logo

New Windows 0-Click Vulnerability Exploited to Bypass Defender SmartScreen

ID: 9f0097c9-30ee-5a97-aa2b-b881e3aeb8f3

STIX ID: report--9f0097c9-30ee-5a97-aa2b-b881e3aeb8f3

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Guru Baran

...
...

Akamai and CERT-UA reported that Russian APT28 weaponized a Windows LNK-based zero-click attack chain (CVE-2026-21510 and related MSHTML exploit CVE-2026-21513) that caused explorer.exe to resolve attacker-controlled UNC paths, triggering SMB/NTLM authentication and leaking Net-NTLMv2 hashes; Microsoft patched the primary RCE vector in February 2026 but a residual path-resolution/authentication issue was assigned CVE-2026-32202 and fixed in April 2026 — organizations should apply patches immediately, monitor outbound SMB to external hosts, and restrict NTLM to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.