// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 6 EXPLOIT IN THE LAST 24H
phishing

ASCII Smuggling: From AI Attack to 2.37 Million Phishing Emails

A technique originally developed for prompt injection against language models has spawned a financial phishing campaign exceeding 2.37…

Sep 04, 2026views - 1k

CYBERSEC

From AI to Inbox: The 'Invisible' Technique That Flooded Corporate Email

Microsoft detected a campaign sending over 2 million messages per day by embedding invisible Unicode characters inside financial keywo…

Sep 04, 2026views - 969

quantum

G7 and CISA: The Quantum Threat Is Here, Time to Act Is Running Out

The G7 and CISA issued a joint advisory on September 3, 2026, turning post-quantum cryptography migration from a future concern into a…

Sep 04, 2026views - 1k

CYBERSEC

Silver Fox Pushes Fake Installers That Kill Windows Update and Weaken Defender

Microsoft exposes a campaign by the Chinese Silver Fox cluster using pixel-perfect clone sites of popular software to deliver installe…

Sep 02, 2026views - 1.2k

CYBERSEC

Spring Ring: The Teams Vishing Campaign That Jumps From Chat to Domain in Minutes

From January to April 2026, the Spring Ring campaign impersonated IT help desk staff on Microsoft Teams to trick employees into runnin…

Aug 31, 2026views - 1.1k

CYBERSEC

Mirage2FA: AiTM Phishing Kit Hits 3,500 Organizations, Bypasses MFA on Microsoft 365

The Mirage2FA phishing-as-a-service kit, operated by LinX Coders, has targeted over 3,500 organizations using Adversary-in-the-Middle…

Aug 26, 2026views - 1.4k

CYBERSEC

Windows: Localized Filename Bug Steals NTLM Credentials with a Single Click

CVE-2026-50508: A flaw in Windows localized filenames enables NTLM hash theft simply by opening a file or visiting a web page. Microso…

Aug 25, 2026views - 1k

CYBERSECZERO-DAY

Windows Compatibility Appraiser: LPE Bug Escalates from LOCAL SERVICE to SYSTEM

ZDI-26-606 discloses a local privilege escalation vulnerability in the Microsoft Windows Compatibility Appraiser. Symbolic link manipu…

Aug 24, 2026views - 1.1k

CYBERSECCVE

CVE-2026-65775: Microsoft Patches win32kfull UAF Discovered at Pwn2Own

Microsoft fixed CVE-2026-65775, a Use-After-Free in the Windows win32kfull driver discovered by Kentaro Kawane at Pwn2Own. The flaw en…

Aug 24, 2026views - 1k

malware

HollowGraph: APT Malware Turns M365 Calendars into Covert C2 Channel

HollowGraph exploits the Microsoft Graph API to transform compromised account calendars into bidirectional command-and-control channel…

Aug 22, 2026views - 1.1k

CYBERSECZERO-DAY

Windows ShieldBreak Zero-Day: Researcher Publishes Exploit Targeting Defender

Nightmare Eclipse released ShieldBreak, a zero-day exploit that weaponizes Windows Defender for local privilege escalation. The exploi…

Aug 22, 2026views - 1k

CYBERSECCVE

Microsoft Corrects Course: CVE-2026-69836 Was CVSS 10, But Not Exploited

Microsoft reclassified CVE-2026-69836, a critical Entra ID flaw, retracting its initial claim of active exploitation. The episode rais…

Aug 22, 2026views - 1k