THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

2 min read

AI-assisted briefingHow we put it together ↗
Critical NGINX flaw (CVE-2026-42945) is being actively exploited

Attackers have begun exploiting a critical vulnerability in NGINX that can cause denial-of-service on default configurations and enable remote code execution when ASLR is disabled. Given NGINX’s ubiquity, admins should prioritize updates, apply vendor workarounds immediately, and monitor for worker crashes and anomalous HTTP requests.

Source: SecurityWeek


Grafana confirms GitHub token breach and code theft, rejects ransom

Grafana disclosed that attackers used a compromised GitHub token to download its codebase and attempted extortion, with the group “Coinbase Cartel” claiming credit and links to ShinyHunters/Scattered Spider/Lapsus$. The company reports no customer data or systems were impacted; organizations should rotate tokens, audit GitHub logs, and re-check CI/CD secrets exposure.

Source: SecurityWeek


Researcher drops ‘MiniPlasma’ Windows exploit reviving unpatched 2020 CVE

A new PoC dubbed MiniPlasma enables SYSTEM-level privilege escalation on fully patched Windows systems, suggesting a 2020 fix (CVE-2020-17103) remains incomplete. The flaw targets the Windows Cloud Files Mini Filter Driver (cldflt.sys); until a patch ships, limit local admin rights, harden privilege paths, and watch for suspicious elevation attempts.

Source: SecurityWeek


Shai-Hulud worm clones emerge to hit NPM developers

Threat actors have started weaponizing recently released Shai-Hulud source code in real-world attacks against NPM developers. Development teams should enable 2FA on package registries, lock and pin dependencies, enforce package signing where possible, and scan for typosquatted and malicious modules entering build pipelines.

Source: SecurityWeek


Attackers exploit WordPress Funnel Builder bug to skim WooCommerce payments

Active exploitation of a critical flaw in Funnel Builder by FunnelKit is enabling attackers to inject e‑skimming JavaScript into WooCommerce checkout pages. Merchants should update the plugin immediately, inspect templates and checkout flows for injected code, rotate payment keys, and review server logs for suspicious admin actions.

Source: Security Affairs


Microsoft Exchange zero-day under active attack—enable Emergency Mitigation

Microsoft and CISA warn of an Exchange zero-day being actively exploited, urging admins to apply emergency mitigations immediately. Organizations should enable Exchange Emergency Mitigation, review exposure of OWA/ECP, audit logs for exploitation indicators, and follow Microsoft’s guidance for durable fixes once available.

Source: Forbes Security


Pwn2Own Berlin 2026: $1.3M paid for exploits across Windows, Linux, VMware, Nvidia, and AI

Researchers earned $1.3 million by demonstrating fresh exploits spanning major enterprise platforms and AI products, underscoring a coming wave of vendor patches. Security teams should track advisories from affected vendors and Trend Micro’s Zero Day Initiative, prioritize patch testing, and apply updates quickly.

Source: SecurityWeek


You May Also Be Interested In...

Pre-Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations
Torvalds: AI-found bug reports are swamping Linux security workflows
Agentic AI Expands Enterprise Attack Surface, Warns NCSC
Cybersecurity — May 18, 2026 | Briefing24