vulnerability Microsoft Reins in RoguePlanet Zero-Day Threat A disgruntled security researcher, known as "Nightmare-Eclipse," published a proof-of-concept exploit (RoguePlanet) for a Windows Defender vulnerability, leading Microsoft to issue an out-of-band patch. The vulnerability, a privilege escalation flaw, allows an attacker with local access to elevate their privileges to S… Dark Reading · Jul 9, 2026 High CVE-2026-50656CVE-2026-33825zero-dayprivilege-escalationmicrosoft
threat-intel Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet A disgruntled researcher known as Nightmare-Eclipse has released another proof-of-concept (PoC) exploit, dubbed RoguePlanet, targeting a Windows Defender vulnerability. This follows a series of similar disclosures aimed… Dark Reading · Jun 10, 2026 High CVE-2026-33825USzero-dayexploitwindows
vulnerability Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Microsoft released a significant security update addressing 206 vulnerabilities across its software portfolio, including multiple critical Remote Code Execution (RCE) flaws and several zero-days. The update focuses on pa… The Hacker News · Jun 10, 2026 Critical CVE-2025-10263CVE-2026-8863CVE-2026-45657USzero-dayrcebitlocker
threat-intel Microsoft's Zero-Day Legal Threats Spark Backlash This article reports on Microsoft's controversial response to a security researcher, "Nightmare-Eclipse," who published several zero-day exploits. Microsoft initially threatened criminal charges against the researcher an… Dark Reading · Jun 1, 2026 High CVE-2026-33825zero-dayvulnerabilityresearcher
vulnerability Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal Microsoft has strongly criticized the public disclosure of zero-day vulnerabilities affecting Windows components, particularly following a researcher's independent disclosures. The company asserts that uncoordinated disc… The Hacker News · May 28, 2026 High CVE-2026-33825CVE-2026-41091CVE-2026-45498zero-dayvulnerabilitydisclosure
threat-intel ⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos This week’s security news highlights a significant GitHub breach orchestrated by TeamPCP, stemming from a compromised developer’s device and leveraging vulnerabilities exposed by the TanStack supply chain attack. Simulta… The Hacker News · May 25, 2026 High CVE-2026-46333CVE-2026-41091CVE-2026-45498USGBsupply-chainlinuxgithub
vulnerability Microsoft Warns of Two Actively Exploited Defender Vulnerabilities Microsoft has disclosed two actively exploited vulnerabilities within its Defender security platform, CVE-2026-41091 and CVE-2026-45498, both of which allow for privilege escalation and denial-of-service attacks. These v… The Hacker News · May 21, 2026 High CVE-2026-41091CVE-2026-45498CVE-2026-33825defendervulnerabilityprivilege escalation
vulnerability Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit This report details a zero-day vulnerability, dubbed ‘YellowKey,’ affecting Windows 11 and Server 2025, allowing attackers to bypass BitLocker Device Encryption through a USB drive exploit. Microsoft has released a mitig… The Hacker News · May 20, 2026 High CVE-2026-45585USbitlockerwinrezero-day
vulnerability Zero-Day Exploit Against Windows BitLocker A new zero-day exploit, dubbed YellowKey, has been discovered targeting Windows BitLocker encryption. The vulnerability allows attackers to bypass BitLocker's security measures with physical access to the affected device… Schneier on Security · May 18, 2026 High zero-dayencryptionbitlocker