CVE-2020-17103, CVE-2025-3465, CVE-2026-3102, CVE-2026-4293, CVE-2026-43491, CVE-2026-43492, CVE-2026-43493, CVE-2026-45585, CVE-2026-47612, CVE-2026-8598
IP Addresses:
1.4.1.12
Get tomorrow's brief in your inbox
May 20, 2026
Today: Microsoft faces a sixth zero-day disclosure in six weeks as researcher "Nightmare Eclipse" releases YellowKey, a BitLocker bypass requiring only physical access and a USB drive, plus two additional Windows exploits. Drupal warns of an urgent core security update dropping tonight between 5-9 PM UTC with exploits expected within hours. CISA exposes its own operational security failure after hardcoded credentials were discovered in a public GitHub repository that had been accessible since November 2025.
YellowKey BitLocker Bypass (CVE-2026-45585)
Microsoft confirmed a security feature bypass vulnerability in Windows BitLocker publicly disclosed as "YellowKey." An attacker with physical access and a USB device can completely negate BitLocker encryption protection without credentials, PIN, or TPM bypass. The exploit requires forcing a reboot into Windows Recovery Environment and entering a specific key combination. Microsoft is issuing mitigation guidance now, with the full security update pending.
Action: Apply Microsoft's interim mitigation guidance immediately for any BitLocker-protected devices that may be physically accessible to unauthorized individuals. Full patch expected in upcoming security update.
Sources: Dark Reading | MSRC Security Update Guide
Drupal Core Security Release Tonight
Drupal announced an urgent core security release scheduled for May 20, 2026, 5-9 PM UTC, affecting all supported branches. The security team warned that exploits could be developed within hours or days, though not all configurations are affected. Mitigation information will be included in the advisory when released.
Action: Reserve time during the 5-9 PM UTC release window to update Drupal installations immediately. Update to the latest supported patch for your version before the deadline (11.3.x, 11.2.x, 10.6.x, or 10.5.x). Sites on end-of-life versions (8 and 9) should plan manual patching or immediate upgrade to supported releases.
Source: The Hacker News
CISA Credentials Exposed in Public GitHub Repository
CISA's own credentials, including SSH keys and plaintext passwords, were discovered in a public GitHub repository where they had been accessible since November 2025. This represents a significant operational security failure by the agency responsible for protecting critical infrastructure and coordinating vulnerability disclosure.
Action: Review all credential management practices, automated secret scanning in CI/CD pipelines, and GitHub repository security settings. Implement pre-commit hooks to prevent credential exposure.
Source: Ars Technica
9 claims tracked across 1 group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| Titan | Apex Maritime Co., Inc. | Maritime/Shipping | Unknown |
| Titan | SIRILAK SEAFOOD (PW) LTD. | Food/Agriculture | Unknown |
| Titan | Mezta Corporativo, S.A. de C.V. | Unknown | Mexico |
| Titan | Abp Autoricambi Srl | Automotive Parts | Italy |
| Titan | DFI AMERICA, LLC | Unknown | United States |
| Titan | CRIT Tunisie | Staffing/HR | Tunisia |
| Titan | Groupe CRIT SA | Staffing/HR | France |
| Titan | ETM-ELECTROMATIC, INC. | Manufacturing | Unknown |
| Titan | Quahe Woo & Palmer LLC | Legal Services | Unknown |
Source: RansomLook
GreenPlasma Windows Privilege Escalation
A new Windows privilege escalation vulnerability dubbed "GreenPlasma" affects Windows 10, Windows 11, and Windows Server. The flaw exploits a Windows component for managing text input services to allow attackers to escalate privileges to SYSTEM on fully patched systems. While the current proof-of-concept stops short of the final SYSTEM stage, it enables credential harvesting, lateral movement, persistence, and security bypass. This is the second of two new zero-days disclosed by researcher "Nightmare Eclipse" following Microsoft's May 2026 Patch Tuesday.
GreenPlasma is typically exploited in conjunction with social engineering attacks. A common scenario involves threat actors convincing target users to install Remote Monitoring and Management (RMM) software, then using remote access to trigger the exploit and elevate from generic user to SYSTEM privileges.
Action: Monitor for unauthorized RMM software installations. Review user permissions and implement application control policies to prevent installation of unauthorized remote access tools. Watch for Microsoft's patch in upcoming security updates.
Source: Dark Reading
MiniPlasma: Six-Year-Old Vulnerability Still Exploitable
Researcher "Nightmare Eclipse" released an exploit for CVE-2020-17103, an elevation-of-privilege vulnerability in Windows Cloud Files Mini Filter Driver that Microsoft supposedly patched in 2020. The original proof-of-concept from Google's Project Zero still works without modifications, and the researcher claims to have weaponized it to allow attackers to gain complete control of vulnerable systems.
Action: Verify CVE-2020-17103 patches are applied across all Windows systems. If Google's original PoC still works unchanged, the 2020 patch may have been incomplete or ineffective.
Source: Dark Reading
Microsoft Teams macOS Location Prompt Issue
Microsoft confirmed that Teams is displaying non-dismissible location prompts on macOS versions 14 (Sonoma), 15 (Sequoia), and 26 (Tahoe). Microsoft blamed a recent macOS security update that prevents the OS from retaining users' location permission selections. While this is primarily an annoyance issue rather than a security vulnerability, it could be exploited in social engineering scenarios where users become conditioned to repeatedly dismiss security prompts.
Action: Work around the issue by manually enabling location access for Microsoft Teams within macOS settings: System Settings > Privacy & Security > Location Services, toggle "Microsoft Teams" and "Microsoft Teams ModuleHost" on and off, then set to desired setting.
Source: BleepingComputer
ABB CoreSense Path Traversal (CVE-2025-3465)
ABB CoreSense HM (versions <=2.3.1) and CoreSense M10 (versions <=1.4.1.12) are vulnerable to path traversal, allowing unauthenticated users to access restricted directories. Exploitation can lead to complete system compromise and exposure of sensitive information. These products are used in food and agriculture, commercial facilities, and critical manufacturing sectors worldwide.
The vulnerability is only exploitable when the attacker has local access to the machine hosting the web application (localhost access). ABB has released patches: CoreSense HM v2.3.4 and CoreSense M10 v1.4.1.31.
Action: Update to CoreSense HM v2.3.4 or CoreSense M10 v1.4.1.31. Configure affected products to restrict local access to authorized users only until patched.
Source: CISA ICS Advisory
Kieback & Peter DDC Building Controllers XSS (CVE-2026-4293)
Multiple Kieback & Peter DDC Building Controllers are vulnerable to cross-site scripting (XSS), enabling JavaScript execution in victims' browsers and allowing attackers to control the browser. Affected devices include DDC4002, DDC4100, DDC4200, DDC4200-L, DDC4400, DDC4002e, DDC4200e, DDC4400e, DDC4020e, DDC4040e, and DDC520 controllers.
Several affected models (DDC4002, DDC4100, DDC4200, DDC4200-L, DDC4400) are end-of-maintenance and will not receive patches. For these devices, vendors recommend operating them in strictly separate OT environments, restricting network access to trusted individuals only, and disabling the web portal if not required.
Action: For supported models (DDC520, DDC4002e, DDC4200e, DDC4400e, DDC4020e, DDC4040e), update firmware to version 1.23.5 or newer (for 'e' models) or 1.24.2 or newer (for DDC520). For end-of-maintenance devices, implement network isolation and disable web portal access.
Source: CISA ICS Advisory
ZKTeco CCTV Cameras Authentication Bypass (CVE-2026-8598)
ZKTeco CCTV cameras using the SSC335-GC2063-Face-0b77 solution (versions <V5.0.1.2.20260421) contain an undocumented configuration export port accessible without authentication. This port exposes critical camera information including open services and camera account credentials.
Action: Update ZKTeco cameras to firmware version V5.0.1.2.20260421 or later immediately. Review camera account credentials and change passwords for any potentially exposed devices.
Source: CISA ICS Advisory
ExifTool macOS Vulnerability (CVE-2026-3102)
A vulnerability in ExifTool allows attackers to compromise macOS systems via a malicious image. ExifTool is commonly used by image processing applications, file managers, and security tools to extract metadata from images. Exploitation could occur when processing untrusted image files.
Action: Update ExifTool to the latest version. Review any automated image processing workflows that handle untrusted input and ensure they run in sandboxed environments with limited privileges.
Source: Securelist (Kaspersky)
Microsoft CVE Disclosures
Microsoft published information for three Linux kernel-related CVEs affecting Windows systems:
All three have minimal EPSS scores indicating extremely low likelihood of active exploitation. These appear to be Linux kernel subsystem vulnerabilities affecting Windows Subsystem for Linux (WSL).
Action: Monitor for patches through standard Windows Update channels. No immediate action required given low EPSS scores.
Sources: MSRC Security Update Guide | MSRC | MSRC
Sophos Firewall Update Bricking Devices
Sophos confirmed that a recent firewall firmware update is causing devices to enter an Access Violation (AV) boot loop, effectively bricking them. The update identified as Hotfix-639-rev-1, released on May 13, 2026, for Sophos Firewall v21 MR1 (21.0.1) and v21 GA (21.0.0), triggers the boot loop during installation. Affected models include XGS series (87, 107, 127, 136, 2100, 2300, 3100, 3300, 4300, 4500, 5500, 6500) and SG/XG series (105, 115, 125, 135, 210, 230, 310, 330, 430, 450).
Sophos has withdrawn the hotfix and is working on a replacement. Devices already affected require manual recovery procedures involving console access and specific boot commands.
Action: Do not install Hotfix-639-rev-1 if not yet applied. For devices already bricking, follow Sophos's manual recovery procedures requiring console access. Plan for potential extended downtime on affected devices.
Source: BleepingComputer
PAN-OS GlobalProtect Portal Command Injection (CVE-2026-47612)
Palo Alto Networks disclosed CVE-2026-47612, a command injection vulnerability in the GlobalProtect portal feature of PAN-OS. While initially rated at CVSS 7.8 (High), Palo Alto found no evidence of active exploitation and considers the exploitability "Less Likely." The vulnerability affects specific PAN-OS versions with GlobalProtect portal enabled.
Action: Apply patches according to Palo Alto's security advisory. Review GlobalProtect portal configurations and ensure external access is properly restricted while awaiting patches.
Source: Bleeping Computer
Ivanti Endpoint Manager Mobile (EPMM) Critical Vulnerabilities
Ivanti disclosed three critical vulnerabilities in Endpoint Manager Mobile affecting EPMM versions 11.10, 11.11, and 12.0. While Ivanti initially found no evidence of exploitation, the company's recent history of zero-day exploitation and delayed disclosure makes these particularly concerning. One of the CVEs is rated 10.0 CVSS (Critical).
Action: Apply Ivanti's patches immediately. Given Ivanti's track record, assume threat actors are actively researching these vulnerabilities. Review all Ivanti EPMM deployments and ensure they are not directly exposed to the internet.
Source: Bleeping Computer
Adobe ColdFusion Patches Critical Pre-Auth RCE
Adobe released security updates for ColdFusion addressing multiple critical vulnerabilities, including a pre-authentication remote code execution flaw. ColdFusion has been a frequent target for initial access in ransomware campaigns.
Action: Apply Adobe's ColdFusion security updates immediately. If ColdFusion servers cannot be patched within 24 hours, consider taking them offline or restricting access to trusted networks only until patched.
Source: BleepingComputer
AI Vulnerability Discovery Accelerates
Recorded Future published analysis on the impact of frontier AI models like Anthropic's Mythos and OpenAI's GPT 5.5 on vulnerability discovery. While AI has commoditized vulnerability discovery, making it cheap, fast, and broadly accessible, the real challenge remains prioritization. In 2025, approximately 50,000 CVEs were disclosed, but only 446 (less than 1%) were actively exploited in the wild.
The key insight: finding vulnerabilities has never been the bottleneck. The limiting factor is the ability to absorb, prioritize, and act on findings before adversaries do. Threat intelligence provides the prioritization layer by filtering CVEs based on live risk scores, active exploitation evidence, ransomware actor associations, and choke-point criticality.
Source: Recorded Future Blog
SentinelOne Announces Prompt Security for Agentic AI
SentinelOne released Prompt Security for Agentic AI, a governance platform designed to provide proactive controls over autonomous AI agents. As enterprises deploy AI agents with expanded privileges and tool access, the security model shifts from perimeter defense to agent-level governance.
Source: SentinelOne Blog
Ransomware Tracker API Disruptions
Multiple ransomware tracking services experienced temporary disruptions over the last 48 hours. RansomLook, RansomWatch, and ThreatFox all reported intermittent availability issues, likely due to increased law enforcement and industry monitoring of dark web infrastructure. Threat intelligence teams should implement redundant data sources to maintain operational continuity.
The six zero-day disclosures from researcher "Nightmare Eclipse" over six weeks represent an unusual pattern of coordinated disclosure outside standard vulnerability coordination processes. This follows the researcher's stated "grudge against Microsoft" and willingness to release proof-of-concept code before patches are available. Organizations should anticipate continued zero-day disclosures targeting Windows and prepare rapid patch deployment capabilities.
The Drupal security team's advance warning with specific time window and exploitation timeline reflects a mature approach to critical vulnerability disclosure, giving defenders time to prepare while maintaining coordination. This model balances transparency with responsible disclosure and should be studied by other vendors.
CISA's credential exposure represents a significant credibility problem for the agency responsible for coordinating critical infrastructure defense and vulnerability disclosure. The incident highlights that even security-focused organizations struggle with fundamental operational security practices like credential management and secret scanning in development workflows.
Brief generated from 40 sources. This briefing is for informational purposes and represents analysis of publicly available security intelligence.