vulnerability Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities Microsoft released its May 2026 Patch Tuesday update, addressing 137 vulnerabilities across its product suite. The update includes a significant number of critical vulnerabilities, primarily remote code execution (RCE) f… Cisco Talos · May 12, 2026 High CVE-2026-32161CVE-2026-33109CVE-2026-33844rcebuffer overflowuse after free
threat-intel Exploits and vulnerabilities in Q1 2026 This Securelist report analyzes vulnerability trends and exploitation activity during Q1 2026, focusing on the expansion of exploit kits targeting Microsoft Office, Windows, and Linux operating systems. The report highli… Securelist · May 7, 2026 High CVE-2018-0802CVE-2017-11882CVE-2017-0199USvulnerabilityexploitationrce
threat-intel Smashing Security podcast #466: Meta sees everything, Copy Fail, and a deepfake gets hired This Smashing Security podcast episode discusses ongoing cybersecurity challenges, including the persistent issues of AI-related bugs, social engineering attacks, and the dangers of deepfakes. A key topic is Meta’s smart… Graham Cluley · May 6, 2026 Medium UKaiprivacydeepfake
apt UAT-8302 and its box full of malware Cisco Talos has identified UAT-8302, a China-nexus advanced persistent threat (APT) group, targeting government entities in South America and southeastern Europe. The group utilizes a range of custom malware families, in… Cisco Talos · May 5, 2026 High CVE-2025-0994BRCOCUchinaaptgovernment
threat-intel CloudZ RAT potentially steals OTP messages using Pheno plugin Cisco Talos identified an intrusion campaign initiated in January 2026 involving the deployment of the CloudZ remote access tool (RAT) alongside a new plugin called ‘Pheno.’ This campaign leveraged the Microsoft Phone Li… Cisco Talos · May 5, 2026 High USotpphone linkcredential theft
threat-intel A rigged game: ScarCruft compromises gaming platform in a supply-chain attack A North Korean-aligned APT group, ScarCruft (also known as APT37 or Reaper), conducted a supply-chain attack targeting a video game platform used by ethnic Koreans in the Yanbian region of China. The attackers injected a… WeLiveSecurity · May 5, 2026 High CNKPsupply-chainnorth-koreaespionage
threat-intel Patch Tuesday, April 2026 Edition Microsoft released a substantial update, Patch Tuesday, addressing 167 vulnerabilities across its operating systems and software, including several zero-days. This update focused on critical flaws in SharePoint Server, W… Krebs on Security · Apr 14, 2026 High CVE-2026-32201CVE-2026-33825CVE-2026-34621zero-daypatch tuesdayvulnerability
threat-intel Bypassing Administrator Protection by Abusing UI Access Google Project Zero researchers have identified a significant bypass in Windows' Administrator Protection feature, a security enhancement designed to prevent privilege escalation. The core issue stems from the UI Access… Google Project Zero · Feb 12, 2026 High uacprivilege escalationsecurity vulnerability
threat-intel Bypassing Windows Administrator Protection Microsoft has introduced Administrator Protection in Windows 11 to replace UAC, aiming to create a more secure boundary for administrator privileges. However, research by Google Project Zero revealed nine separate vulner… Google Project Zero · Jan 26, 2026 High uacadministratorbypass
vulnerability Welcome to the new Project Zero Blog Project Zero has revived older research to highlight the ongoing need for zero-day defenses. The blog post focuses on past exploitation techniques, specifically a 2016 article detailing race conditions in Windows path lo… Google Project Zero · Dec 16, 2025 Medium vulnerabilitywindowsexploitation