Microsoft Warns of Two Actively Exploited Defender Vulnerabilities
2026-05-21T13:24:10Z•2a9bd2081ea6faa43c905ae980877d425fb2ffa3e6d6c241accba831c0ddae28
active-exploitationbitlockerdrupalgithub-breachincident-responselinux-kernelmicrosoft-defendernpm-compromiseprivilege-escalationproof-of-conceptremote-code-executionseppmailsupply-chainthreat-actorvscode-extensionvulnerability-disclosurewindowszero-day
What happened
A batch of high-impact security reports: Microsoft disclosed two actively exploited Microsoft Defender flaws (including privilege-escalation CVE-2026-41091, CVSS 7.8). Multiple supply-chain and developer‑tool compromises were reported — GitHub internal repos exfiltrated following a poisoned Nx Console VS Code extension (rwl.angular-console 18.95.0) and other attacks on GitHub Actions and npm packages (TanStack/AntV, Mini Shai‑Hulud). Drupal Core has a critical database‑API vulnerability (CVE-2026-9082) enabling RCE, and a long‑undetected Linux kernel flaw (CVE-2026-46333) allows local LPE. PoC
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 2a9bd2081ea6faa43c905ae980877d425fb2ffa3e6d6c241accba831c0ddae28
- Enrichment time
- 2026-05-21T13:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.