THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft’s May Patch Tuesday fixes 137 vulnerabilities, including critical Netlogon and DNS RCEs

Microsoft released patches for 137 CVEs across Windows, Azure, Office, Edge, and more, with 30 rated critical. Standouts include CVE-2026-41089 (Windows Netlogon, unauthenticated RCE on domain controllers) and CVE-2026-41096 (Windows DNS Client RCE), both high-impact targets for rapid exploitation even as no active attacks are currently reported.

Source: SecurityWeek


Fresh supply-chain attack poisons npm and PyPI packages in “Mini Shai‑Hulud” wave

Over 400 malicious versions of 170 packages were pushed in a rapid campaign hitting TanStack, Mistral AI, UiPath and others, with payloads stealing CI/CD secrets and developer credentials. Notably, the attackers shipped valid provenance for doctored artifacts, underscoring that signed builds don’t guarantee safe pipelines and that dependency and workflow hardening are essential.

Source: SecurityWeek


TeamPCP open-sources Shai‑Hulud tooling, lowering the barrier for copycat supply-chain attacks

Researchers report the Shai‑Hulud worm code has been released publicly, including techniques to forge trust and extract OIDC tokens from CI/CD. This elevates risk beyond a single actor, making mis-scoped identity, cache poisoning, and insufficient workflow isolation urgent audit items for any org publishing to npm or PyPI.

Source: Vectra Networks


Google flags first known AI‑assisted zero‑day exploit seen in the wild

Attackers used AI to help craft an exploit script for a two‑factor authentication bypass in an open-source project, according to Google. The case highlights how AI can compress exploit development timelines, shrinking defenders’ patch windows and raising the premium on rapid detection and coordinated disclosure.

Source: SC Media


“Copy.Fail” dubbed worst Linux kernel bug in years enables stealth local privilege escalation

Theori’s Copy.Fail (CVE‑2026‑31431) abuses AF_ALG sockets and splice() to overwrite file page cache contents four bytes at a time, letting attackers escalate privileges without touching the file on disk. The exploit works reliably across major distros and evades checksum-based integrity tools, making rapid kernel patching and AF_ALG hardening priorities.

Source: Schneier on Security


Fortinet and Ivanti ship critical fixes that can lead to code execution and data exposure

Fortinet addressed critical issues in FortiSandbox and FortiAuthenticator (e.g., CVE‑2026‑44277), while Ivanti patched high‑severity bugs across its portfolio. Given these products’ placement at security boundaries, organizations should prioritize updates, review external exposure, and hunt for suspicious management activity.

Source: SecurityWeek


Android adds ‘Intrusion Logging’ to expose sophisticated spyware operations

Google, working with Amnesty International, introduced an opt‑in Advanced Protection Mode feature that preserves privacy‑aware forensic logs to aid detection and investigation of high‑end spyware. It’s the first vendor‑level capability designed to make stealth mobile intrusions more visible to defenders and investigators.

Source: CyberScoop


You May Also Be Interested In... - Apple Patches Dozens of Vulnerabilities in macOS, iOS - Foxconn confirms cyberattack impacting North American factories - Global cyber threats spike in April 2026, ransomware expands
Cybersecurity — May 13, 2026 | Briefing24