// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 6 EXPLOIT IN THE LAST 24H
CYBERSEC

Local Malware Bypasses Google Passkeys: The Flaw Is in Chrome, Not FIDO2

Palo Alto Networks Unit 42 research demonstrates that local malware can bypass FIDO2 passkeys in Chrome on Windows using three techniq…

Aug 11, 2026views - 1.2k

ransomware

Microsoft Analyzes DeadLock: Rust Ransomware with Decentralized Infrastructure

Microsoft Threat Intelligence published a full technical analysis of DeadLock on August 11, 2026. The Rust-based ransomware has been a…

Aug 11, 2026views - 1.2k

CYBERSEC

APT29 Hits Hotel Wi-Fi: Steals M365 Credentials with Malware

Microsoft attributes the CaptiveCrunch campaign to Storm-2945, a Midnight Blizzard sub-group, which compromises hotel captive portals…

Aug 10, 2026views - 1.2k

CYBERSECEXPLOIT

Microsoft Uses AI to Find Windows Flaws Before Attackers Could Exploit Them

In the May 2026 Patch Tuesday, Microsoft fixed 138 vulnerabilities. Sixteen were discovered by the MDASH AI system before they could b…

Aug 10, 2026views - 1.2k

phishing

The Microsoft 365 Account Takeover That Leaves No Trace

Proofpoint tracks active campaigns since September 2025 that abuse Microsoft's OAuth 2.0 device authorization grant flow. MFA is bypas…

Aug 10, 2026views - 1.2k

CYBERSECZERO-DAY

June 2026 Patch Tuesday: Microsoft's Largest Ever, With Three Publicly Disclosed Zero-Days

Microsoft fixed nearly 200 vulnerabilities in the June 2026 Patch Tuesday, the most voluminous monthly cycle in the company's history.…

Aug 07, 2026views - 1.1k

CYBERSEC

Swiss Federal SharePoint Breach Compromises 200 Accounts

The Federal Office for Information Technology and Telecommunication (BIT/FOITT) confirms exploitation of already-patched SharePoint fl…

Aug 07, 2026views - 1.1k

CYBERSEC

CaptiveCrunch: Midnight Blizzard Turns Hotel Wi-Fi into an APT Delivery Vector

Microsoft Threat Intelligence has exposed CaptiveCrunch, a Storm-2945 campaign that weaponizes hotel captive portals to deliver the Co…

Aug 06, 2026views - 1.1k

phishing

Greatness PhaaS Bypasses M365 MFA by Abusing Whitelists

The Greatness Phishing-as-a-Service platform has evolved beyond credential theft to advanced adversary-in-the-middle and device-code p…

Aug 06, 2026views - 1.2k

phishing

Authorities Dismantle Kratos Phishing Kit, but the Code Lives On With 1,800 Customers

German and U.S. law enforcement seized over 200 servers and took down the Kratos phishing-as-a-service platform on July 21, 2026, whil…

Aug 05, 2026views - 1.3k

CYBERSEC

PNLD Data Breach: UK Police Contacts Published on Dark Web July 26

The Police National Legal Database confirms the exfiltration of names, organizations, and work emails of officers, government staff, a…

Aug 04, 2026views - 1.3k

CYBERSEC

Pass-ta-key Exposes the Gap Between FIDO2 Cryptography and Windows Implementation

Unit 42 reveals three post-compromise techniques that bypass PIN and biometrics on Chrome for Windows. Passkeys resist phishing, not m…

Aug 04, 2026views - 1.2k