Windows kernel zero-day exploited; Zoom annotation RCE, Sandworm VPN campaign
ID: 311696d4-85b6-558d-a9c7-d3e83ce3b816
STIX ID: report--311696d4-85b6-558d-a9c7-d3e83ce3b816
Feed Name: defend.network
Threat Score
This multi-source briefing reports several high-priority threats: an actively exploited Windows kernel zero-day (afd.sys) enabling SYSTEM escalation, zero-click Zoom annotation RCE, Sandworm (UAC-0145) targeted social-engineering delivering trojanized WireGuard VPN, an AI-assisted SharePoint unauthenticated RCE (CVE-2026-55040), and active DoS exploitation of Cisco ASA/FTD VPNs; it urges immediate patching, monitoring, segmentation, and user awareness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
