SharePoint auth bypass exploited; 737 Chrome VPN extensions abused; Microsoft patches 398 flaws
ID: 3ebd317f-da45-56bf-a458-fb348e206f0f
STIX ID: report--3ebd317f-da45-56bf-a458-fb348e206f0f
Feed Name: defend.network
TL;DR — Multiple high-severity threats are active: SharePoint CVE-2026-55040 (CVSS 9.1) is being exploited after PoC release; 737 malicious Chrome VPN/proxy extensions are intercepting traffic and routing it through attacker proxies; Microsoft released patches for 398 vulnerabilities including an actively exploited Windows zero-day; Lazarus Group used a Windows zero-day to deploy a SYSTEM-level backdoor against defense/aerospace organizations across several countries; and Adobe Commerce CVE-2026-71362 saw immediate exploitation attempts. Immediate actions recommended are to urgently patch affected systems (SharePoint, Windows, Adobe Commerce), remove and control browser extensions, hunt for Lazarus IOCs, and verify patch deployment across enterprise assets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
