# Exchange Zero-Day Under Attack, Ransomware Gets Smarter, Fortinet Critical Flaws Page: https://stenobird.com/podcast/cybersecurity-today-65508/exchange-zero-day-under-attack-ransomware-gets-smarter-fortinet-critical-flaws Text version: https://stenobird.com/podcast/cybersecurity-today-65508/exchange-zero-day-under-attack-ransomware-gets-smarter-fortinet-critical-flaws.md Podcast: [Cybersecurity Today](https://stenobird.com/podcast/cybersecurity-today-65508) Published: 2026-05-19T03:53:00+00:00 Episode link: https://cybersecuritytoday.libsyn.com/exchange-zero-day-under-attack-ransomware-gets-smarter-fortinet-critical-flaws Audio file: https://traffic.libsyn.com/secure/cybersecuritytoday/Cybersecurity_Today__Tuesday_May_19.mp3?dest-id=679928 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/exchange-zero-day-under-attack-ransomware-gets-smarter-fortinet-critical-flaws Duration seconds: 768 ## Resource A dangerous new Microsoft Exchange zero-day is being actively exploited, ransomware gangs are adopting nation-state-style tactics, two fired contractors were caught deleting U.S. government databases after accidentally recording themselves on Microsoft Teams, and Fortinet has patched critical remote code execution flaws. In this episode of Cybersecurity Today, David Shipley breaks down four major cybersecurity stories that security teams need to know. Cybersecurity Today would like to thank Material Security for supporting this podcast. Material security provides. faster, more complete detection and response for email, identity, and data threats inside Google Workspace and Microsoft 365. Contact them at material[dot]security Microsoft has confirmed active exploitation of a new Exchange Server zero-day, CVE-2026-42897, affecting Exchange Server 2016, Exchange Server 2019, and Exchange Subscription Edition. There is currently no patch, only mitigations through the Exchange Emergency Mitigation Service, with some trade-offs for Outlook Web App users. Security researcher Marcus Hutchins highlights an unusually disciplined ransomware affiliate operation using tradecraft more commonly associated with nation-state attackers, including a custom SentinelOne endpoint detection and response (EDR) killer and a stripped-down toolset designed to leave fewer forensic traces. In one of the more astonishing insider threat stories of the week, former OPEX Corporation contractors Muneeb and Sohaib Akhtar were allegedly caught deleting 96 U.S. government databases after leaving a Microsoft Teams recording running. Also in this episode: Fortinet has released urgent patches for critical unauthenticated remote code execution vulnerabilities in FortiAuthenticator (CVE-2026-44277) and FortiSan… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cybersecurity-today-65508/episodes/exchange-zero-day-under-attack-ransomware-gets-smarter-fortinet-critical-flaws/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cybersecurity-today-65508/exchange-zero-day-under-attack-ransomware-gets-smarter-fortinet-critical-flaws.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.