Big Tech
Big Tech analyzes decisions by major platforms and their impact on security, privacy, infrastructure and the market. The cluster connects product announcements, strategic changes and technical consequences for users and businesses.

APT29 Hits Hotel Wi-Fi: Steals M365 Credentials with Malware
Microsoft attributes the CaptiveCrunch campaign to Storm-2945, a Midnight Blizzard sub-group, which compromises hotel captive portals…

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them
In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…

The Microsoft 365 Account Takeover That Leaves No Trace
Proofpoint tracks active campaigns since September 2025 that abuse Microsoft's OAuth 2.0 device authorization grant flow. MFA is bypas…

June 2026 Patch Tuesday: Microsoft's Largest Ever, With Three Publicly Disclosed Zero-Days
Microsoft fixed nearly 200 vulnerabilities in the June 2026 Patch Tuesday, the most voluminous monthly cycle in the company's history.…

Chrome's Fifth 2026 Zero-Day: Google Issues Emergency Patch for Actively Exploited V8 Flaw
Google released an emergency update on June 8, 2026, for CVE-2026-11645, an out-of-bounds vulnerability in the V8 JavaScript engine al…

Swiss Federal SharePoint Breach Compromises 200 Accounts
The Federal Office for Information Technology and Telecommunication (BIT/FOITT) confirms exploitation of already-patched SharePoint fl…

DarkSword Exposes the Hidden iOS Exploit Market: Zero-Days in the Wild
DarkSword exploits six Apple vulnerabilities — three zero-days — to achieve full iPhone takeover. Three threat groups of differing geo…

Amazon Attributes Four NPM Supply-Chain Attacks to North Korean Hackers
Amazon Threat Intelligence links the compromise of axios, debug, chalk, and typo-crypto to a North Korean group tracked as SAPPHIRE SL…

CaptiveCrunch: Midnight Blizzard Turns Hotel Wi-Fi into an APT Delivery Vector
Microsoft Threat Intelligence has exposed CaptiveCrunch, a Storm-2945 campaign that weaponizes hotel captive portals to deliver the Co…

Greatness PhaaS Bypasses M365 MFA by Abusing Whitelists
The Greatness Phishing-as-a-Service platform has evolved beyond credential theft to advanced adversary-in-the-middle and device-code p…

Apple Releases iOS 18.6.2: Zero-Click Spyware Patch for Active ImageIO Exploit
On August 20, 2025, Apple patched CVE-2025-43300, an out-of-bounds write in the ImageIO framework exploited in spyware attacks against…

Samsung Patches Android Zero-Day Discovered by Meta: The Invisible Chain of Responsibility
Samsung has patched CVE-2025-21043, an out-of-bounds write in libimagecodec.quram.so enabling remote code execution. The flaw was repo…