Visual Studio is a tool tracked across 15 threat clusters and 20 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity July 16, 2026.
A critical vulnerability in FortiWeb Web Application Firewall (WAF) has been actively exploited, allowing attackers to gain full administrative access to affected systems. Organizations using FortiWeb are at risk of…
In July 2026, Adobe and Microsoft released significant security updates addressing numerous vulnerabilities. Adobe issued 12 bulletins for 88 unique CVEs, with a focus on ColdFusion and Commerce patches, including a…
A high-severity vulnerability (CVE-2026-12957) in Amazon Q Developer for Visual Studio Code allowed attackers to execute arbitrary code and steal AWS credentials by automatically loading malicious MCP server…
In June 2026, Microsoft released its largest Patch Tuesday update, addressing 206 vulnerabilities, including critical flaws in Windows kernel and BitLocker. Notable CVEs include a zero-day in Visual Studio Code that…
A vulnerability named GhostApproval has been discovered in six major AI coding assistants, including Amazon Q Developer, Anthropic Claude Code, Augment, Cursor, Google Antigravity, and Windsurf. This flaw allows…
ToddyCat, an advanced persistent threat group, has adapted its tactics to exploit OAuth-based authorization flows, allowing them to compromise Gmail accounts without stealing user credentials. The group utilizes a…
Support for Windows 10 ended on October 14, 2025, leaving users without security updates. Microsoft is cutting off Secure Boot certificates for Windows 10 in June 2026, complicating the situation for users unable to…
Recent vulnerabilities in GitHub Copilot and Visual Studio have been identified, allowing attackers to bypass security features. These flaws pose risks to users relying on these platforms for secure coding practices.…
In July 2025, Microsoft discovered a new backdoor named SesameOp that exploits the OpenAI Assistants API for command-and-control operations. This malware allows attackers to remotely access and manage compromised…
Microsoft's Detection and Response Team (DART) discovered a new backdoor malware named SesameOp, which utilizes the OpenAI Assistants API for command-and-control (C2) communications. This malware allows attackers to…