Daily Digest

Windows Zero-Days Leaked, Exchange Under Active Attack, and Vulnerability Exploits Overtake Credential Theft in Breaches

Windows Zero-Days Leaked, Exchange Under Active Attack, and Vulnerability Exploits Overtake Credential Theft in Breaches

May 20, 2026
12 articles (7 new, 5 updated)
36 min read

Summary

A tumultuous day in cybersecurity for May 20, 2026, is marked by the active exploitation of a new Microsoft Exchange zero-day (CVE-2026-42897) and the public leak of six Windows zero-day exploits by a threat actor dubbed 'Nightmare-Eclipse'. Verizon's 2026 DBIR confirms a strategic shift in the threat landscape, with vulnerability exploitation now the top initial access vector in breaches, surpassing stolen credentials for the first time. Major data breaches continue to plague critical sectors, with NYC Health + Hospitals reporting a potential impact on 1.8 million individuals and BWH Hotels confirming a long-term intrusion. Ransomware attacks also persist, hitting West Pharmaceutical Services and a new 'WantToCry' variant abusing SMB for remote encryption.

Filter by Category

New Articles (7)

Updated Articles (5)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.