// 1 CRITICAL · 2 ZERO-DAY · 4 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H
microsoftZERO-DAY

Microsoft Backtracks on Legal Threats Against Zero-Day Researcher Following Industry Backlash

Microsoft threatened criminal action against researcher Nightmare-Eclipse over six Defender zero-days, partially retracting its stance…

Jun 08, 2026views - 1.2k

CYBERSECZERO-DAY

Edge Tab-Splitting and Invisible Phishing: The Pwn2Own Flaw

CVE-2026-45494: A Universal XSS in Microsoft Edge discovered by Orange Tsai leverages tab-splitting to mask malicious URLs. Update to…

Jun 08, 2026views - 1.6k

CYBERSECZERO-DAY

Microsoft Retracts Legal Threats Against Researchers Following Zero-Day Disclosure Backlash

Microsoft threatened criminal prosecution against researcher Nightmare-Eclipse for publishing six Windows zero-days before walking bac…

Jun 04, 2026views - 1.2k

VULNCRITICAL

Microsoft Patched This Pwn2Own Edge RCE Weeks Ago—But the Disclosure Gap Leaves Enterprises Exposed

CVE-2026-45495: A directory traversal vulnerability in Microsoft Edge feedback logs enables remote code execution. While Microsoft rel…

Jun 04, 2026views - 1k

CYBERSECCVE

Edge Vulnerability CVE-2026-45492: Origin Validation Error Bypasses Windows VBS

A flaw in Microsoft Edge’s cross-device sign-in mechanism, tracked as CVE-2026-45492, allows attackers to bypass Windows Virtualizatio…

Jun 04, 2026views - 826

CYBERSEC

Google Gemini Hijacked via Messaging Notifications: The 'Dual Illusion' Attack

SafeBreach researchers have demonstrated how the Google Gemini voice assistant on Android can be hijacked through indirect prompt inje…

Jun 04, 2026views - 696

VULN

Microsoft Refuses to Patch Windows Search URI Flaw Enabling NTLM Hash Theft

Huntress has disclosed an unpatched vulnerability in the Windows search: URI handler that allows attackers to steal NTLMv2 hashes via…

Jun 03, 2026views - 95

CYBERSEC

Cybanetix Launches Managed AI Service: AI-Native MDR Powered by Four-Vendor Stack

Cybanetix has unveiled its Managed AI Service, integrating NOMA, SentinelOne, Microsoft, and Exabeam under a unified 24/7 SOC with a s…

Jun 02, 2026views - 35

CYBERSECCRITICAL

Microsoft Patched a Critical SharePoint RCE but Omitted the CVE from Official Documentation

CVE-2026-45659, a CVSS 8.8 SharePoint Server RCE, was missing from Microsoft’s May 2026 security update list. While the patch was dist…

Jun 01, 2026views - 68

CYBERSEC

Poisoned AI Chatbots: A New Vector for High-Performance GPU Cryptojacking

Microsoft has identified an active campaign that manipulates AI chatbot recommendations to distribute GPU-based cryptojacking malware…

May 31, 2026views - 36

googleCRITICAL

Chrome 148: Google Patches 151 Vulnerabilities, Including 22 Critical Flaws

Google has released Chrome 148, addressing 151 security vulnerabilities with 22 rated at maximum criticality. The update includes over…

May 29, 2026views - 35

CYBERSECEXPLOIT

Apple macOS USD Library Flaw Enables Information Disclosure and Exploit Chaining

A vulnerability in the macOS Universal Scene Description (USD) library (ZDI-26-315) allows for out-of-bounds reads and potential code…

May 26, 2026views - 76