Leaked Windows Defender 0-Day Vulnerability Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

An active in-the-wild exploitation of three recently leaked Windows Defender privilege escalation vulnerabilities, with threat actors deploying proof-of-concept exploit code sourced directly from public GitHub repositories against real enterprise targets. …

Microsoft Confirms Windows Servers Enter Reboot Loops Following April Patches

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has confirmed a critical known issue affecting Windows Server 2025 domain controllers following the deployment of the April 2026 Patch Tuesday cumulative update, KB5082063, where affected servers are entering …

Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft has addressed a moderate-severity security flaw in the Windows Snipping Tool that could allow malicious actors to steal user credentials. Tracked as CVE-2026-33829, this spoofing vulnerability was officially patched …

One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Windows Admin Center is a locally deployed, browser-based management tool used by IT administrators to manage Windows servers, clients, and clusters from a centralized graphical interface. This newly discovered critical …

SpankRAT Exploits Windows Explorer Processes for Stealth and Delayed Detection

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly identified two-component Remote Access Trojan (RAT) toolkit built in Rust, dubbed SpankRAT, is being used by threat actors to abuse legitimate Windows processes, bypass reputation-based security controls, and …

Microsoft 365 Web Services Hit by Google Chrome 147 Compatibility Issue

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Microsoft is actively investigating a widespread authentication issue affecting users attempting to access Microsoft 365 web-based services through Google Chrome version 147. The problem, first reported on April 16, 2026, …

Two U.S. Nationals Sentenced for Running Laptop Farm for DPRK Remote Workers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Two American nationals have been sentenced to federal prison for operating a sophisticated “laptop farm” scheme. The operation successfully infiltrated over 100 U.S. companies, generating more than $5 million in …

New UAC-0247 Campaign Steals Browser and WhatsApp Data From Hospitals and Governments

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A threat cluster tracked as UAC-0247 has been running an active campaign since early 2026, targeting local governments and municipal healthcare institutions across Ukraine, including clinical hospitals and emergency ambulance …

Critical Cisco ISE Vulnerabilities Let Remote Attackers Execute Malicious Code

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cisco has issued an urgent security advisory warning of multiple vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). According to the official Cisco security advisory …

31 High-Impact Vulnerabilities Exploited in March as Interlock Hits Cisco FMC Zero-Day

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

March 2026 turned out to be one of the more active months for vulnerability exploitation this year. Security researchers tracked 31 high-impact vulnerabilities that were actively used against real-world systems, …