Security Brief Daily

May 20, 2026 · #62


Listen Later

Episode 62

Security Brief Daily | 20 May 2026

In This Episode
  • Microsoft shares mitigation for YellowKey Windows zero-dayBleeping Computer
    Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives. The security flaw was disclosed last week by an anonymous security researcher known as 'Nightmare Eclipse,' who described it...
  • Grafana GitHub Breach Exposes Source Code via TanStack npm AttackThe Hacker News
    Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It said the scope of the incident is limited to the Grafana Labs GitHub environment, which includes public and private...
  • Max-severity flaw in ChromaDB for AI apps allows server hijackingBleeping Computer
    A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers. The flaw is tracked as CVE-2026-45829 and was reported to ChromaDB on February 17. It received the maximum...
  • GitHub confirms breach of 3,800 repos via malicious VSCode extensionBleeping Computer
    GitHub has confirmed that roughly 3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension. The company has since removed the unnamed trojanized extension from the VS Code marketplace and has secured the compromised device....
  • Cybercrime service disrupted for abusing Microsoft platform to sign malwareBleeping Computer
    Microsoft says it has disrupted a malware-signing-as-a-service (MSaaS) operation that abused the company's Artifact Signing service to generate fraudulent code-signing certificates used by ransomware gangs and other cybercriminals. According to a report published today by...
  • DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE VulnerabilityThe Hacker News
    Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE). Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12...
  • Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation FlawsThe Hacker News
    Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS...
  • ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and MoreThe Hacker News
    Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted. The pattern is clear....
  • Security Brief Daily is an AI-generated cybersecurity news podcast. Always verify critical information with primary sources.

    ...more
    View all episodesView all episodes
    Download on the App Store

    Security Brief DailyBy Security Brief Daily