Cyber Threat Pulse · May 29 Daily Digest
Zero-Day Disclosure Risks
- 🔥 Microsoft Warning: Microsoft warned against public release of zero-day details before vendor coordination, citing...

Created by Elhanan Abrams
48‑hour breach, ransomware, zero‑day intel for critical infrastructure and government
Explore the latest content tracked by Cyber Threat Pulse
Unpatched vulnerabilities continue driving both data theft and ransomware campaigns.
Microsoft calls uncoordinated zero-day disclosures never justifiable, as they hand threat actors immediate attack vectors before patches exist and...
No significant updates today.
No significant updates today.
Attackers are hitting trusted tools and supply chains simultaneously, forcing IR teams to rethink single-vendor reliance.
The European Central Bank is convening banks to remediate systemic cybersecurity flaws that AI models like Mythos continue to uncover.
Anthropic's Mythos model discovered over 10,000 high or critical zero-day vulnerabilities in a single week across Apple, AWS, Google, Microsoft,...
Two unpatched Microsoft Defender zero-days remain under active exploitation by hands-on attackers, enabling local privilege escalation to SYSTEM level...
Unpatched Chromium flaw turns browsers into reboot-surviving botnets after Google leaked exploit code, hitting 70% of UK businesses. Dutch raids...
Qilin ransomware struck Eyguières Town Hall on May 22, disrupting municipal systems and exposing resident data to risk.
Law enforcement continues disrupting ransomware infrastructure even as attacks persist.
Endpoint security tools face active exploitation, turning trusted defenses into attack surfaces.
A public GitHub repo labeled “CISA-Private” leaked internal DHS/CISA credentials, cloud keys, tokens, and plaintext passwords—likely due to a...
Adversaries are actively weaponizing the unpatched MiniPlasma zero-day to bypass traditional endpoint security. Continuous network visibility is essential for detection until patches are available.
Unauthenticated attackers can exploit CVE-2026-20223 in Cisco Secure Workload's internal REST APIs to seize full Site Admin privileges across cloud...