Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack
ID: d2bc5deb-751f-56b8-b1bd-3338825e2bb2
STIX ID: report--d2bc5deb-751f-56b8-b1bd-3338825e2bb2
Feed Name: The Register (Security)
Microsoft and CISA warn of CVE-2026-32202, a zero-click Windows Shell authentication coercion vulnerability that can leak Net-NTLMv2 hashes to attackers, enabling credential theft and unauthorized access. The bug resulted from an incomplete fix for CVE-2026-21510; Microsoft marked exploitation as detected and CISA added the CVE to its Known Exploited Vulnerabilities catalog, prompting remediation deadlines for federal agencies. Akamai researchers discovered the flaw while testing February patches, and the report references prior exploitation of related CVEs by APT28.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
