
Microsoft Releases Patches for 137 Vulnerabilities Amid Supply Chain Attacks
🎬 On May 13, 2026, Microsoft released patches addressing 137 vulnerabilities, including 30 critical ones, with 14 requiring no customer action as they affected Microsoft cloud systems. Notable critical vulnerabilities included a remote code execution flaw in Outlook triggered by previewing an email, a vulnerability in the Microsoft single sign-on plugin for Jira and Confluence, and a remote code execution issue in the Netlogon service. Additionally, Microsoft Edge patched 127 Chromium vulnerabilities, though none of the patched flaws were actively exploited or disclosed as zero-days. Concurrently, a surge in supply chain attacks targeted npm and Python packages, with 84 compromised packages initially tied to Tanstack, a widely used npm library, before spreading to others like OpenSearch and Guardrails AI. Attackers exploited GitHub actions to compromise credentials, exfiltrate tokens, and deploy time-bomb malware that wipes systems if tokens are revoked. RubyGems also suspended new account signups due to a flood of malicious packages, indicating broader attacks across multiple programming ecosystems. The video advised caution in updating software components temporarily, particularly for npm and Python, unless addressing urgent vulnerabilities.