// 1 CRITICAL · 2 ZERO-DAY · 5 CVE · 6 EXPLOIT IN THE LAST 24H
ransomware

Hyadina Strikes with GodDamn: Microsoft-Signed Driver Disables EDR in 24 Hours

The Hyadina ransomware-as-a-service group deploys a new locker, GodDamn, using the Microsoft-signed PoisonX kernel driver to neutraliz…

Jul 09, 2026views - 2k

CYBERSEC

Vishing 2.0 Hits Teams: Fake IT Support Calls Deploy EtherRAT

Palo Alto Networks Unit 42 uncovered a campaign that abuses Microsoft Teams voice calls to impersonate corporate IT support and trick…

Jul 06, 2026views - 1.6k

CYBERSECEXPLOIT

CISA Confirms: BlueHammer Now Exploited by Ransomware

CISA has elevated CVE-2026-33825 to a confirmed ransomware vector. Microsoft has not updated its advisory, creating an intelligence ga…

Jun 30, 2026views - 1.3k

CYBERSEC

Microsoft Removes 119 Edge Extensions Hiding Malware in Images and Fonts

Microsoft purged 119 Edge extensions that concealed StegoAd malware inside PNG, WebP, and WOFF2 font files, reaching a combined instal…

Jun 29, 2026views - 865

cloud

Unit 42 Uncovers Universal Bucket Hijacking Across Multiple Clouds

Unit 42/Palo Alto Networks research: globally unique bucket names in Google Cloud, AWS, and Azure allow data-flow hijacking without co…

Jun 27, 2026views - 1.3k

malware

Edgecution: Malicious Edge Extension Bypasses Sandbox via Native Messaging

Zscaler ThreatLabz documents a campaign where the Edgecution extension abuses Chrome's Native Messaging API to escape the browser sand…

Jun 25, 2026views - 1.2k

CYBERSECZERO-DAY

Microsoft Confirms RoguePlanet Zero-Day: Defender Becomes Attack Vector

CVE-2026-50656: Microsoft confirms zero-day vulnerability in Defender that elevates privileges to SYSTEM. Patch in development, public…

Jun 23, 2026views - 1.7k

aiCRITICAL

AutoJack: A Single Web Page Hijacks AI Agents to Execute Code on the Host

Microsoft Security has disclosed AutoJack, a three-vulnerability chain in AutoGen Studio that turns browsing-capable AI agents into ve…

Jun 19, 2026views - 1k

malware

Lorem Ipsum Pivots to ClickFix After Fox Tempest Takedown

BlueVoyant reports the Lorem Ipsum malware abandoned signed Microsoft Teams installers for ClickFix tactics on compromised WordPress s…

Jun 16, 2026views - 826

CYBERSEC

GhostTree: The NTFS Attack That Freezes EDR

Varonis Threat Labs disclosed GhostTree, an evasion technique that neutralizes Windows Defender using recursive NTFS junctions — no el…

Jun 16, 2026views - 989

malware

DragonForce Weaponizes Microsoft Teams TURN Relays for Stealth C2

The DragonForce ransomware group deployed Backdoor.Turn, the first documented in-the-wild malware to abuse Microsoft Teams' legitimate…

Jun 16, 2026views - 862

CYBERSECZERO-DAY

Microsoft Patches Actively Exploited Exchange Zero-Day, Mandates Dual-Layer Defense

Microsoft has released a permanent patch for CVE-2026-42897, an XSS zero-day in Exchange OWA. Despite the update, the EEMS mitigation…

Jun 10, 2026views - 890