Big Tech
Big Tech analyzes decisions by major platforms and their impact on security, privacy, infrastructure and the market. The cluster connects product announcements, strategic changes and technical consequences for users and businesses.

ShieldBreak: New Zero-Day in Defender Exposes Windows Systems
Nightmare Eclipse released ShieldBreak, an exploit that bypasses the patch for CVE-2026-50656 and enables privilege escalation to SYST…

ZDI-26-558: Amazon Smart Plug Certificate Validation Flaw in OTA Firmware Updates
A vulnerability in the Amazon Smart Plug's over-the-air update process allows a network-adjacent attacker to bypass certificate valida…

Windows: win32kfull Driver Bug Allows Escalation to SYSTEM
Microsoft released a fix on August 11, 2026 for CVE-2026-62712, a vulnerability in the win32kfull driver that allows code running with…

Lazarus Strikes with CVE-2026-68820: Microsoft Zero-Day in Defense Sector
Check Point discovers the 2026 wave of Operation Dream Job. Lazarus exploits CVE-2026-68820 in AFD.sys to deploy FudModule via fake jo…

CISA Confirms SharePoint Ransomware Exploitation; Microsoft Stays Silent
The U.S. cybersecurity agency confirmed on August 11, 2026, that ransomware groups are actively exploiting CVE-2026-45659 in on-premis…

Local Malware Bypasses Google Passkeys: The Flaw Is in Chrome, Not FIDO2
Palo Alto Networks Unit 42 research demonstrates that local malware can bypass FIDO2 passkeys in Chrome on Windows using three techniq…

Microsoft Analyzes DeadLock: Rust Ransomware with Decentralized Infrastructure
Microsoft Threat Intelligence published a full technical analysis of DeadLock on August 11, 2026. The Rust-based ransomware has been a…

Qualcomm Zero-Day Exploited in Targeted Attacks: Android Remains Exposed
Google confirms limited exploitation of CVE-2026-21385 in the Qualcomm graphics kernel. Patches have existed since January, but delive…

Apple Patches CVE-2026-20700: Zero-Day in dyld Survived Two Decades in iOS
Apple has fixed CVE-2026-20700, a zero-day memory corruption vulnerability in the dyld dynamic linker that existed in iOS for over a d…

APT29 Hits Hotel Wi-Fi: Steals M365 Credentials with Malware
Microsoft attributes the CaptiveCrunch campaign to Storm-2945, a Midnight Blizzard sub-group, which compromises hotel captive portals…

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them
In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…

The Microsoft 365 Account Takeover That Leaves No Trace
Proofpoint tracks active campaigns since September 2025 that abuse Microsoft's OAuth 2.0 device authorization grant flow. MFA is bypas…