Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This vulnerability was actively exploited for weeks before a patch was released on August 1...
A critical remote code execution vulnerability in Microsoft Windows Internet Key Exchange (IKE), tracked as CVE-2026-33824, is being actively exploited. This double-free memory corruption issue affects all supported versions of Windows 10, Windows 11, and Windows Server. Attackers can exploit the vu...
The Warlock ransomware group, tracked as Longlegs or Storm-2603, has targeted critical infrastructure in Portuguese- and Spanish-speaking countries, including a water utility, a telecommunications provider, a regional government body, and an university. Recent attacks exploited vulnerabilities in Mi...
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that could steal GitHub tokens. The updates are crucial for protecting a wide range of Mi...