Microsoft
Curated coverage and analysis in this editorial area.

CVE-2024-9042: SYSTEM-Level RCE on Kubernetes Windows Nodes via a Single curl Request
A vulnerability in Kubernetes' Log Query feature enables remote code execution with SYSTEM privileges on every Windows node in a clust…

SynkLoader: The 'Kitchen Sink' Malware Attacking via Microsoft Teams
Expel researchers have uncovered SynkLoader, a modular, multi-language malware family that uses Microsoft Teams phishing to breach cor…

SharePoint On-Prem Under Attack: Rapid7 PoC Weaponized Within 24 Hours
Threat actors are actively exploiting CVE-2026-55040 on Microsoft SharePoint on-premises servers using Rapid7's proof-of-concept code.…

Passkey Bypass: Three Attacks Demolish Phishing-Resistant Authentication
Three independent studies published in August 2026 demonstrate post-compromise attack chains that bypass passkey-based phishing-resist…

Rubrik Zero Labs Unveils RPE: From Word Document to Shell on Copilot
Remote Prompt Execution turns prompt injection into full enterprise identity compromise on Microsoft 365 Copilot. The five-stage chain…

ShieldBreak: Zero-Day Exploit Targets Windows Defender for SYSTEM Privilege Escalation
Nightmare Eclipse released ShieldBreak, a zero-day exploit achieving SYSTEM privileges on fully patched Windows via Microsoft Defender…

CVE-2026-62911: Exchange Authentication Bypass Enables Full Mailbox Takeover
Discovered at Pwn2Own by Orange Tsai, ZDI-26-534 hits on-premises Exchange with a CVSS 8.0 score. Microsoft released the patch after 8…

Passkey Bypass: Three Studies Shatter FIDO2's 'Anti-Phishing' Promise
On August 3, 2026, researchers from SpecterOps, Palo Alto Networks Unit 42, and independent researcher Dirk-jan Mollema published dist…

ShieldBreak: New Zero-Day in Defender Exposes Windows Systems
Nightmare Eclipse released ShieldBreak, an exploit that bypasses the patch for CVE-2026-50656 and enables privilege escalation to SYST…

Windows: win32kfull Driver Bug Allows Escalation to SYSTEM
Microsoft released a fix on August 11, 2026 for CVE-2026-62712, a vulnerability in the win32kfull driver that allows code running with…

Lazarus Strikes with CVE-2026-68820: Microsoft Zero-Day in Defense Sector
Check Point discovers the 2026 wave of Operation Dream Job. Lazarus exploits CVE-2026-68820 in AFD.sys to deploy FudModule via fake jo…

CISA Confirms SharePoint Ransomware Exploitation; Microsoft Stays Silent
The U.S. cybersecurity agency confirmed on August 11, 2026, that ransomware groups are actively exploiting CVE-2026-45659 in on-premis…