Related Threat Clusters
-
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
GitLab's CVE-2026-19478, a critical code injection vulnerability with a CVSS score of 9.4, is currently under active exploitation just days after its public disclosure on August 17, 2026. Attackers are leveraging this…
2 articles · Updated August 22, 2026 -
Malware Campaign Disables Windows Update in Corporate China
Microsoft detected an active malware campaign targeting corporate systems in China, where attackers use fake software download sites to distribute malware that disables Windows Update and weakens Microsoft Defender. The…
3 articles · Updated September 3, 2026 -
Microsoft September 2026 Patch Tuesday: Record 974 Vulnerabilities Addressed
On September 8, 2026, Microsoft released a record-breaking 974 patches for vulnerabilities across its products, including two actively exploited zero-day vulnerabilities: CVE-2026-81963 and CVE-2026-85880. These…
74 articles · Updated September 8, 2026 -
Download More RAM Attack Bypasses Windows 11 Security Defenses
Researchers have identified a new attack, termed 'Download More RAM', that allows attackers to bypass Windows 11's Virtualization-Based Security (VBS) and disable Microsoft Defender without physical access to the target…
10 articles · Updated August 13, 2026 -
Active Vulnerabilities in Microsoft Defender Expose Users to Cyberattacks
Microsoft has confirmed two active vulnerabilities in its Defender software, CVE-2024-21314 and CVE-2024-21315, which are being exploited by cybercriminals. CVE-2024-21314 allows remote code execution through specific…
3 articles · Updated May 24, 2026 -
Microsoft Acknowledges RoguePlanet Zero-Day Vulnerability in Defender
Microsoft has confirmed a critical zero-day vulnerability in Microsoft Defender, identified as CVE-2026-50656, which allows for local privilege escalation. The flaw, dubbed 'RoguePlanet,' was disclosed by security…
9 articles · Updated June 17, 2026 -
Critical Vulnerabilities Discovered in Apache OFBiz Affecting All Versions Pre-24.09.06
Apache OFBiz has critical vulnerabilities that allow attackers to exploit hardcoded keys and bypass authentication. The vulnerabilities, CVE-2026-31986 and CVE-2026-45434, were published on 2026-05-19 and affect all…
3 articles · Updated May 21, 2026 -
Microsoft June 2026 Patch Tuesday: Record 206 Vulnerabilities Addressed
On June 9, 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including three zero-day flaws. Among the critical vulnerabilities, 32 were rated as critical, with 28 classified as…
57 articles · Updated June 9, 2026 -
Adobe and Microsoft June 2026 Security Updates Address Critical Vulnerabilities
In June 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe's update included 11 bulletins covering 123 CVEs, with critical vulnerabilities in Adobe Campaign…
4 articles · Updated June 10, 2026 -
Microsoft July 2026 Security Patches Address Critical Vulnerabilities
On July 15, 2026, Microsoft released security patches to address multiple critical vulnerabilities across its software products. The vulnerabilities include Remote Code Execution and Elevation of Privilege issues…
2 articles · Updated July 15, 2026
Recent Intelligence Reports
- Microsoft's September 2026 Patch Tuesday Fixes 114 Critical Flaws — Petri · September 9, 2026
- Microsoft Deploys Codename MDASH Agentic AI Scanning to Azure Government — Unite.Ai · September 9, 2026
- September 2026 Patch Tuesday: Updates and Analysis — Crowdstrike · September 9, 2026
- Codename MDASH brings agentic AI security scanning to US government — Microsoft · September 8, 2026
- September 2026 Patch Tuesday forecast: All we need is more time — Helpnetsecurity · September 4, 2026
- Chaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlank — Securityaffairs.Co · September 3, 2026
- Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon — Thehackernews · September 3, 2026
- Instaladores falsos desactivan Windows Update en operaciones corporativas en China — Ciberseguridadlatam · September 3, 2026