// 2 CRITICAL · 5 ZERO-DAY · 10 CVE · 8 EXPLOIT · 1 ADVISORY IN THE LAST 24H
CYBERSEC

Poisoned AI Chatbots: A New Vector for High-Performance GPU Cryptojacking

Microsoft has identified an active campaign that manipulates AI chatbot recommendations to distribute GPU-based cryptojacking malware…

May 31, 2026views - 161

CYBERSECZERO-DAY

Windows Hit by Post-Patch Tuesday Zero-Day Blitz

Security researcher Chaotic Eclipse has disclosed three new Windows zero-day vulnerabilities following the May 2026 Patch Tuesday. To…

May 25, 2026views - 645

CYBERSECZERO-DAY

YellowKey: Microsoft Issues Emergency Mitigations for BitLocker Bypass

Microsoft issued temporary mitigations on May 20 for CVE-2026-45585, a BitLocker bypass vulnerability exploited through the Windows Re…

May 25, 2026views - 304

CYBERSECCVE

CISA Adds Microsoft Defender DoS Flaw to KEV Catalog with June 3 Deadline

CISA has added CVE-2026-45498, a Denial of Service vulnerability in Microsoft Defender, to its Known Exploited Vulnerabilities catalog…

May 24, 2026views - 219

CYBERSECCVE

CVE-2026-41091: Microsoft Defender Engine Exploited for SYSTEM Privilege Escalation

A link-following vulnerability in the Microsoft Malware Protection Engine enables local privilege escalation to SYSTEM. An analysis of…

May 24, 2026views - 360

CYBERSECCRITICAL

May 2026 Patch Tuesday: 137 Flaws and the Domain Controller Threat

Microsoft's May 2026 security update addresses 137 vulnerabilities, including 31 critical flaws. While no zero-days were reported, una…

May 23, 2026views - 176

phishing

M365 Phishing: How Kali365 and EvilTokens Bypass MFA Without Passwords

Two emerging Phishing-as-a-Service (PhaaS) platforms are leveraging device code phishing and OAuth consent abuse to hijack Microsoft 3…

May 22, 2026views - 482

CYBERSECZERO-DAY

Microsoft Defender Zero-Days Under Active Attack; CISA Mandates Patching by June 3

Microsoft has confirmed that two vulnerabilities in Microsoft Defender are being actively exploited in the wild. CISA has added both f…

May 21, 2026views - 220

microsoft

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agent Workflows

Microsoft has unveiled two open-source security tools for AI agents: RAMPART, a Pytest-native framework for build-time testing, and Cl…

May 20, 2026views - 184

CYBERSEC

GitHub Breach: 3,800 Internal Repositories Stolen via Malicious VS Code Extension

GitHub has confirmed a security breach affecting approximately 3,800 internal repositories after an employee device was compromised by…

May 20, 2026views - 522

CYBERSECZERO-DAY

BitLocker Bypassed: New Zero-Day Trio Targets Windows Following Patch Tuesday

An analysis of the YellowKey, GreenPlasma, and MiniPlasma vulnerabilities disclosed shortly after the May 2026 Patch Tuesday, impactin…

May 20, 2026views - 224

CYBERSEC

Microsoft Neutralizes Fox Tempest: Malware-Signing-as-a-Service Operation Dismantled

Microsoft has disrupted Fox Tempest, a sophisticated 'Malware-Signing-as-a-Service' operation that leveraged stolen identities to expl…

May 20, 2026views - 111