Big Tech
Big Tech analyzes decisions by major platforms and their impact on security, privacy, infrastructure and the market. The cluster connects product announcements, strategic changes and technical consequences for users and businesses.

CVE-2026-11645: Google Patches Fifth Chrome Zero-Day of 2026
Google has released a critical patch for CVE-2026-11645, a zero-day vulnerability in Chrome's V8 engine. With an exploit active in the…

Microsoft Patches Actively Exploited Exchange Zero-Day, Mandates Dual-Layer Defense
Microsoft has released a permanent patch for CVE-2026-42897, an XSS zero-day in Exchange OWA. Despite the update, the EEMS mitigation…

RoguePlanet: Zero-Day Exploit (CVE-2026-42897) Hits Fully Patched Windows 10 and 11 Systems
RoguePlanet (CVE-2026-42897) leverages a race condition in Microsoft Defender to gain SYSTEM privileges on Windows 10 and 11 devices,…

Windows Narrator Braille: LPE Hidden in the Accessibility Path
CVE-2026-48565: Local escalation to SYSTEM via brlapi, the Windows Braille service frequently overlooked by enterprise patching cycles.

Microsoft June 2026 Patch Tuesday: 200 Flaws Fixed, 3 Public Zero-Days Addressed
Microsoft’s June 2026 security update addresses approximately 200 vulnerabilities, including three publicly disclosed zero-days: the '…

Microsoft Backtracks on Legal Threats Against Zero-Day Researcher Following Industry Backlash
Microsoft threatened criminal action against researcher Nightmare-Eclipse over six Defender zero-days, partially retracting its stance…

Edge Tab-Splitting and Invisible Phishing: The Pwn2Own Flaw
CVE-2026-45494: A Universal XSS in Microsoft Edge discovered by Orange Tsai leverages tab-splitting to mask malicious URLs. Update to…

Microsoft Retracts Legal Threats Against Researchers Following Zero-Day Disclosure Backlash
Microsoft threatened criminal prosecution against researcher Nightmare-Eclipse for publishing six Windows zero-days before walking bac…

Microsoft Patched This Pwn2Own Edge RCE Weeks Ago—But the Disclosure Gap Leaves Enterprises Exposed
CVE-2026-45495: A directory traversal vulnerability in Microsoft Edge feedback logs enables remote code execution. While Microsoft rel…

Edge Vulnerability CVE-2026-45492: Origin Validation Error Bypasses Windows VBS
A flaw in Microsoft Edge’s cross-device sign-in mechanism, tracked as CVE-2026-45492, allows attackers to bypass Windows Virtualizatio…

Google Gemini Hijacked via Messaging Notifications: The 'Dual Illusion' Attack
SafeBreach researchers have demonstrated how the Google Gemini voice assistant on Android can be hijacked through indirect prompt inje…

Microsoft Refuses to Patch Windows Search URI Flaw Enabling NTLM Hash Theft
Huntress has disclosed an unpatched vulnerability in the Windows search: URI handler that allows attackers to steal NTLMv2 hashes via…