SANS Stormcast Thursday, May 14th, 2026: Flexbile Windows Proxy; News from Nightmare Eclipse; A…

https://www.youtube.com/watch?v=-T1x8rCIblA

#vulnerability #exploit #securitypatch

SANS Stormcast Thursday, May 14th, 2026: Flexbile Windows Proxy; News from Nightmare Eclipse; A…

YouTube
Espanso 2.3.0 Shell and Script Extension Arbitrary Command Execution https://packetstorm.news/files/220990 #exploit
Packet Storm

Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers

Espanso 2.3.0 Shell Extension Arbitrary Command Execution https://packetstorm.news/files/220989 #exploit
Packet Storm

Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers

Event Booking Calendar 5.0 Cross Site Scripting https://packetstorm.news/files/220962 #exploit
Packet Storm

Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers

Shai-Hulud Worm Open-Sourced https://packetstorm.news/files/220934 #exploit
Packet Storm

Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers

Fragnesia Universal Linux Local Privilege Escalation https://packetstorm.news/files/220922 #exploit
Packet Storm

Information Security Services, News, Files, Tools, Exploits, Advisories, and Whitepapers

Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor | Tom's Hardware

#microsoft #bitlocker #encryption #exploit #zeroday

https://www.tomshardware.com/tech-industry/cyber-security/microsoft-bitlocker-protected-drives-can-now-be-opened-with-just-some-files-on-a-usb-stick-yellowkey-zero-day-exploit-demonstrates-an-apparent-backdoor

Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor

Also, it's a twofer with the GreenPlasma zero-day local privilege escalation.

Tom's Hardware
EntryPoint Hijacking

The technique of EntryPoint Hijacking introduces a stealthier approach to code injection as it doesn’t use API calls that create a new thread within the context of a process, and it independe…

Purple Team
Disgruntled researcher releases two more Microsoft zero-days

Security pros warn YellowKey claim could make stolen laptops a much bigger problem

theregister