Windows Search URI Handler Flaw Leaks NTLMv2 Hashes to Attacker
A newly disclosed flaw in the Windows URI handler can silently leak NTLMv2 hashes to attacker-controlled servers with nothing more than a single link click. This behavior is the same bug class as CVE-2026-33829 in the Snipping Tool, but Microsoft has assigned no CVE and shipped no fix for this variant. On April 14, 2026, Microsoft […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
