← Carolina Clear Tech

Cyber Threat Brief

2026-05-18

Listen to this brief (24:14)

Download MP3
Show Notes

Show Notes - 2026-05-18

Stories Covered

CVEs Referenced

CVE-2020-17103, CVE-2025-62221, CVE-2026-28515, CVE-2026-28516, CVE-2026-28517, CVE-2026-31635, CVE-2026-33825, CVE-2026-42945

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cybersecurity Brief

May 18, 2026

Today: Windows zero-day MiniPlasma grants SYSTEM privileges on fully patched systems with PoC released. NGINX CVE-2026-42945 exploited in the wild, causing worker crashes and possible RCE. Tycoon2FA rebounds from takedown with device-code phishing targeting Microsoft 365 accounts.

Critical Alerts

MiniPlasma Windows Zero-Day Enables SYSTEM Privilege Escalation (CVE-2025-62221, CVE-2020-17103)

Security researcher Chaotic Eclipse released a proof-of-concept exploit for a Windows privilege escalation zero-day that grants SYSTEM privileges on fully patched Windows systems. The vulnerability impacts the Windows Cloud Files Mini Filter Driver (cldflt.sys) in the HsmOsBlockPlaceholderAccess routine. Microsoft claimed to have patched this issue in December 2020 as CVE-2020-17103, but the exact same vulnerability remains unpatched. CVE-2025-62221 (CVSS 7.8) in the same component was added to CISA KEV with a due date of December 30, 2025, after exploitation by unknown threat actors. BleepingComputer and security researcher Will Dormann confirmed the exploit works reliably on fully patched Windows 11 Pro systems running May 2026 updates, though it does not work on the latest Insider Preview Canary build. The exploit abuses how the Windows Cloud Filter driver handles registry key creation through an undocumented CfAbortHydration API, allowing arbitrary registry keys to be created without proper access checks. All Windows versions are likely affected by this vulnerability.

NGINX CVE-2026-42945 Exploited in the Wild

A critical heap buffer overflow vulnerability in NGINX (CVE-2026-42945, CVSS 9.2) is under active exploitation days after public disclosure. The flaw affects NGINX versions 0.6.27 through 1.30.0 in the ngx_http_rewrite_module and was introduced in 2008. VulnCheck detected exploitation attempts against honeypot networks over the weekend. The vulnerability allows unauthenticated attackers to crash worker processes or execute remote code with crafted HTTP requests, but requires a specific rewrite configuration to be vulnerable. Code execution is only possible on devices where Address Space Layout Randomization (ASLR) is disabled. On default deployments with ASLR enabled, successful exploitation triggers a denial-of-service condition. Censys query surfaces roughly 5.7 million internet-exposed NGINX servers running potentially vulnerable versions, though the truly exploitable population is likely much smaller.

openDCIM Critical Vulnerabilities Exploited

VulnCheck reports exploitation attempts targeting two critical flaws in openDCIM (CVE-2026-28515 and CVE-2026-28517, both CVSS 9.3). CVE-2026-28515 is a missing authorization vulnerability allowing authenticated users to access LDAP configuration functionality regardless of privileges. In Docker deployments where REMOTE_USER is set without authentication enforcement, the endpoint may be reachable without credentials. CVE-2026-28517 is an OS command injection vulnerability in report_network_map.php that processes the "dot" parameter without sanitization and passes it directly to a shell command. The two vulnerabilities can be chained with CVE-2026-28516 (SQL injection, CVSS 9.3) to achieve remote code execution over five HTTP requests and spawn a reverse shell. Attacker activity originates from a single Chinese IP using a customized implementation of AI vuln discovery tool Vulnhuntr to automatically check for vulnerable installations before dropping a PHP web shell.

Business & Infrastructure Threats

Tycoon2FA Hijacks Microsoft 365 Accounts via Device-Code Phishing

The Tycoon2FA phishing kit rebounded from an international law enforcement disruption in March and now supports device-code phishing attacks targeting Microsoft 365 accounts. The platform abuses Trustifi click-tracking URLs to hijack accounts despite the earlier takedown. Device code phishing leverages OAuth 2.0 device authorization grant flows where attackers send a device authorization request to the target service and forward the generated code to the victim. When the victim enters the code on the legitimate login page, the attacker gains unrestricted access to the victim's Microsoft 365 data including email, calendar, and cloud file storage. Push Security warned that device code phishing attacks have increased by 37x this year, supported by at least ten distinct phishing-as-a-service platforms and private kits. The attack chain starts with an invoice-themed phishing email containing a Trustifi tracking URL that redirects through Trustifi, Cloudflare Workers, and obfuscated JavaScript layers, landing the victim on a fake Microsoft CAPTCHA page. The page retrieves a Microsoft OAuth device code from the attacker's backend and instructs the victim to paste it to microsoft.com/devicelogin. After the victim completes MFA, Microsoft issues OAuth access and refresh tokens to the attacker-controlled device. The kit includes extensive anti-analysis protection against researchers, blocking 230 vendor names, Selenium, Puppeteer, Playwright, Burp Suite, security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

Grafana Labs Confirms Breach After Source Code Theft

Grafana Labs confirmed a data breach on May 18 after attackers downloaded its codebase from GitHub using a compromised token. The incident granted access to the Grafana Labs GitHub environment, allowing hackers to download the codebase. Grafana stated no personal or customer information was stolen and the incident has not impacted customer systems or operations. The attackers demanded a ransom to prevent source code from being leaked, but Grafana has decided not to pay. The compromised credentials have been reset and a forensic analysis is underway. Grafana was listed on the Coinbase Cartel leak site on May 15, an extortion group active since September 2025 that conducts data theft without file-encrypting ransomware. The Coinbase Cartel website currently lists 105 victims. Cybersecurity companies link Coinbase Cartel to ShinyHunters, Scattered Spider, and Lapsus$, whose members have been collaborating since at least mid-2025. The alliance has been conducting a major data theft campaign using the ShinyHunters name to sign intrusions against high-profile companies including Instructure, Vimeo, Wynn Resorts, Vercel, and Medtronic.

First Shai-Hulud Worm Clones Emerge

The first Shai-Hulud worm clones emerged days after TeamPCP released the malware's source code on GitHub. Ox Security reports that a threat actor published four NPM packages containing infostealer malware, including one that is a direct clone of Shai-Hulud. The package 'chalk-tempalte' contains the Shai-Hulud code without obfuscation, implementing its own C&C server and private key. The other three packages use typo-squatting to infect Axios users, with one ensnaring infected machines into a DDoS botnet. The four packages have a combined weekly download count of over 2,600. Shai-Hulud was first used in supply chain attacks in September 2025 and again in November, hitting hundreds of NPM packages and likely infecting thousands of developers. The malware steals credentials, API keys, tokens, and other secrets from infected machines and uses them for self-propagation by injecting itself into packages maintained by victims and publishing malicious versions on their behalf. Last week, several repositories containing the Shai-Hulud source code briefly appeared on GitHub, accompanied by an announcement from TeamPCP and BreachForums encouraging miscreants to use the code in a supply chain challenge.

Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations

Broadcom-owned Symantec and Carbon Black teams confirmed that the Lua-based fast16 malware was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations. The pre-Stuxnet tool was engineered to corrupt uranium-compression simulations central to nuclear weapon design. Fast16's hook engine selectively targets high-explosive simulations inside LS-DYNA and AUTODYN, checking for material density above 30 g/cm3, a threshold uranium can only reach under the shock compression of an implosion device. SentinelOne previously presented analysis describing fast16 as the first sabotage framework whose components may have developed as early as 2005, predating the earliest known version of Stuxnet by two years. Evidence included a reference to the string "fast16" in a text file leaked by The Shadow Brokers in 2017 as part of alleged Equation Group hacking tools. The malware features 101 rules to tamper with mathematical calculations in engineering and simulation programs. The 101 hook rules categorize into 9-10 hook groups, each targeting different builds of LS-DYNA or AUTODYN, suggesting developers tracked software updates and added support for different versions over time. Fast16 will not infect computers with certain security products installed and automatically spreads to other endpoints on the same network so any machine used to run simulations will generate tampered outputs. The findings indicate strategic industrial sabotage using malware was conducted by nation-state actors as far back as 20 years ago, well before Stuxnet damaged uranium enrichment centrifuges at Iran's Natanz nuclear plant.

Indonesia Emerges as New Hub for Cyber Scam Operations

Indonesia is emerging as a new hub for cyber scam operations and illegal online gambling in Southeast Asia after massive crackdowns in neighboring countries sent criminal groups fleeing across borders. Local authorities detained more than 550 suspects following three raids this month. More than 200 suspects were detained after a raid on an apartment complex in Batam on May 6. Another 321 were arrested in a commercial building near Jakarta's Chinatown neighborhood on May 10. Another 30 were detained at guest houses on Bali a few days after. Almost all arrested suspects were foreigners, mainly from China, but also from the Philippines, Myanmar, Thailand, Malaysia, Cambodia, and other Southeast Asian countries. Indonesia's national police says most entered the country using the visa-free policy, requested a visa on arrival, and overstayed the 30-day period while working in cyber compounds carrying out online scams or helping lure people on betting portals. The Indonesian government has started procedures to review the process and even rescind the policy for nationals of neighboring Southeast Asian countries as a way to combat criminal groups relocating operations. Hidden cyber scam compounds have been mainly located in Cambodia, Myanmar, and Thailand. As local authorities cracked down, operators started moving operations to Vietnam, the Philippines, the Middle East, and Africa. Cyber scam compounds are generating billions in US dollars. Left unattended, they have spread in Myanmar and Cambodia where several government and military officials have been added to international sanctions lists for protecting and benefiting from the compounds.

Windows / AD Security

Microsoft Confirms Windows 11 Security Update Install Issues (KB5089549)

Microsoft confirmed that the May 2026 Windows 11 security update (KB5089549) fails to install on some systems and triggers 0x800f0922 errors. The issue is caused by insufficient free space on the EFI System Partition (ESP), resulting in automatic rollback on affected devices. The issue affects devices with limited free space on the ESP, especially when the device has 10 MB or less space available. On affected devices, installation proceeds through initial phases but fails during the reboot phase at approximately 35-36% completion. Users see the "Something didn't go as planned. Undoing changes." message when installation rolls back. Log entries point to insufficient ESP free space such as "SpaceCheck: Insufficient free space", "ServicingBootFiles failed. Error = 0x70", and "SpaceCheck: value used by third-party/OEM files outside of Microsoft boot directories".

Patch Priority

Vulnerability Disclosures

DirtyDecrypt Linux Root Escalation Flaw (CVE-2026-31635)

A recently patched local privilege escalation vulnerability in the Linux kernel's rxgk module now has a proof-of-concept exploit allowing attackers to gain root access on some Linux systems. Named DirtyDecrypt and also known as DirtyCBC, the security flaw was autonomously found and reported by the V12 security team earlier this month. The vulnerability is a rxgk pagecache write due to missing COW guard in rxgk_decrypt_skb. Successful exploitation requires running a Linux kernel with the CONFIG_RXGK configuration option, which enables RxGK security support for the Andrew File System (AFS) client and network transport. This limits the attack surface to Linux distributions that closely follow the latest upstream kernel releases, including Fedora, Arch Linux, and openSUSE Tumbleweed. V12's proof-of-concept exploit has only been tested against Fedora and the mainline Linux kernel. DirtyDecrypt belongs to the same vulnerability class as several other root-escalation flaws disclosed in recent weeks, including Dirty Frag, Fragnesia, and Copy Fail. CISA added Copy Fail to its list of flaws exploited in attacks on May 1 and ordered federal agencies to secure their Linux devices within two weeks.

Pwn2Own Berlin 2026 Results

The Pwn2Own Berlin 2026 hacking contest concluded with security researchers collecting $1,298,250 in rewards after exploiting 47 zero-day flaws. The competition took place at OffensiveCon from May 14-16 and focused on enterprise technologies and artificial intelligence. DEVCORE won with 50.5 Master of Pwn points and $505,000 in rewards after hacking Microsoft SharePoint, Microsoft Exchange, Microsoft Edge, and Windows 11. The competition's highest reward was $200,000 awarded to Cheng-Da Tsai (Orange Tsai) of DEVCORE for chaining three bugs to gain remote code execution with SYSTEM privileges on Microsoft Exchange. Competitors demonstrated multiple Windows 11 local privilege escalation vulnerabilities, Red Hat Enterprise Linux for Workstations root-privilege escalation vulnerabilities, and zero-days in multiple AI coding agents. Several AI products were successfully exploited, earning researchers $40,000 rewards for hacking LiteLLM, OpenAI Codex, and LM Studio. Cursor exploits earned $15,000 and $30,000, while an Ollama exploit earned $28,000. $20,000 bounties were received for OpenAI Codex, Claude Code, LM Studio, NVIDIA Megatron Bridge, and Chroma vulnerabilities. There were eight failed attempts targeting Oracle Autonomous AI Database, NV Container Toolkit, OpenAI Codex, Safari, SharePoint, Red Hat Enterprise Linux for Workstations, Firefox, and VMware ESX. After Pwn2Own ends, vendors have 90 days to release security patches before TrendMicro's Zero Day Initiative publicly discloses them.

General Security News

Linus Torvalds: AI-Powered Bug Hunters Have Made Linux Security Mailing List 'Almost Entirely Unmanageable'

Linus Torvalds stated that AI-powered bug hunters have made the Linux security mailing list almost entirely unmanageable. The article does not provide additional details on the nature of the AI-generated submissions or specific actions being taken to address the issue.

Former CISA Nominee Sean Plankey Named US CEO of Defense Startup

Sean Plankey, most recently the nominee for director of the Cybersecurity and Infrastructure Security Agency, joined defense technology company UFORCE as its U.S. chief executive officer. The London-based company was created out of nine Ukrainian-based firms and announced Plankey's move less than a month after he withdrew his nomination amid difficulties overcoming objections from senators. UFORCE makes combat drones for air, land and sea and plans to have its first U.S.-made unmanned surface vessels hitting the water by this summer. The startup reportedly brought its valuation to $1 billion earlier this year. CISA has gone without a permanent director for the entirety of the second Trump administration, and the president has yet to put forward a nominee for the position since Plankey's withdrawal last month.

South Korea Tests Deepfake Laws in June Local Elections

South Korea will hold local elections on June 3, enforcing two laws aiming to curb the use of AI deepfakes to support political campaigns. Article 82-8 of the Public Official Election Act, established in 2023, prohibits the use of virtual sounds, images, or videos that are difficult to distinguish from reality for 90 days prior to election day. Violations are punishable by imprisonment with labor for not more than 7 years or a fine between 10 million won and 50 million won (approximately $6,700 USD to $33,500 USD). The AI Basic Act, established early last year and put into effect this January, requires AI business operators to notify or indicate to users when AI systems generate virtual audio, images, or video that are difficult to distinguish from real content. The June 3 elections will be the first real stress test of South Korea's full regulatory framework. The problem exists in channels that regulators cannot clearly reach. Deepfakes distributed through encrypted messaging apps, targeted SMS campaigns, and direct voice calls move faster than any fact-checker. By the time a platform removes a clip, it has already reached the people it was designed to reach.

Trends & Context

Today's brief is dominated by zero-day disclosures and active exploitation of critical vulnerabilities. The MiniPlasma Windows zero-day and NGINX CVE-2026-42945 represent immediate threats requiring urgent attention. The researcher behind MiniPlasma is systematically releasing Windows zero-days in protest of Microsoft's bug bounty program, indicating more disclosures are likely. The Tycoon2FA phishing kit's rapid rebound from law enforcement disruption demonstrates the resilience of cybercrime infrastructure. The emergence of Shai-Hulud worm clones following public source code release highlights the accelerating timeline from vulnerability disclosure to active exploitation. Pwn2Own Berlin 2026 results indicate significant security research focus on AI coding agents, with multiple successful exploits across LiteLLM, OpenAI Codex, LM Studio, Cursor, Ollama, Claude Code, and other AI products.