Microsoft Patch Tuesday April 2026: 168 Vulnerabilities Fixed Including Actively Exploited SharePoint Zero-Day
Microsoft's April 2026 Patch Tuesday fixes a record 168 vulnerabilities, including an actively exploited SharePoint zero-day (CVE-2026-32201) and a publicly disclosed Microsoft Defender privilege escalation flaw. Security teams...
PoC Exploit Leaked for Unpatched Windows Privilege Escalation Zero-Day ‘BlueHammer’
A disgruntled researcher has published a working exploit for BlueHammer, an unpatched Windows local privilege escalation zero-day that abuses Windows Defender's update mechanism. Fully patched Windows 10, 11,...
Windows Zero-Day “BlueHammer” Exploit Code Released — SYSTEM Privileges at Risk
Exploit code has been publicly released for BlueHammer, a Windows zero-day privilege escalation vulnerability that allows attackers to gain full SYSTEM or administrator access. The availability of working...
A Silent Vulnerability Exposed: How Hackers Used Hidden Commands to Steal Sensitive Data
Microsoft’s seemingly “unremarkable” November 2025 Patch Tuesday update actually contained a major security fix. But even the most meticulous patching process can sometimes be outmaneuvered by cunning threat...
ClickFix: Fake Windows Updates and PNG Steganography Make a Darker Play for User Machines
For those deeply involved with cybersecurity, the past few years have seen a dramatic rise in sophisticated phishing campaigns leveraging social engineering to deliver malware onto unsuspecting victims....
Windows 11 fails to start after KB5058405 update
The recent disclosure by Microsoft regarding the KB5058405 cumulative update for Windows 11 has significant implications for enterprise cybersecurity and IT operations. This update, released as part of...
Critical vulnerability in the 7-Zip file archiver allows attackers to bypass MotW
A significant security vulnerability has been identified in the popular file archiver 7-Zip, allowing attackers to bypass the Windows Mark of the Web (MotW) security feature. This flaw,...
FLUX#CONSOLE: new malware campaign exploits Windows Management Console
In a sophisticated attack dubbed FLUX#CONSOLE, threat actors are employing tax-themed phishing lures to exploit the Microsoft Management Console (MMC), leveraging .msc files to deliver stealthy backdoor payloads....