Daily Digest

Active Zero-Day Exploits Target Microsoft Defender & Windows; Widespread Supply Chain Attacks Hit Open-Source Ecosystems

Active Zero-Day Exploits Target Microsoft Defender & Windows; Widespread Supply Chain Attacks Hit Open-Source Ecosystems

May 23, 2026
10 articles (5 new, 5 updated)
30 min read

Summary

This week's cybersecurity landscape is dominated by the active exploitation of critical zero-day vulnerabilities in Microsoft products, including two in Defender and a new unpatched flaw in Windows dubbed 'MiniPlasma'. Concurrently, multiple sophisticated supply chain attacks have compromised hundreds of open-source packages across npm, PyPI, and Packagist, deploying credential-stealing worms and malware. New ransomware strains like 'Aur0ra' are emerging with dual-extortion tactics, while Iran-linked APTs escalate espionage campaigns, highlighting a period of heightened risk across software supply chains, endpoint security, and critical infrastructure.

Filter by Category

New Articles (5)

Updated Articles (5)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.