# SANS Stormcast Tuesday, May 19th, 2026: New libssh in Malware; Exchange 0-Day; MSFT Authenticator Update (#) Page: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-tuesday-may-19th-2026-new-libssh-in-malware-exchange-0-day-msft-authenticator-update Text version: https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-tuesday-may-19th-2026-new-libssh-in-malware-exchange-0-day-msft-authenticator-update.md Podcast: [SANS Internet Storm Center's Daily Network Security News Podcast](https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820) Published: 2026-05-18T21:43:02+00:00 Episode link: https://mp3.sans.edu/sans-stormcast-tuesday-may-19th-2026-new-libssh-in-malware-exchange-0-day-msft-authenticator-update Audio file: https://traffic.libsyn.com/secure/securitypodcast/9936.mp3?dest-id=448030 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/episodes/sans-stormcast-tuesday-may-19th-2026-new-libssh-in-malware-exchange-0-day-msft-authenticator-update Duration seconds: 369 ## Resource SANS Stormcast Tuesday, May 19th, 2026: New libssh in Malware; Exchange 0-Day; MSFT Authenticator Update New Malware Libraries means New Signatures https://isc.sans.edu/diary/%5BGuest%20Diary%5D%20%20New%20Malware%20Libraries%20means%20New%20Signatures/32986 Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 https://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498 Microsoft Authenticator Update CVE-2026-41615 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41615 ssh-keysign-pwn (CVE-2026-46333) Patches Released https://almalinux.org/blog/2026-05-15-ssh-keysign-pwn-cve-2026-46333/ keywords: ssh-keysign-pwn; ssh; authenticator; exchange; malware; ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/episodes/sans-stormcast-tuesday-may-19th-2026-new-libssh-in-malware-exchange-0-day-msft-authenticator-update/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/sans-internet-storm-center-s-daily-network-security-news-podcast-2484820/sans-stormcast-tuesday-may-19th-2026-new-libssh-in-malware-exchange-0-day-msft-authenticator-update.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.