Critical Microsoft Vulnerabilities Doubled in 2025, Report Finds
Microsoft's total vulnerability count dipped in 2025, but critical-severity flaws doubled year-over-year, driven by privilege escalation and identity abuse, according to BeyondTrust.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,755 stories synthesized.
Microsoft's total vulnerability count dipped in 2025, but critical-severity flaws doubled year-over-year, driven by privilege escalation and identity abuse, according to BeyondTrust.
The 2026 Verizon Data Breach Investigations Report reveals vulnerability exploitation as the leading initial access vector, now accounting for 31% of breaches, while median time-to-patch has increased 34% to 43 days.
Fortinet researchers have uncovered a global phishing campaign delivering the PureLogs infostealer via steganography, hiding encrypted payloads inside cat images to evade detection.
Attackers are increasingly abusing Microsoft's legacy MSHTA utility to silently deliver stealers, loaders, and persistent malware, with BitDefender detecting a dramatic rise in activity since the start of 2026.
A critical unpatched vulnerability in ChromaDB, CVE-2026-45829, allows unauthenticated remote attackers to execute arbitrary code and fully compromise servers running the popular AI vector database.
A Facebook scam campaign uses fake Aldi meat box offers to trick users into entering payment details on phishing sites, with Malwarebytes flagging the operation as a classic social engineering scheme.
Canonical released Ubuntu Core 26, a minimal immutable OS for IoT and edge devices, with up to 15 years of security maintenance.
The dark web carding marketplace B1ack’s Stash has released 4.6 million stolen credit card records as a free download, punishing sellers who resold data on rival platforms.
The EvilTokens phishing-as-a-service platform compromised over 340 Microsoft 365 organizations in five weeks by abusing OAuth device code authentication, bypassing MFA entirely.
Microsoft has confirmed that Windows Update failures in restricted network environments are caused by the January 2026 optional non-security preview update, with affected systems displaying error code 0x80010002.
Drupal announced an urgent core security release for all supported branches on May 20, warning that exploits may be developed within hours or days of the patch.
Apache released OFBiz 24.09.06 on May 19, 2026, fixing 17 vulnerabilities including three critical-severity bugs spanning authentication bypass, LDAP injection, and hard-coded cryptographic keys.
Cisco Talos has uncovered a BadIIS variant identified by 'demo.pdb' strings that is sold as a malware-as-a-service tool among multiple Chinese-speaking cybercrime groups for SEO fraud and traffic manipulation.
A proof-of-concept exploit for DirtyDecrypt, a Linux kernel privilege escalation flaw in the RxGK subsystem, has been publicly released, affecting distributions like Arch Linux, Fedora, and openSUSE.
InfoGuard Labs disclosed seven critical vulnerabilities in the SEPPMail Secure E-Mail Gateway, including a CVSS 10.0 path traversal flaw, enabling attackers to read all mail traffic and achieve persistent remote code execution.
Grafana Labs confirmed that attackers stole proprietary source code from its GitHub repositories after compromising a token, but said no customer data or cloud services were affected.
A malicious version of the popular Nx Console VS Code extension (18.95.0) was published to the marketplace, deploying a sophisticated credential stealer that harvests secrets from 1Password, npm, GitHub, and AWS.
A critical OS command injection vulnerability, CVE-2026-8153, has been disclosed in Universal Robots PolyScope 5, exposing industrial robot fleets to potential remote compromise.
A new study from the University of Texas at Arlington and Louisiana State University shows that attackers can generate convincing, personalized phishing emails using just a handful of public Instagram posts and generative AI.
Threat actors compromised the popular GitHub Action actions-cool/issues-helper, redirecting all tags to a malicious commit that harvests CI/CD credentials and exfiltrates them to an attacker-controlled server.
Ten vulnerabilities hit OpenHarmony v6.0 and earlier on May 19, including two high-severity remote code execution bugs in pre-installed apps and a permanent denial-of-service flaw.
A joint report warns that Anthropic's Claude Mythos AI tool, if leaked, could dramatically accelerate vulnerability exploitation in healthcare, echoing past abuse of Cobalt Strike and Brute Ratel.
Trend Micro researchers have reconstructed the complete operational model of Banana RAT, a banking trojan attributed to the SHADOW-WATER-063 cluster that targets Brazilian financial institutions.
Microsoft warns that threat actor Storm-2949 is abusing Self-Service Password Reset and legitimate admin tools to steal sensitive data from Azure and Microsoft 365 environments.