Cyber Crime
FBI Takes Down NightmareStresser DDoS Platform
The FBI has seized the domains of NightmareStresser, one of the world's longest-running DDoS-for-hire platforms, linked to thousands of attacks globally.
Malware
Malware Bypasses Browser Checks to Force Install Chrome and Edge Extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data.
Artificial Intelligence
Microsoft Commits to Sweeping AI Privacy Rules for Students
Microsoft has committed to implementing comprehensive AI privacy rules for students, a move that may influence other tech companies to follow suit.
Critical Vulnerabilities
Microsoft Authenticator Elevation of Privilege Vulnerability (CVE-2026-80097)
Microsoft has addressed a critical elevation of privilege vulnerability in its Authenticator app, identified as CVE-2026-80097. This flaw could allow unauthorized access to sensitive features.
Critical Vulnerabilities
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability - CVE-2026-69486
A heap-based buffer overflow in Microsoft Edge allows an unauthorized attacker to execute code over a network.
Critical Vulnerabilities
Information Disclosure Vulnerability in Microsoft Teams for Android (CVE-2026-69559)
The CVE-2026-69559 vulnerability in Microsoft Teams for Android allows for information disclosure, highlighting the need for regular updates to protect sensitive data.
Critical Vulnerabilities
Microsoft Edge Elevation of Privilege Vulnerability (CVE-2026-85893)
A critical vulnerability in Microsoft Edge allows unauthorized attackers to elevate privileges over a network, posing a serious security risk to users.
Critical Vulnerabilities
Microsoft Teams for Android Information Disclosure Vulnerability (CVE-2026-65812)
A new information disclosure vulnerability has been identified in Microsoft Teams for Android, potentially exposing sensitive user data. A fix has been issued, but awareness of the issue is crucial.
Malware
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
A China-aligned espionage group is exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. This exploitation poses significant risks to users and organizations alike.
Cyber Crime
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.
Critical Vulnerabilities
CVE-2026-85053: Improper Resource Exposure in Chromium's CacheStorage
The CVE-2026-85053 vulnerability in Chromium could expose sensitive resources, affecting Microsoft Edge. It's crucial for users to update their browsers to avoid risks.
Critical Vulnerabilities
CVE-2026-76039: Incorrect Reference Resolution in Chromium Core
The CVE-2026-76039 vulnerability affects Chromium and, by extension, Microsoft Edge. This security flaw could lead to significant risks, requiring immediate attention from users.