Big Tech
Big Tech analyzes decisions by major platforms and their impact on security, privacy, infrastructure and the market. The cluster connects product announcements, strategic changes and technical consequences for users and businesses.

LegacyHive: The Windows Zero-Day With Free Micropatches While Microsoft Investigates
The LegacyHive zero-day in the Windows User Profile Service enables local privilege escalation. ACROS Security has already released fr…

Microsoft Patches RoguePlanet, the Defender Black Hole That Handed SYSTEM to Anyone
CVE-2026-50656: a race condition in the Windows 10 and 11 antivirus engine let a standard user gain SYSTEM privileges. The silent engi…

OWAReaper: The Malware That Survives Device Reimaging
Russia-aligned APT Laundry Bear (TA488) exploited CVE-2026-42897, an XSS flaw in Outlook Web Access, to deploy OWAReaper — a browser-b…

macOS USD Library Buffer Overflow Enables RCE via Malicious 3D Files
CVE-2026-43729 is a heap-based buffer overflow in Apple's USD library that allows arbitrary code execution through crafted 3D scene fi…

WhatsApp's CVSS 5.4 Falls Short: Zero-Click Surveillance Lurks Behind the Score
WhatsApp released an emergency update on July 28, 2025, patching CVE-2025-55177, an insufficient authorization flaw in Linked Devices…

CVE-2026-56163: Microsoft Mitigates Critical AKS Flaw Without Customer Action
Microsoft assigned CVE-2026-56163 a maximum CVSS 10.0 score for a critical elevation-of-privilege vulnerability in Azure Kubernetes Se…

Kratos Phishing Kit Dismantled: 200 Servers Seized, but AiTM Code Remains in Circulation
German, U.S., and Indonesian authorities took down the Kratos phishing kit, seizing over 200 servers and arresting the alleged develop…

Hotel Wi-Fi DNS Attacks Steal Microsoft 365 Accounts, Bypass MFA
Threat actors compromise hotel and conference center Wi-Fi captive portals to manipulate DNS and steal Microsoft 365 credentials, sess…

Certighost: Ten Days After the Patch, the Exploit Is Public and the Domain Falls
The Certighost proof-of-concept for CVE-2026-54121 lets a standard domain user impersonate a Domain Controller via AD CS. Released exa…

Record Patch Tuesday: Microsoft Fixes 570 CVEs and Two Actively Exploited Zero-Days in AD FS and SharePoint
The July 14, 2026 Patch Tuesday sets a record with 570 CVEs patched, two actively exploited zero-days, and a third publicly disclosed.…

Apple Patches iOS 26 dyld Zero-Day: Targeted Attacks Already Underway
Apple has released iOS 26.3 to address CVE-2026-20700, a zero-day vulnerability in the dyld component exploited in sophisticated attac…

LegacyHive: Zero-Day Windows Flaw Patched by 0Patch Before Microsoft
The LegacyHive vulnerability in the Windows User Profile Service enables local privilege escalation. ACROS Security has released free…