Microsoft's MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday
2026-05-14T01:24:07Z•e45ca9cd2cdd6aad91a3a6cf1f9d9106bedbb22c1b21dadbf49034ec3f9d3b89
active-exploitationaicpaneleximfamoussparrowgemstuffermalwaremicrosoftollamapatch-managementrubygemssupply-chainsupply-chain-attackteampcptrickmovulnerability-disclosurezero-day
What happened
A batch of high‑impact security stories: Microsoft unveiled MDASH (and OpenAI launched Daybreak) — AI-driven systems for vulnerability discovery/remediation — while Microsoft pushed fixes for 138 bugs. Multiple actively exploited or severe vulnerabilities were reported: cPanel CVE-2026-41940 is being used in the wild to deploy a Filemanager backdoor; Exim’s BDAT flaw (CVE-2026-45185, “Dead.Letter”) is a use‑after‑free that can lead to memory corruption/RCE; Ollama suffers a critical out‑of‑bounds read (CVE-2026-7482, “Bleeding Llama”, CVSS 9.1) allowing remote process memory leaks; and cPanel/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- e45ca9cd2cdd6aad91a3a6cf1f9d9106bedbb22c1b21dadbf49034ec3f9d3b89
- Enrichment time
- 2026-05-14T01:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.