logo

Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack

ID: 1422c4c8-d057-55bb-9cba-50f58e0c79c8

STIX ID: report--1422c4c8-d057-55bb-9cba-50f58e0c79c8

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Jessica Lyons

...
...

Microsoft and CISA warned that CVE-2026-32202 is a zero-click Windows Shell authentication-coercion vulnerability that can expose Net-NTLMv2 hashes via auto-parsed LNK files, enabling credential theft and impersonation; Microsoft marked it "exploitation detected" and CISA added it to its Known Exploited Vulnerabilities catalog, and researchers link the bug to an incomplete fix for a previously exploited vulnerability associated with Russian APT28.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.