THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Microsoft patches critical zero-click Outlook bug dubbed an “enterprise killer”

Microsoft fixed CVE-2026-40361, a critical zero-click Outlook vulnerability reminiscent of the decade-old “BadWinmail” flaw that allowed attacks with no user interaction. Enterprises should prioritize this patch across Outlook deployments and review mail gateway hardening and attachment handling, given the vulnerability’s high potential for mass exploitation. The update lands amid a broader Patch Tuesday wave addressing more than a hundred flaws.

Source: SecurityWeek


18-year-old NGINX rewrite module flaw enables unauthenticated RCE/DoS (CVE-2026-42945)

Researchers disclosed a heap buffer overflow in NGINX’s ngx_http_rewrite_module that went undetected for 18 years, enabling remote code execution or denial-of-service without authentication. Given NGINX’s massive footprint across the internet, organizations should urgently assess exposure, apply vendor fixes/workarounds, and increase monitoring for anomalous HTTP traffic and crashes.

Source: The Hacker News


Two new Windows zero-days: “YellowKey” BitLocker bypass and “GreenPlasma” privilege escalation

An independent researcher dropped two unpatched Windows flaws: YellowKey, a BitLocker bypass requiring physical access that raises the risk profile of stolen or lost laptops, and GreenPlasma, which elevates privileges to SYSTEM. While official fixes are pending, defenders should enforce strong pre-boot protections (TPM+PIN), secure boot, device encryption policies, and tighten physical access controls, especially for mobile/remote fleets.

Source: SecurityWeek


From Teams chat to domain compromise: Rapid7 dissects ModeloRAT intrusions

Rapid7 detailed an April 2026 attack that began with a fake “IT Support” message over Microsoft Teams and escalated via a Dropbox-hosted portable Python payload (ModeloRAT), exploitation of CVE-2023-36036 for SYSTEM, a fake Windows lock screen to harvest credentials, and stealthy WebDAV-based credential validation. The campaign underscores how collaboration platforms, identity abuse, and Living-off-the-Land tooling let attackers rapidly pivot from endpoint to enterprise-wide identity compromise.

Source: Rapid7


Ransomware gang “Gentlemen” hacked: leak reveals operators, tactics, and edge-device focus

Check Point’s analysis of a May 2026 breach of the “Gentlemen” RaaS operation shows a program with 400+ public victims—making it the #2 ransomware group this year—run by ~nine operators under a single admin tied to Qilin. The leak confirms initial access is largely via unpatched edge devices or bought credentials, reinforcing the need to aggressively patch internet-facing gear, lock down remote access, and monitor for credential abuse.

Source: Check Point Blog


Foxconn confirms cyberattack at North American factories; Nitrogen claims 8TB data theft

Electronics giant Foxconn disclosed a cyberattack impacting several North American facilities. The Nitrogen ransomware group claims it stole 8TB of data, including confidential documents, highlighting the persistent risk to complex manufacturing supply chains and the importance of segmented networks, hardened OT/IT boundaries, and robust backup/exfiltration detection controls.

Source: SecurityWeek


RubyGems suspends new registrations after flood of malicious packages targets registry

RubyGems temporarily halted new account and gem registrations after more than 500 malicious packages were pushed in a campaign that appears to target the registry itself rather than end users. The incident is another reminder to lock down CI/CD pipelines, enforce MFA and signing, and pin/verify package sources to reduce software supply-chain risk.

Source: SecurityWeek


You May Also Be Interested In...
UK moves to shield security researchers in cybercrime law overhaul
New “Fragnesia” Linux kernel LPE grants root via page cache corruption
F5 patches over 50 vulnerabilities across BIG-IP, BIG-IQ, and NGINX
Cybersecurity — May 14, 2026 | Briefing24