Big Tech
Big Tech analyzes decisions by major platforms and their impact on security, privacy, infrastructure and the market. The cluster connects product announcements, strategic changes and technical consequences for users and businesses.

Microsoft Corrects Course: CVE-2026-69836 Was CVSS 10, But Not Exploited
Microsoft reclassified CVE-2026-69836, a critical Entra ID flaw, retracting its initial claim of active exploitation. The episode rais…

CVE-2024-9042: SYSTEM-Level RCE on Kubernetes Windows Nodes via a Single curl Request
A vulnerability in Kubernetes' Log Query feature enables remote code execution with SYSTEM privileges on every Windows node in a clust…

SynkLoader: The 'Kitchen Sink' Malware Attacking via Microsoft Teams
Expel researchers have uncovered SynkLoader, a modular, multi-language malware family that uses Microsoft Teams phishing to breach cor…

SharePoint On-Prem Under Attack: Rapid7 PoC Weaponized Within 24 Hours
Threat actors are actively exploiting CVE-2026-55040 on Microsoft SharePoint on-premises servers using Rapid7's proof-of-concept code.…

Apple Patches Decade-Old iOS Zero-Day: dyld Exposed to Commercial Spyware
Apple has fixed CVE-2026-20700, a vulnerability in dyld present for over a decade and exploited in targeted attacks. The exploit chain…

Passkey Bypass: Three Attacks Demolish Phishing-Resistant Authentication
Three independent studies published in August 2026 demonstrate post-compromise attack chains that bypass passkey-based phishing-resist…

Rubrik Zero Labs Unveils RPE: From Word Document to Shell on Copilot
Remote Prompt Execution turns prompt injection into full enterprise identity compromise on Microsoft 365 Copilot. The five-stage chain…

AmnesiaStealer: The macOS Malware That Hijacks Victim Browser Sessions in Real Time
Jamf Threat Labs has documented AmnesiaStealer, a Rust-based macOS infostealer that clones the victim's Chromium profile, launches it…

ShieldBreak: Zero-Day Exploit Targets Windows Defender for SYSTEM Privilege Escalation
Nightmare Eclipse released ShieldBreak, a zero-day exploit achieving SYSTEM privileges on fully patched Windows via Microsoft Defender…

CVE-2026-62911: Exchange Authentication Bypass Enables Full Mailbox Takeover
Discovered at Pwn2Own by Orange Tsai, ZDI-26-534 hits on-premises Exchange with a CVSS 8.0 score. Microsoft released the patch after 8…

Passkey Bypass: Three Studies Shatter FIDO2's 'Anti-Phishing' Promise
On August 3, 2026, researchers from SpecterOps, Palo Alto Networks Unit 42, and independent researcher Dirk-jan Mollema published dist…

Apple Patches Decade-Old Zero-Day in iOS Core: dyld Exposed for 10+ Years
CVE-2026-20700 affects the dyld dynamic linker, a fundamental component present for over a decade. Apple confirms targeted exploitatio…