Daily Digest

Windows Zero-Days Expose Systems, Critical NGINX Flaw Under Active Attack, and State-Sponsored Ransomware Targets OT

Windows Zero-Days Expose Systems, Critical NGINX Flaw Under Active Attack, and State-Sponsored Ransomware Targets OT

May 18, 2026
12 articles (5 new, 7 updated)
36 min read

Summary

This week in cybersecurity, researchers disclosed multiple Windows zero-day vulnerabilities, including 'MiniPlasma' and 'YellowKey,' granting attackers full system access and bypassing BitLocker encryption. A critical 18-year-old flaw in NGINX, 'NGINX Rift,' is now under active exploitation, threatening millions of web servers. The line between cybercrime and nation-state attacks continues to blur as Iran-aligned actors weaponize ransomware against critical infrastructure. Additionally, a logical flaw in the Verus-Ethereum bridge led to an $11.5 million theft, and a widespread supply chain attack compromised popular open-source packages.

Filter by Category

New Articles (5)

Updated Articles (7)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.