惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

www.infosecurity-magazine.com

Chinese Threat Actors Ditch Static Phishing Pages for Live Credential Interception BTMOB Android RAT Spreads Through No-Code Builder Tooling Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens Fake Streams, Counterfeit Merch and Other Scams: How Fraudsters Target F1 Fans Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning Apple Blocked $2.2bn in App Store Fraud in the Last Year Cybercriminal VPN Dismantled in Europol Crackdown GitHub Breach Traced to Malicious 'Nx Console' VS Code Extension Three-Quarters of Firms Knowingly Ship Vulnerable Code Nine-Year-Old Linux Kernel Flaw Leaks SSH Keys and Password Hashes Grafana Labs Says Code Breach Stemmed from TanStack Attack Android Malware Campaign Used Hundreds of Fake Apps to Silently Charge Users Mini Shai-Hulud Hits Hundreds of npm Packages in AntV Ecosystem China-Linked Webworm APT Evolves Tactics, Expands to European Targets GitHub Confirms Breach of Internal Repositories Via Malicious VS Code Extension Researchers Warn CypherLoc Scareware Has Targeted Millions of Users Verizon DBIR: Vulnerability Exploits Overtake Credentials as Top Access Vector Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool AI Raises the Bar on Vulnerability Awareness and Secure-by-Design Software Agentic AI Accelerates Software Builds and Mobile App Attacks Grafana Labs Confirms Hackers Stole Source Code Hackers Bypass Security Tools to Target Users Directly Interpol Launches Sweeping Cybercrime Crackdown in MENA Region The Infosecurity Europe Cyber Startup Competition: Meet the Finalists NCSC Publishes Guidance on Securing Agentic AI Use Security Researchers Find 47 Zero-Days at Pwn2Own Berlin Bank of England, FCA and Treasury Raise Alarm Over Frontier AI Gremlin Stealer Evolves into Modular Threat with Advanced Evasion Capabilities Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers China-Linked Hackers Deploy New TencShell Malware Against Global Manufacturer Mustang Panda Linked to Updated FDMTP Backdoor in Asia-Pacific Espionage Campaign New Fragnesia Flaw Hands Linux Local Users Root Access ICO Publishes Five-Step Plan to Counter Emerging AI-Powered Attacks Canvas Owner Reaches Agreement With Cybercriminals After Ransomware Attack Avada Builder Flaws Expose One Million WordPress Sites Ransomware: Over Half of CISOs Would Consider Paying Ransom to Hackers Global Cyber Agencies Issue New SBOMs for AI Guidance to Tackle AI Supply Chain Risks UK Cybersecurity Market Expands to £14.7bn with Strong Growth in AI Security Firms Mini Shai-Hulud Hits TanStack npm Packages End‑to‑End Encrypted RCS Messaging Arrives Across iPhone and Android Attackers Combine ClickFix With PySoxy Proxying to Maintain Persistence Malicious Hugging Face Repository Typosquats OpenAI South Staffordshire Water Fined £1m After Data Breach TrickMo Variant Routes Android Trojan Traffic Through TON Rushed Patches Follow Broken Embargo on New Linux Kernel Vulnerabilities Fake Claude Code Page Pushes PowerShell Stealer at Devs Hackers Observed Using AI to Develop Zero-Day for the First Time US: FCC Relaxes Foreign-Made Router Ban to Allow for Security Updates ShinyHunters Escalates Canvas Extortion with School by School Ransom Campaign Zara Data Breach Impacts Nearly 200,000 Customers Police Shut Relaunched Crimenetwork Dark Web Marketplace Australian Cyber Security Centre Issues Alert Over ClickFix Attacks PCPJack Campaign Boots TeamPCP Off Compromised Machines Legacy Security Tools Are Failing Data Protection, Capital One Software Report Finds Cline Kanban Flaw Lets Websites Hijack AI Coding Agents OpenAI and Anthropic LLMs Used in Critical Infrastructure Cyber-Attack, Warns Dragos Fake Claude AI Site Drops Beagle Backdoor on Windows Users Daemon Tools Developer Confirms Software Was Trojanized Researchers Spot Uptick in Use of Vercel for Phishing Campaigns CloudZ Malware Abuses Phone Link to Steal SMS OTPs CISA Urges Critical Infrastructure Providers to Make Plans to Remain Operational if hit by Cyber-Attack Iran-Linked APT Posed as Chaos Ransomware Member in Espionage Campaign One in Eight Workers Has Sold Their Corporate Logins Microsoft Flags Mass Phishing Campaign Using Fake Compliance Emails North Korean APT Targets Yanbian Gamers via Trojanized Platform Fake SSA Emails Drive Venomous#Helper Phishing Campaign AI Adoption Outpaces Safety Policies, Leaving Organizations Exposed to Cyber Risk NCSC Warns of an AI-Fuelled “Vulnerability Patch Wave” Trellix Reveals Unauthorized Access to Source Code Small Defense Firms Lack Network Data to Stop Nation-State Hackers, Analyst Says OpenAI To Extend Cyber Program to Government Agencies Anthropic Rolls Out Claude Security for AI Vulnerability Scanning Two American Cybersecurity Workers Jailed for BlackCat Ransomware Attacks Nine-Year-Old Zero-Day Flaw in Linux Kernel Discovered by AI-Equipped Security Researcher Three Arrested for Hacking Over 610,000 Roblox Accounts Deep#Door Python Backdoor Evades Detection On Windows CISA and Partners Publish Zero Trust Guidance For OT Security UK: Education Sector Faces Surge in Cyber Breaches Despite Stable National Threat Levels Europol Busts Albanian Scam Call Centers in Major Online Fraud Case Cyber is the Number One Global “People Risk,” Says Marsh Cursor Extension Flaw Exposes Developer API Keys Malicious npm Dependency Linked to AI Assisted Commit Targets Crypto Wallets Researchers Track 2.9 Billion Compromised Credentials Critical Flaw Turns Vect Ransomware into Data Destroying Wiper A Quarter of Healthcare Organizations Report Medical Device Cyber-Attacks Medtronic Confirms Data Breach After ShinyHunters Claims Ransomware Turf War as 0APT and KryBit Groups Trade Blows Chinese National Extradited Over Silk Typhoon Cyber Campaign No Metrics Are Better Than Bad Metrics in the SOC, Says NCSC North Korean Hackers Target Crypto Firms with ClickFix and AI-Made Zoom Lures US Sanctions Target Cambodian Scam Network Leaders Utilities Tech Supplier Itron Discloses Cyber-Attack, Operations Unaffected Widely Used Browser Extensions Selling User Data Most Cybersecurity Professionals Feel Undervalued and Underpaid Researchers Identify Fast16 Sabotage Malware That Pre-Dates Stuxnet BlackFile Group Targets Retail and Hospitality with Vishing Attacks UK Biobank Data Breach: Health Data of 500,000 Listed for Sale in China AI Rush is Reviving Old Cybersecurity Mistakes, Mandiant VP Warns Npm Supply Chain Malware Attack Targets Developers With Worm-Like Propagation
Microsoft Fixes 17 Critical Flaws in May Patch Tuesday
2026-05-13 · via www.infosecurity-magazine.com

Photo of Phil Muncaster

Microsoft has published security updates to fix 120 CVEs in the May Patch Tuesday, 16 of which were discovered by a new multi-model agentic security system.

The overall list included 17 critical vulnerabilities, 14 of which were classed as remote code execution (RCE), two were elevation of privilege (EoP) flaws and one was an information disclosure vulnerability.

In total, the majority of the 120 CVEs listed were EoP (61), RCE (31) and information disclosure (14).

Read more on Patch Tuesday: Microsoft Fixes Two Zero-Days in April Patch Tuesday

Adam Barnett, principal software engineer at Rapid7, urged “anyone responsible for securing a domain controller” to prioritize CVE-2026-41089 for remediation.

It’s a critical stack-based buffer overflow in Windows Netlogon with a CVSS v3 base score of 9.8 which could give attackers system privileges on the domain controller, Barnett warned.

“For most pentesters, that’s the point at which the customer report more or less writes itself,” he continued. “No privileges or user interaction are required, and attack complexity is low, which suggests that creation of a reliable exploit might not be especially difficult for anyone with knowledge of the specific mechanism.”

Also top of mind for sysadmins should be CVE-2026-41096 – a critical RCE in the Windows DNS client implementation with a CVSS score of 9.8.

“Because DNS is a core networking service used across enterprise environments, exploitation could impact a large number of systems rapidly,” warned Action1 director of vulnerability research, Jack Bicer. “Successful attacks may lead to widespread endpoint compromise, ransomware deployment, credential harvesting, and operational disruption across corporate networks.” 

Bicer also flagged CVE-2026-42898, a critical RCE bug in Microsoft Dynamics 365 On-Premises. It could allow an authenticated attacker with low privileges to execute malicious code over the network by manipulating process session data within Dynamics CRM.

“With no user interaction required, and the potential to impact systems beyond the vulnerable component's original security scope, this vulnerability poses serious enterprise risk,” he continued. “An attacker with only basic access could turn a business application server into a remote execution platform.”

The Benefits of AI-Powered Vulnerability Research

Rapid7’s Barnett noted that Microsoft’s Windows Attack Research and Protection (WARP) team is credited with multiple critical vulnerabilities. “We can speculate that they likely know a great deal about the current state of AI-powered vulnerability research as it applies to Microsoft products,” he suggested.

Microsoft explained in a blog post published on 12 May how WARP collaborated with the firm’s Autonomous Code Security (ACS) on a new agentic AI initiative which discovered 16 CVEs listed in this month’s Patch Tuesday.

Taesoo Kim, VP of agentic security at Microsoft, explained that the new “agentic security harness” system, codenamed MDASH, uses over 100 specialized agents across multiple models to find novel vulnerabilities.

“The multi-model agentic scanning harness runs a configurable panel of models. That includes SOTA models as the heavy reasoner, distilled models as a cost-effective debater for high-volume passes, and a second separate SOTA model as an independent counterpoint,” he said.

“Disagreement between models is itself a signal: when an auditor flags something as suspect and the debater can’t refute it, that finding’s posterior credibility goes up.”