meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS Stormcast Wednesday, May 13th, 2026: Microsoft Patch Tuesday; Large npm/pypi Compromise; Rubygems Attack

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 13 May 2026

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. SANS Stormcast Wednesday, May 13th, 2026: Microsoft Patch Tuesday; Large npm/pypi Compromise; Rubygems Attack

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, May 13th,

0:07.4

2026 edition of the Sands Internet Stormsunters Stormcast.

0:12.4

My name is Johannes Ulrich, recording today from San Diego, California.

0:18.2

And this episode is brought you by the sands.edu credit certificate program in cyber security leadership.

0:24.6

Well, today, Microsoft Patch Tuesday, so let's start with a quick summary here.

0:30.6

We got a total of 137 vulnerabilities being addressed by Microsoft.

0:36.6

Now, this is quite a large number, but in addition to this, we actually also got 127 chromium

0:43.3

vulnerabilities being addressed in Microsoft Edge.

0:47.3

Now when it comes to the Microsoft vulnerability, so the 137, you had 30 critical ones here. That's a fairly large number compared

0:56.7

to what we saw in the past, but 14 of these 30, so pretty much half of them, do not require

1:03.9

any customer action, because these vulnerabilities are vulnerabilities in Microsoft Cloud

1:09.3

systems, and as such, of course, there's nothing you have to do.

1:13.1

Microsoft already took care of these for you.

1:17.1

Now, among the remaining critical vulnerabilities,

1:20.3

there are couples of that caught my eye.

1:22.4

One actually that I haven't listed in the diary is one in Outlook.

1:26.6

That's a remote code execution vulnerability

1:28.7

that could be triggered by just previewing an email, so no attachment that you need to open.

1:35.2

There is also a vulnerability in the Microsoft single sign-on plugin for GERA and Confluence.

1:42.1

Given all the news we had about supply chain issues and such,

1:47.0

that's certainly something to watch out for.

1:49.7

The other one that I thought was kind of interesting

...

Transcript will be available on the free plan in 5 days. Upgrade to see the full transcript now.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.