New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released

2026-05-18T01:23:27Z497779e5af64aa41a3c5369793b70ee591d65e83df0671fc0783cfeab319d20c
aksavada-builderazurebotnetburst-statisticscredential-theftdevice-code-phishingexchangefunnel-builderinfostealerkazuarmicrosoft-365miniPlasmanode-ipcnpmp2pphishingprivilege-escalationproof-of-conceptremussupply-chainwindowswordpressxss','edge-passwords-in-memory','driver-rollback','pwn2own','te-zero-day

What happened

Multiple high-risk security developments reported by BleepingComputer: a new Windows privilege-escalation zero-day called “MiniPlasma” has a public proof-of-concept that yields SYSTEM on fully patched hosts; the Tycoon2FA phishing kit now supports device-code phishing to hijack Microsoft 365 accounts; a researcher alleges Microsoft silently fixed an Azure Backup for AKS issue without issuing a CVE; the Kazuar backdoor has been refactored into a modular P2P botnet by the Secret Blizzard group; several WordPress plugins (Funnel Builder, Avada Builder, Burst Statistics) are being actively abused—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
497779e5af64aa41a3c5369793b70ee591d65e83df0671fc0783cfeab319d20c
Enrichment time
2026-05-18T01:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.