commands on Israeli or Iranian systems.
AI Application Misconfigurations Create Exploitable Attack Paths
Microsoft Defender for Cloud signals show AI services publicly exposed with weak or missing authentication, enabling low-effort, high-impact outcomes including remote code execution, credential theft, and access to sensitive internal tools. More than half of cloud-native workload exploitations, including AI applications, stem from misconfigurations rather than zero-days. Exploitable misconfigurations combine public exposure (internet-reachable UI or API) with missing or weak authentication and authorization, creating practical attack paths without requiring sophisticated techniques. AI deployments on Kubernetes emerge as the preferred operating layer. Organizations prioritize speed over secure configuration. As AI applications connect to more internal systems and data sources, a single misconfiguration can expose not just an application endpoint but also sensitive data, infrastructure, and operational capabilities. Examples include exposed Model Context Protocol (MCP) servers that let AI agents discover and interact with external tools and data sources. MCP servers can be installed locally or accessed remotely with support for Server-Sent Events.
Windows Privilege Escalation Zero-Day (GreenPlasma)
Anonymous researcher Nightmare-Eclipse disclosed a privilege escalation zero-day affecting Windows CTFMON (Collaborative Translation Framework). The vulnerability, codenamed GreenPlasma, arises from Windows CTFMON arbitrary section creation. The released proof-of-concept is incomplete and lacks the necessary code to obtain a full SYSTEM shell. In its current form, the exploit allows an unprivileged user to create arbitrary memory section objects within directory objects writable by SYSTEM. This could enable manipulation of privileged services or drivers that implicitly trust those paths, as a standard user does not have write access to those locations. The researcher released this zero-day and YellowKey after allegedly expressing dissatisfaction with Microsoft's handling of previous vulnerability disclosures. The researcher previously published three Defender zero-days (BlueHammer, RedSun, UnDefend) that came under active exploitation. BlueHammer was assigned CVE-2026-33825 and patched last month. Microsoft appears to have silently addressed RedSun without issuing any advisory. The researcher promised a "big surprise" coinciding with June 2026 Patch Tuesday.
Federal Identity Security Critical in Age of AI
White House cyber official Nick Polk stated that AI models will still generally require trusted access first, making identity security the critical control layer. Even in an AI-powered future, the network security boundary matters, providing meaningful control over who gets access to systems and data. AI tools have given attackers advantages including obviating the need for stealth with smash-and-grab attacks faster than response times. AI tools can also easily become insider threats, bypassing guardrails by exploiting obscure technical loopholes. Research from UC-Riverside found that automated AI agents "can become dangerously fixated on completing assignments without recognizing when their actions are harmful, contradictory or simply irrational." The study examined Claude Sonnet and Opus 4, as well as ChatGPT-5, finding model agents struggled with contextual reasoning, had biases towards taking action, and would frequently get tripped up by contradictory or infeasible goals. Anna Libkhen, acting CISO for the Bureau of Economic Analysis at the Department of Commerce, stated AI has become "much more clever in hiding how it managed to penetrate and attack and come through as a trustworthy source," adding "It is scary, yes, we are very vulnerable."
Pwn2Own Berlin 2026 Day 1: $523,000 in Rewards for 24 Zero-Days
Security researchers collected $523,000 in cash awards on Day 1 of Pwn2Own Berlin 2026 after exploiting 24 unique zero-days. Orange Tsai earned $175,000 by chaining 4 logic bugs to achieve a sandbox escape on Microsoft Edge. Windows 11 was hacked three times with privilege escalation zero-days by Angelboy and TwinkleStar03 (DEVCORE Internship Program), Marcin Wiązowski, and Kentaro Kawane of GMO Cybersecurity, each earning $30,000. Valentina Palmiotti (IBM X-Force Offensive Research) collected $20,000 for rooting Red Hat Linux for Workstations and $50,000 for an NVIDIA Container Toolkit zero-day. Other successful attempts included k3vg3n chaining 3 bugs to take down LiteLLM ($40,000), Satoki Tsuji and haehae exploiting NVIDIA Megatron Bridge ($20,000), Compass Security and maitai of Doyensec hacking OpenAI's Codex ($40,000 each), haehae dropping a Chroma zero-day ($20,000), and STARLabs SG exploiting LM Studio ($40,000). DEVCORE Research Team leads the competition with $205,000. Day 2 targets include Microsoft SharePoint, Exchange, Windows 11, Apple Safari, Cursor, Red Hat Enterprise Linux, LM Studio, OpenAI Codex, LiteLLM, Anthropic Claude Code, and Mozilla Firefox. All targeted devices run latest operating system versions. Vendors have 90 days to release security fixes.
Linux Kernel Privilege Escalation Vulnerability (Fragnesia - CVE-2026-46300)
A new Linux kernel vulnerability named Fragnesia allows local attackers to escalate privileges to root by exploiting the XFRM ESP-in-TCP subsystem. The flaw allows an unprivileged attacker to gain root permissions by overwriting sensitive system files. A proof-of-concept exploit is available but there is no evidence of in-the-wild exploitation. Fragnesia exploits a vulnerability in the XFRM ESP-in-TCP subsystem to achieve a memory write primitive in the kernel. The primitive is used to corrupt the page cache memory of the /usr/bin/su binary, launching a shell with root privilege. Exploitation is not constrained to the su binary and can modify any file readable by the user, including /etc/passwd. Most Linux distributions are affected and have started releasing patches. Fragnesia is in the same class as Dirty Frag and Copy Fail. Copy Fail has been exploited in the wild. Microsoft noted shortly after Dirty Frag's disclosure that it may have also been leveraged in malicious attacks. Microsoft Defender detected limited in-the-wild activity on May 8 that could indicate exploitation of either Dirty Frag or Copy Fail.
Secret Blizzard's Kazuar Evolves into Modular P2P Botnet
Microsoft reported that Kazuar, a malware family attributed to Russian state actor Secret Blizzard, has evolved from a traditional backdoor into a highly modular peer-to-peer botnet ecosystem. The botnet consists of three module types: Kernel (central coordinator issuing tasks, managing communication, maintaining logs), Bridge (communication relay), and Worker (task executors). The architecture reduces observable footprint by restricting external communications to a single elected leader while maintaining flexible tasking, data staging, and multiple fallback C2 channels. The threat actor targets organizations in government and diplomatic sectors in Europe and Central Asia, as well as systems in Ukraine previously compromised by Aqua Blizzard, for intelligence collection supporting Russia's foreign policy and military objectives. Delivery occurs through multiple dropper variants. The Pelmeni dropper embeds encrypted second-stage payload as an encrypted byte array, often bound to the target environment (encrypted using target hostname). Another method deploys a small .NET loader alongside the final payload, invoked as a COM object. Kazuar performs extensive anti-analysis and sandbox checks, including checking for running processes containing analysis tools, canary files on desktop, and loaded process for sandbox indicators.
Siemens Industrial Control Systems (Multiple Products)
Siemens released security advisories for multiple industrial control systems with vulnerabilities ranging from remote code execution to cross-site scripting. SIMATIC CN 4100 contains multiple vulnerabilities leading to compromise in availability, integrity, and confidentiality (update to V5.0 or later). Simcenter Femap heap-based buffer overflow in Datakit library when reading IPT files can lead to remote code execution (update to V2512.0003 or later). CVE-2025-12659 EPSS 0.000 (4th percentile). Teamcenter affected by XSS, hardcoded credentials, and PDF.js type check issues (update V2312, V2406, V2412, V2506 to latest versions). CVE-2026-33862 EPSS 0.000 (10th percentile), CVE-2024-4367 EPSS 0.378 (97th percentile), CVE-2026-33893 EPSS 0.000 (11th percentile). ROS# path traversal vulnerability in file_server service before V2.2.2 (update to V2.2.2 or later). CVE-2026-41551 EPSS 0.000 (15th percentile). gWAP remote code execution via Axios HTTP client library prototype pollution (update to V3.1.1 or later). CVE-2026-40175 EPSS 0.000 (9th percentile). Solid Edge PAR file parsing vulnerabilities leading to code execution (update to V226.0 Update 5 or later). CVE-2026-44411 EPSS 0.000 (3rd percentile), CVE-2026-44412 EPSS 0.000 (3rd percentile). Opcenter RDnL missing authentication in ActiveMQ Artemis Core protocol (update to Apache Artemis 2.52.0 or later, implement Core interceptor, remove Core protocol support from untrusted acceptors, or use two-way SSL). CVE-2026-27446 EPSS 0.002 (36th percentile). SIMATIC S7 PLC Web Server XSS vulnerabilities across multiple CPU models (apply available updates or countermeasures). CVE-2026-25787 EPSS 0.000 (13th percentile), CVE-2026-25786 EPSS 0.000 (13th percentile), CVE-2026-25789 EPSS 0.001 (33rd percentile). Ruggedcom Rox command injection in Scheduler functionality allowing root command execution (update to V2.17.1 or later). CVE-2025-40949 EPSS 0.002 (38th percentile). SENTRON 7KT PAC1261 Data Manager HTTP request smuggling in Go net/http package (update to V2.1.0 or later, use encrypted protocols). CVE-2025-22871 EPSS 0.003 (53rd percentile). SIPROTEC 5 weak session identifiers facilitating brute-force attacks (update CP300 devices to V11.0 or later, apply mitigations for other platforms). CVE-2024-54017 EPSS 0.000 (8th percentile). Multiple industrial devices denial of service vulnerability (update SCALANCE and RUGGEDCOM models to V8.3 or later, apply countermeasures for end-of-life products). CVE-2025-40833 EPSS 0.000 (12th percentile).
GnuTLS Authentication Bypass and Name Constraint Issues
Two GnuTLS vulnerabilities published: CVE-2026-42011 (security bypass due to incorrect name constraint handling, EPSS 0.000, 8th percentile) and CVE-2026-42010 (authentication bypass via null character in username, EPSS 0.001, 32nd percentile). Both vulnerabilities are documented in MSRC Security Update Guide with minimal details provided.
Twisted DNS Denial of Service
CVE-2026-42304 affects twisted.names, allowing denial of service via crafted DNS compression pointer chains. EPSS 0.000 (2nd percentile). Minimal details provided in MSRC advisory.
Today's threat landscape is dominated by the intersection of infrastructure vulnerabilities and operational urgency. Cisco SD-WAN's sixth exploited zero-day of 2026 demonstrates persistent attacker focus on network infrastructure that businesses cannot afford to take offline. The BitLocker bypass and Exchange zero-day both highlight how attackers target protective mechanisms (encryption, web access) that organizations rely on daily. The shift to supply chain attacks (TanStack/OpenAI) and social engineering via trusted platforms (Teams/KongTuke) shows adversaries adapting to improved endpoint defenses by targeting the trust relationships and development pipelines that security teams struggle to instrument and control.