Microsoft Office Equation Editor RCE (cited as veteran exploit by Kaspersky Q1 2026 exploit report)
cve · CVE-2017-11882
Coverage timeline
1
first 2026-05-10 → last 2026-05-10
no data
Briefs
1
1 distinct
Sources cited
315
106 hosts
Sections touched
0
—
Co-occurring entities
0
no co-occurrence
Story timeline
Source distribution
- attack.mitre.org43 (14%)
- thehackernews.com29 (9%)
- msrc.microsoft.com20 (6%)
- microsoft.com19 (6%)
- bleepingcomputer.com18 (6%)
- helpnetsecurity.com11 (3%)
- securityweek.com8 (3%)
- security-hub.ncsc.admin.ch7 (2%)
- other160 (51%)
External references
All cited sources (315)
- securelist.comprimaryinlineKaspersky Securelist — Exploits and Vulnerabilities Q1 2026https://securelist.com/vulnerabilities-and-exploits-in-q1-2026/119733/
- securelist.comprimaryinlineSecurelist (Kaspersky), 2026-05-12https://securelist.com/state-of-ransomware-in-2026/119761/
- securelist.comprimaryinlineKaspersky Securelist, 2026-06-22https://securelist.com/whatsapp-vbs-rmm-campaign/120290/
- access.redhat.cominlineRed Hat, updated 2026-05-09https://access.redhat.com/security/vulnerabilities/RHSB-2026-003
- advisories.ncsc.nlinlineNCSC-NL NCSC-2026-0158, 2026-05-15https://advisories.ncsc.nl/advisory?id=NCSC-2026-0158
- advisories.ncsc.nlinlineNCSC-NL NCSC-2026-0159, 2026-05-15https://advisories.ncsc.nl/advisory?id=NCSC-2026-0159
- advisories.ncsc.nlinlineNCSC-NL, 2026-06-11https://advisories.ncsc.nl/advisory?id=NCSC-2026-0185
- advisories.ncsc.nlinlineNCSC-NL 0189https://advisories.ncsc.nl/advisory?id=NCSC-2026-0189
- aikido.devinlineAikidohttps://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys
- aikido.devinlineAikido Securityhttps://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm
- akamai.cominlineAkamai Security Researchhttps://www.akamai.com/blog/security-research/incomplete-patch-apt28s-zero-day-cve-2026-32202
- almalinux.orginlineAlmaLinux bloghttps://almalinux.org/blog/2026-05-07-dirty-frag/
- amd.cominlineAMD Product Security, 2026-05-12https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html
- arcticwolf.cominlinein-the-wild campaign abusing CVE-2026-35616https://arcticwolf.com/resources/blog/forticlient-ems-exploited-via-cve-2026-35616-to-deliver-ekz-infostealer-disguised-as-a-fortinet-patch/
- attack.mitre.orginlineT1021.002https://attack.mitre.org/techniques/T1021/002/
- attack.mitre.orginlineT1021.004https://attack.mitre.org/techniques/T1021/004/
- attack.mitre.orginlineT1021.007 (Remote Services: Cloud Services)https://attack.mitre.org/techniques/T1021/007/
- attack.mitre.orginlineT1027https://attack.mitre.org/techniques/T1027/
- attack.mitre.orginlineT1041https://attack.mitre.org/techniques/T1041/
- attack.mitre.orginlineT1053.005https://attack.mitre.org/techniques/T1053/005/
- attack.mitre.orginlineT1055https://attack.mitre.org/techniques/T1055/
- attack.mitre.orginlineT1056.001https://attack.mitre.org/techniques/T1056/001/
- attack.mitre.orginlineT1068https://attack.mitre.org/techniques/T1068/
- attack.mitre.orginlineWeb Protocolshttps://attack.mitre.org/techniques/T1071/001/
- attack.mitre.orginlineT1078.004 (Valid Accounts: Cloud Accounts)https://attack.mitre.org/techniques/T1078/004/
- attack.mitre.orginlineT1083 (File and Directory Discovery)https://attack.mitre.org/techniques/T1083/
- attack.mitre.orginlineCloud Account Discoveryhttps://attack.mitre.org/techniques/T1087/004/
- attack.mitre.orginline`T1090` Proxyhttps://attack.mitre.org/techniques/T1090/
- attack.mitre.orginlineT1090.001https://attack.mitre.org/techniques/T1090/001/
- attack.mitre.orginlineT1095https://attack.mitre.org/techniques/T1095/
- attack.mitre.orginlineT1098.005 (Account Manipulation: Device Registration)https://attack.mitre.org/techniques/T1098/005/
- attack.mitre.orginlineDead Drop Resolverhttps://attack.mitre.org/techniques/T1102/001/
- attack.mitre.orginlineT1114.002https://attack.mitre.org/techniques/T1114/002/
- attack.mitre.orginline`T1136.001`https://attack.mitre.org/techniques/T1136/001/
- attack.mitre.orginline`T1140`https://attack.mitre.org/techniques/T1140/
- attack.mitre.orginline`T1190` Exploit Public-Facing Applicationhttps://attack.mitre.org/techniques/T1190/
- attack.mitre.orginlineT1195.002https://attack.mitre.org/techniques/T1195/002/
- attack.mitre.orginlineUser Execution: Malicious Filehttps://attack.mitre.org/techniques/T1204/002/
- attack.mitre.orginlineT1218https://attack.mitre.org/techniques/T1218/
- attack.mitre.orginline`T1480.001`https://attack.mitre.org/techniques/T1480/001/
- attack.mitre.orginline`T1485`https://attack.mitre.org/techniques/T1485/
- attack.mitre.orginlineCloud Service Discoveryhttps://attack.mitre.org/techniques/T1526/
- attack.mitre.orginlineSteal Application Access Tokenhttps://attack.mitre.org/techniques/T1528/
- attack.mitre.orginlineT1530 (Data from Cloud Storage)https://attack.mitre.org/techniques/T1530/
- attack.mitre.orginlineSteal Web Session Cookiehttps://attack.mitre.org/techniques/T1539/
- attack.mitre.orginlineT1542.001https://attack.mitre.org/techniques/T1542/001/
- attack.mitre.orginline`T1543.003`https://attack.mitre.org/techniques/T1543/003/
- attack.mitre.orginlineWeb Session Cookiehttps://attack.mitre.org/techniques/T1550/004/
- attack.mitre.orginlineT1552.001 (Unsecured Credentials: Credentials In Files)https://attack.mitre.org/techniques/T1552/001/
- attack.mitre.orginline`nss3.dll`https://attack.mitre.org/techniques/T1555/003/
- attack.mitre.orginlineT1556https://attack.mitre.org/techniques/T1556/
- attack.mitre.orginlineT1556.006 (Modify Authentication Process: Multi-Factor Authentication)https://attack.mitre.org/techniques/T1556/006/
- attack.mitre.orginlineAdversary-in-the-Middlehttps://attack.mitre.org/techniques/T1557/
- attack.mitre.orginlineT1562.001https://attack.mitre.org/techniques/T1562/001/
- attack.mitre.orginlineT1562.007 (Impair Defenses: Disable or Modify Cloud Firewall)https://attack.mitre.org/techniques/T1562/007/
- attack.mitre.orginlineT1566.004https://attack.mitre.org/techniques/T1566/004/
- attack.mitre.orginline`T1574.002`https://attack.mitre.org/techniques/T1574/002/
- bitdefender.cominlineBitdefender Labs, 2026-05-13https://www.bitdefender.com/en-us/blog/businessinsights/famoussparrow-apt-targets-azerbaijani-oil-gas-industry
- bleepingcomputer.cominlineBleepingComputer, 2026-06-01https://www.bleepingcomputer.com/news/microsoft/critical-windows-netlogon-remote-code-execution-flaw-now-exploited-in-attacks/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/microsoft/microsoft-june-2026-patch-tuesday-fixes-6-zero-days-200-flaws/
- bleepingcomputer.cominlineBleepingComputer — MiniPlasma zero-day PoChttps://www.bleepingcomputer.com/news/microsoft/new-windows-miniplasma-zero-day-exploit-gives-system-access-poc-released/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-24https://www.bleepingcomputer.com/news/security/amadey-stealc-malware-operations-disrupted-in-operation-endgame-action/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-04https://www.bleepingcomputer.com/news/security/chinese-hackers-use-new-atlas-rat-malware-in-european-cyberattacks/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-20https://www.bleepingcomputer.com/news/security/grafana-breach-caused-by-missed-token-rotation-after-tanstack-attack/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/malicious-edge-extension-abuses-native-messaging-as-bridge-to-malware/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-18https://www.bleepingcomputer.com/news/security/microsoft-links-mastra-ai-supply-chain-attack-to-north-korean-hackers/
- bleepingcomputer.cominlineBleepingComputer corroboration on 2026-05-19https://www.bleepingcomputer.com/news/security/microsoft-self-service-password-reset-abused-in-azure-data-theft-attacks/
- bleepingcomputer.cominlineBleepingComputer — MuddyWater hackers use Chaos ransomware as a decoyhttps://www.bleepingcomputer.com/news/security/muddywater-hackers-use-chaos-ransomware-as-a-decoy-in-attacks/
- bleepingcomputer.cominlineBleepingComputer — IronWormhttps://www.bleepingcomputer.com/news/security/new-ironworm-malware-hits-36-packages-in-npm-supply-chain-attack/
- bleepingcomputer.cominlineBleepingComputer 2026-05-05https://www.bleepingcomputer.com/news/security/new-stealthy-quasar-linux-malware-targets-software-developers/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-11https://www.bleepingcomputer.com/news/security/nottingham-university-data-breach-affects-over-450-000-students/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-15https://www.bleepingcomputer.com/news/security/pwn2own-day-two-hackers-demo-microsoft-exchange-windows-11-red-had-enterprise-linux-zero-days/
- bleepingcomputer.cominlineBleepingComputer, 2026-06-16https://www.bleepingcomputer.com/news/security/ransomware-gang-abuses-microsoft-teams-relays-to-hide-malicious-traffic/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-17https://www.bleepingcomputer.com/news/security/tycoon2fa-hijacks-microsoft-365-accounts-via-device-code-phishing/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-13https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/
- blog.ammaraskar.cominlineAmmar Askar, 2026-06-02https://blog.ammaraskar.com/github-token-stealing/
- blog.calif.ioinlineCalif/Codex, 2026-06-02https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb
- blog.fox-it.cominlineFox-IT, 2026-05-22https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/
- blog.sekoia.ioinlineSekoia TDR, 2026-06-11https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/
- blog.sekoia.ioinlineSekoia's reference analysishttps://blog.sekoia.io/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit/
- blog.talosintelligence.cominlineCisco Talos, 2026-05-05https://blog.talosintelligence.com/cloudz-pheno-infostealer/
- blog.talosintelligence.cominlineCisco Talos 2026-05-05https://blog.talosintelligence.com/uat-8302/
- blogs.microsoft.cominlineMicrosoft On the Issues — DCU legal action, 2026-05-19https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/
- broadcom.cominlineSymantec, 2026-06-24https://www.broadcom.com/support/security-center/protection-bulletin/backdoor-mistic-new-backdoor-may-be-linked-to-ransomware-access-broker
- ccb.belgium.beinlineCCB Belgium, 2026-05-08https://ccb.belgium.be/advisories/warning-dirty-frag-new-linux-local-privilege-escalation-vulnerability-was-disclosed
- cert.europa.euinlineCERT-EU 2026-005https://cert.europa.eu/publications/security-advisories/2026-005/
- cert.europa.euinlineCERT-EU, 2026-06-10https://cert.europa.eu/publications/security-advisories/2026-007/
- cert.plinlineCERT Polska CVE-2026-42096https://cert.pl/en/posts/2026/05/CVE-2026-42096/
- cert.ssi.gouv.frinlineCERT-FR — CERTFR-2026-ACT-016, 2026-05-08https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-016/
- cert.ssi.gouv.frinlineCERT-FR / ANSSI advisory CERTFR-2026-AVI-0652https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0652/
- cisa.govinlineCISA KEV cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
- cisa.govinlineCISA Alert AA21-321A, 2021-11-17https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-321a
- cloud.google.cominlineGoogle Threat Intelligence Group, 2026-05-15https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation/
- cloud.google.cominlineMandiant GTIG, 2026-06-11https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-targets-education-sector-oracle-exploit/
- cloud.google.cominlineMandiant, 2026-04-23https://cloud.google.com/blog/topics/threat-intelligence/unc6692-social-engineering-custom-malware
- cpomagazine.cominlineCPO Magazinehttps://www.cpomagazine.com/cyber-security/microsoft-doubles-down-on-opposition-to-public-disclosure-as-chaotic-eclipse-wave-of-zero-day-vulnerabilities-continues/
- csoonline.cominlineCSO Onlinehttps://www.csoonline.com/article/4189132/be-on-the-lookout-for-mistic-a-new-backdoor-used-by-ransomware-broker.html
- cyberscoop.cominlineCyberScoop, 2026-05-22https://cyberscoop.com/fbi-phishing-kali365-microsoft365-access-tokens/
- cyera.cominlineCyera Research, 2026-05-15https://www.cyera.com/blog/claw-chain-cyera-research-unveil-four-chainable-vulnerabilities-in-openclaw
- drupal.orginlineDrupal PSA-2026-05-18https://www.drupal.org/psa-2026-05-18
- edri.orginlineEDRi, 2026-05-28https://edri.org/our-work/inside-italys-low-cost-spyware-economy/
- elastic.coinlineElastic Security Labs, 2026-06-19https://www.elastic.co/security-labs/aad-graph-activity-logs-threat-detection
- elastic.coinlineElastic Security Labs 2026-05-07https://www.elastic.co/security-labs/tclbanker-brazilian-banking-trojan
- elastic.coinlineElastic Security Labs, 2026-05-26https://www.elastic.co/security-labs/tycoon-2fa-aitm-detection-engineering
- enisa.europa.euinlineENISA, 2026-06-11https://www.enisa.europa.eu/news/cyber-europe-2026-all-eyes-on-the-eus-collective-response-and-resilience
- enki.co.krinlineENKI WhiteHat, 2026-05-27https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant
- esentire.cominlineeSentire TRU, 2026-05-12https://www.esentire.com/blog/tycoon-2fa-operators-adopt-oauth-device-code-phishing
- europol.europa.euinlineEuropol, 2026-06-24https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks
- fortiguard.fortinet.cominlineCWE-284 improper-access-control flaw in Fortinet FortiClient EMS 7.4.5 and 7.4.6https://fortiguard.fortinet.com/psirt/FG-IR-26-099
- genians.co.krinlineGenians, 2026-06-16https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat
- github.bloginlineGitHub Changelog, 2026-06-18https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/
- github.cominlineResearcher write-up (V4bel), 2026-05-07https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md
- github.cominlineHealthChecker.ps1https://github.com/microsoft/CSS-Exchange
- github.cominlineGitHub GHSA-2ww3-72rp-wpp4https://github.com/microsoft/semantic-kernel/security/advisories/GHSA-2ww3-72rp-wpp4
- github.cominlineGitHub GHSA-xjw9-4gw8-4rqxhttps://github.com/microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx
- github.cominlineGitHub Security Advisory GHSA-c9ph-gxww-7744, 2026-04-29https://github.com/thymeleaf/thymeleaf/security/advisories/GHSA-c9ph-gxww-7744
- grafana.cominlineGrafana Labs, 2026-05-19https://grafana.com/blog/grafana-labs-security-update-latest-on-tanstack-npm-supply-chain-ransomware-incident/
- hackread.cominlineHackread, 2026-05-16https://hackread.com/pwn2own-berlin-2026-hits-capacity-hackers-0-days/
- haveibeenpwned.cominlineHave I Been Pwnedhttps://haveibeenpwned.com/Breach/Charter
- heise.deinlineheise Securityhttps://www.heise.de/en/news/Too-many-zero-days-Microsoft-threatens-legal-action-11310736.html
- helpnetsecurity.cominlineHelp Net Security, 2026-04-29https://www.helpnetsecurity.com/2026/04/29/windows-cve-2026-32202-exploited/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-08https://www.helpnetsecurity.com/2026/05/08/dirty-frag-linux-vulnerability-cve-2026-43284-cve-2026-43500/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-12https://www.helpnetsecurity.com/2026/05/12/microsoft-may-2026-patch-tuesday/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-20https://www.helpnetsecurity.com/2026/05/20/github-breached-teampcp/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-22https://www.helpnetsecurity.com/2026/05/22/kali365-microsoft-365-phishing-fbi-warning/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-26https://www.helpnetsecurity.com/2026/05/26/sharepoint-vulnerability-cve-2026-45659/
- helpnetsecurity.cominlineHelp Net Securityhttps://www.helpnetsecurity.com/2026/06/01/windows-netlogon-rce-exploited-cve-2026-41089/
- helpnetsecurity.cominlineHelp Net Security forecasthttps://www.helpnetsecurity.com/2026/06/05/june-2026-patch-tuesday-forecast/
- helpnetsecurity.cominlineHelp Net Security, 2026-06-16https://www.helpnetsecurity.com/2026/06/16/dragonforce-microsoft-teams-malware-backdoor-turn/
- helpnetsecurity.cominlineHelp Net Security, 2026-06-17https://www.helpnetsecurity.com/2026/06/17/rogueplanet-zero-day-cve-2026-50656/
- helpnetsecurity.cominlineHelp Net Security, 2026-06-18https://www.helpnetsecurity.com/2026/06/18/eset-gentlemen-edr-killers/
- huntress.cominlineHuntress Labs' 2026-05-21 IR reporthttps://www.huntress.com/blog/the-gentlemen-ransomware-defense-evasion-ttps
- huntress.cominlineHuntress, 2026-06-03https://www.huntress.com/blog/unpatched-ntlm-leak-windows-search-uri-handler
- infosecurity-magazine.cominlineInfosecurity Magazine, 2026-05-20https://www.infosecurity-magazine.com/news/github-confirms-breach-vs-code/
- isc.sans.eduinlineSANS ISC diary 33016 — Mini Shai-Hulud framework / Microsoft SDKhttps://isc.sans.edu/diary/33016
- isc.sans.eduinlineSANS ISC Diary, 2026-05-04https://isc.sans.edu/diary/Cleartext+Passwords+in+MS+Edge+In+2026/32954/
- isc.sans.eduinlineSANS ISC, 2026-06-01https://isc.sans.edu/diary/rss/33034
- isc.sans.eduinlineSANS ISC, 2026-06-05https://isc.sans.edu/diary/rss/33054
- isc.sans.eduinlineSANS ISC, 2026-06-09https://isc.sans.edu/diary/rss/33064
- krebsonsecurity.cominlineKrebs on Security, 2026-05-12https://krebsonsecurity.com/2026/05/patch-tuesday-may-2026-edition/
- krebsonsecurity.cominlineKrebsOnSecurity, 2026-06-10https://krebsonsecurity.com/2026/06/who-runs-the-ransomware-group-the-gentlemen/
- labs.cloudsecurityalliance.orginlineCSA research notehttps://labs.cloudsecurityalliance.org/research/csa-research-note-shai-hulud-megalodon-supply-chain-cascade/
- labs.infoguard.chinlineInfoGuard, 2026-06-09https://labs.infoguard.ch/posts/ghost-sender/
- labs.watchtowr.cominlinewatchTowr Labs, 2026-06-12https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/
- learn.microsoft.cominlineASR rules referencehttps://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference
- learn.microsoft.cominlineMicrosoft Authentication Broker clienthttps://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-device-code
- learn.microsoft.cominlineEntra Conditional Access policyhttps://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-block-authentication-flows
- malwarebytes.cominlineMalwarebytes — Shub Stealer earlier wave, 2026-03https://www.malwarebytes.com/blog/threat-intel/2026/03/fake-cleanmymac-site-installs-shub-stealer-and-backdoors-crypto-wallets
- microsoft.cominlineMicrosoft Threat Intelligence, 2021-03-02https://www.microsoft.com/en-us/security/blog/2021/03/02/hafnium-targeting-exchange-servers/
- microsoft.cominlineMicrosoft Security Blog, 2026-05-01https://www.microsoft.com/en-us/security/blog/2026/05/01/cve-2026-31431-copy-fail-vulnerability-enables-linux-root-privilege-escalation/
- microsoft.cominlineMicrosoft Security Blog 2026-05-04https://www.microsoft.com/en-us/security/blog/2026/05/04/breaking-the-code-multi-stage-code-of-conduct-phishing-campaign-leads-to-aitm-token-compromise/
- microsoft.cominlineMicrosoft Security Blog, 2026-05-06https://www.microsoft.com/en-us/security/blog/2026/05/06/clickfix-campaign-uses-fake-macos-utilities-lures-deliver-infostealers/
- microsoft.cominlineMicrosoft Security Bloghttps://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/
- microsoft.cominlineMicrosoft Security Bloghttps://www.microsoft.com/en-us/security/blog/2026/05/08/active-attack-dirty-frag-linux-vulnerability-expands-post-compromise-risk/
- microsoft.cominlineMicrosoft Security Blog, 2026-05-12https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-finds-16-new-vulnerabilities/
- microsoft.cominlineMicrosoft Security Blog, 2026-05-12https://www.microsoft.com/en-us/security/blog/2026/05/12/undermining-the-trust-boundary-investigating-a-stealthy-intrusion-through-third-party-compromise/
- microsoft.cominlineMicrosoft Security Bloghttps://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/
- microsoft.cominlineMicrosoft Security Blog, 2026-05-18https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/
- microsoft.cominlineMicrosoft Threat Intelligence — Fox Tempesthttps://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/
- microsoft.cominlineMicrosoft Security Blog — search-poisoning cryptojackinghttps://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/
- microsoft.cominlineMicrosoft Threat Intelligence, 2026-05-28https://www.microsoft.com/en-us/security/blog/2026/05/28/the-gentlemen-ransomware-dissecting-a-self-propagating-go-encryptor/
- microsoft.cominlineMicrosoft, 2026-05-30https://www.microsoft.com/en-us/security/blog/2026/05/29/33-malicious-npm-packages-abuse-dependency-confusion-profile-developer-environments/
- microsoft.cominlineMicrosoft, 2026-06-08https://www.microsoft.com/en-us/security/blog/2026/06/08/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering/
- microsoft.cominlineMicrosoft Security, 2026-06-17https://www.microsoft.com/en-us/security/blog/2026/06/17/crypto-clipper-uses-tor-worm-like-propagation-for-persistence-control/
- microsoft.cominlineMicrosoft Security, 2026-06-17https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/
- microsoft.cominlineMicrosofthttps://www.microsoft.com/en-us/security/blog/2026/06/18/autojack-single-page-rce-host-running-ai-agent/
- microsoft.cominlineMicrosoft, 2026-06-24https://www.microsoft.com/en-us/security/blog/2026/06/24/stealc-and-amadey-breaking-down-infostealers-and-the-cybercrime-services-that-deliver-them/
- msrc.microsoft.cominlineMicrosoft MSRC, 2026-06-09https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-26142
- msrc.microsoft.cominlineMicrosoft MSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41089
- msrc.microsoft.cominlineMicrosoft MSRC — CVE-2026-41091https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091
- msrc.microsoft.cominlineMSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42822
- msrc.microsoft.cominlineMicrosoft MSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-42897
- msrc.microsoft.cominlineMSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45584
- msrc.microsoft.cominlineMSRC — CVE-2026-45585https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45585
- msrc.microsoft.cominlineMSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45657
- msrc.microsoft.cominline`CVE-2026-45659`https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-45659
- msrc.microsoft.cominlineMSRChttps://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-47291
- msrc.microsoft.cominlineMicrosoft MSRC, 2026-06-09https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-47643
- msrc.microsoft.cominlineMicrosoft MSRC, 2026-06-04https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-48579
- msrc.microsoft.cominlineMicrosoft MSRChttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32202
- msrc.microsoft.cominlineMSRC Security Update Guidehttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41089
- msrc.microsoft.cominlineMSRC Security Update Guidehttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41096
- msrc.microsoft.cominlineMSRC Security Update Guidehttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41103
- msrc.microsoft.cominlineMicrosoft MSRChttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42824
- msrc.microsoft.cominlineMSRC Security Update Guidehttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42898
- msrc.microsoft.cominlineMicrosoft MSRChttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45585
- msrc.microsoft.cominlineMSRChttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50656
- ncsc.admin.chinlineNCSC-CH, 2026-06-23https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2026/wochenrueckblick_25.html
- noscope.cominlineNoScope, 2026-05-25https://www.noscope.com/blog/gitea-instances-exposing-private-container
- nottingham.ac.ukinlineUniversity of Nottingham, 2026-06-10https://www.nottingham.ac.uk/currentstudents/news/student-and-alumni-data-has-been-compromised-in-a-data-security-incident
- novee.securityinlineNovee Security, 2026-06-23https://novee.security/blog/cordyceps/
- nvd.nist.govinlineNVD — CVE-2026-32202https://nvd.nist.gov/vuln/detail/CVE-2026-32202
- nvd.nist.govinlineCISA KEV since 2026-04-06https://nvd.nist.gov/vuln/detail/CVE-2026-35616
- oasis.securityinlineOasis Security 2026-05-07https://www.oasis.security/blog/cline-kanban-websocket-hijack
- obsidiansecurity.cominlineObsidian, 2026-06-16https://www.obsidiansecurity.com/blog/litellm-privilege-escalation-rce
- opensourcemalware.cominlineOpenSourceMalwarehttps://opensourcemalware.com/blog/miasma-reaches-azure
- openwall.cominlineoss-security, 2026-06-03https://www.openwall.com/lists/oss-security/2026/06/03/3
- oracle.cominlineOracle, 2026-06-10https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
- permiso.ioinlinePermiso Security — ChatGPhishhttps://permiso.io/blog/chatgpt-markdown-rendering-vulnerability
- posthogstatus.cominlinePostHog status, 2026-05-30https://www.posthogstatus.com/incidents/01KSV6HJYKG5QJAP8HVTSQVSM1
- proofpoint.cominlineProofpoint/IBM X-Force, 2026-06-24https://www.proofpoint.com/us/blog/threat-insight/stealc-you-later-proofpoint-and-ibm-x-force-support-operation-endgame
- pushsecurity.cominlinePush Security — LLMSharehttps://pushsecurity.com/blog/llmshare-malvertising-campaign
- rapid7.cominlineRapid7, 2026-06-09https://www.rapid7.com/blog/post/em-patch-tuesday-june-2026
- rapid7.cominlineRapid7 — Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomwarehttps://www.rapid7.com/blog/post/tr-muddying-tracks-state-sponsored-shadow-behind-chaos-ransomware/
- redcanary.cominlineRed Canary, 2026-06-08https://redcanary.com/blog/threat-detection/entra-id-ai-workflows-assistive-agents/
- redcanary.cominlineRed Canary — Entra Agent IDhttps://redcanary.com/blog/threat-detection/entra-id-ai-workflows/
- reliaquest.cominlineReliaQuest, 2026-06-05https://reliaquest.com/blog/threat-spotlight-reliaquests-agentic-ai-uncovers-new-china-linked-cluster-op-512
- research.checkpoint.cominlineCheck Point Research, 2026-05-13https://research.checkpoint.com/2026/thus-spoke-the-gentlemen/
- research.jfrog.cominlineJFrog, 2026-06-22https://research.jfrog.com/post/from-postcss-typosquat-to-windows-rat/
- research.jfrog.cominlineJFrog Security Research — IronWormhttps://research.jfrog.com/post/iron-worm-shai-hulud-rustier-cousin/
- seclists.orginlineCalif/oss-securityhttps://seclists.org/oss-sec/2026/q2/790
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub #12574, 2026-05-14https://security-hub.ncsc.admin.ch/#/posts/12574
- security-hub.ncsc.admin.chinlineNCSC.ch Security Hub #12577https://security-hub.ncsc.admin.ch/#/posts/12577
- security-hub.ncsc.admin.chinlineNCSC-CH post 12594https://security-hub.ncsc.admin.ch/#/posts/12594
- security-hub.ncsc.admin.chinlineNCSC-CH, 2026-06-09https://security-hub.ncsc.admin.ch/#/posts/12619
- security-hub.ncsc.admin.chinlineNCSC-CH CSH, 2026-06-11https://security-hub.ncsc.admin.ch/#/posts/12622
- security-hub.ncsc.admin.chinlineNCSC-CH Security Hub post 12547, 2026-05-08https://security-hub.ncsc.admin.ch/api/posts/12547/details
- security-hub.ncsc.admin.chinlineNCSC.ch Security Hub #12577https://security-hub.ncsc.admin.ch/api/posts/12577/details
- security.cominlineSymantec / Broadcom, 2026-06-16https://www.security.com/threat-intelligence/dragonforce-msteams-backdoor
- security.cominlineBroadcom/Symantec, 2026-06-03https://www.security.com/threat-intelligence/stock-exchange-espionage
- securityaffairs.cominlineSecurity Affairs, 2026-05-30https://securityaffairs.com/192907/uncategorized/shinyhunters-leaks-charter-communications-data-potentially-impacting-5-million-customers.html
- securityaffairs.cominlineSecurity Affairs, 2026-06-11https://securityaffairs.com/193530/hacking/cve-2026-10520-exploited-ivanti-sentry-gateways-compromised-shortly-after-patch-release.html
- securityweek.cominlineSecurityWeek, 2026-06-02https://www.securityweek.com/exclusive-how-one-line-of-code-put-billions-of-microsoft-android-app-downloads-at-risk/
- securityweek.cominlineSecurityWeek, 2026-06-24https://www.securityweek.com/exploitable-ci-cd-vulnerabilities-expose-millions-of-repositories-to-hijacking/
- securityweek.cominlineSecurityWeekhttps://www.securityweek.com/greatxml-zero-day-exploit-bypasses-bitlocker/
- securityweek.cominlineSecurityWeek, 2026-06-03https://www.securityweek.com/hackers-target-global-stock-exchange-in-espionage-operation/
- securityweek.cominlineSecurityWeek — Iranian APT intrusion masquerades as Chaos ransomware attackhttps://www.securityweek.com/iranian-apt-intrusion-masquerades-as-chaos-ransomware-attack/
- securityweek.cominlineSymantec, 2026-06-24https://www.securityweek.com/new-mistic-rat-opens-door-to-several-ransomware-families/
- securityweek.cominlineSecurityWeek, 2026-06-10https://www.securityweek.com/new-windows-zero-day-exploit-rogueplanet-released/
- securityweek.cominlineSecurityWeek, 2026-06-11https://www.securityweek.com/oracle-addresses-peoplesoft-vulnerability-amid-reports-of-zero-day-attacks/
- seqrite.cominlineSeqrite Labs, 2026-06-01https://www.seqrite.com/blog/operation-dragon-weave-uncovering-a-china-linked-campaign-targeting-czech-republic-and-taiwan-using-azure-cloud-c2/
- seqrite.cominlineSeqrite Labs, 2026-05-29https://www.seqrite.com/blog/operation-xenofiscal-sidecopy-deploying-persistent-xenorat-targeting-the-mof-afghanistan/
- snyk.ioinlineSnyk, 2026-06-16https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/
- socket.devinlineSocket — TrapDoorhttps://socket.dev/blog/trapdoor-crypto-stealer-npm-pypi-crates
- sonatype.cominlineSonatype, 2026-05-28https://www.sonatype.com/blog/inside-a-176-package-npm-campaign-built-to-beat-your-internal-dependencies
- sophos.cominlineSophos bloghttps://www.sophos.com/en-us/blog/sophos-state-of-identity-security-2026
- stepsecurity.ioinlineStepSecurityhttps://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials
- stepsecurity.ioinlineStepSecurityhttps://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents
- sysdig.cominlineSysdig TRT — LLM-agent post-exploitationhttps://www.sysdig.com/blog/ai-agent-at-the-wheel-how-an-attacker-used-llms-to-move-from-a-cve-to-an-internal-database-in-4-pivots
- techcommunity.microsoft.cominlineMS Exchange Bloghttps://techcommunity.microsoft.com/blog/exchange/addressing-exchange-server-may-2026-vulnerability-cve-2026-42897/4518498
- techcommunity.microsoft.cominlineMicrosoft, 2021-09-28https://techcommunity.microsoft.com/blog/exchange/new-security-feature-in-september-2021-cumulative-update-for-exchange-server/2783477
- techzine.euinlineTechzine, 2026-02-16https://www.techzine.eu/news/security/138806/data-breach-at-odido-responsibility-and-compensation-under-discussion/
- tenable.cominlineTenablehttps://www.tenable.com/blog/microsofts-june-2026-patch-tuesday-addresses-198-cves-cve-2026-49160-cve-2026-50507
- tenable.cominlineTenable, 2026-05-12https://www.tenable.com/blog/microsofts-may-2026-patch-tuesday-addresses-118-cves-cve-2026-41103
- thedfirreport.cominlineThe DFIR Report's 2026-05-11 alerthttps://thedfirreport.com/2026/05/11/flash-alert-etherrat-and-tuktuk-c2-end-in-the-gentleman-ransomware/
- thehackernews.cominlineThe Hacker News, 2026-05-27https://thehackernews.com/2026/05/ai-chatbot-recommendations-redirect.html
- thehackernews.cominlineThe Hacker News, 2026-05-15https://thehackernews.com/2026/05/four-openclaw-flaws-enable-data-theft.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/ghostwriter-targets-ukrainian.html
- thehackernews.cominlineThe Hacker News, 2026-05-27https://thehackernews.com/2026/05/gitea-vulnerability-exposes-private.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/github-investigating-teampcp-claimed.html
- thehackernews.cominlineThe Hacker News, 2026-05-29https://thehackernews.com/2026/05/kimsuky-deploys-httpspy-expands-arsenal.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/05/microsoft-warns-of-two-actively.html
- thehackernews.cominlineThe Hacker News, 2026-05-19https://thehackernews.com/2026/05/mini-shai-hulud-pushes-malicious-antv.html
- thehackernews.cominlineThe Hacker News, 2026-05-18https://thehackernews.com/2026/05/miniplasma-windows-0-day-enables-system.html
- thehackernews.cominlineThe Hacker News, 2026-05-15https://thehackernews.com/2026/05/on-prem-microsoft-exchange-server-cve.html
- thehackernews.cominlineThe Hacker News 2026-05-04https://thehackernews.com/2026/05/progress-patches-critical-moveit.html
- thehackernews.cominlineThe Hacker News, 2026-05-25https://thehackernews.com/2026/05/trapdoor-supply-chain-attack-spreads.html
- thehackernews.cominlineThe Hacker News — Turla Kazuarhttps://thehackernews.com/2026/05/turla-turns-kazuar-backdoor-into.html
- thehackernews.cominlineThe Hacker News, 2026-05-20https://thehackernews.com/2026/05/webworm-deploys-echocreep-and-graphworm.html
- thehackernews.cominlineThe Hacker News, 2026-06-19https://thehackernews.com/2026/06/autojack-attack-lets-one-web-page.html
- thehackernews.cominlineThe Hacker News, 2026-06-04https://thehackernews.com/2026/06/china-linked-ta4922-expands-phishing.html
- thehackernews.cominlineThe Hacker News, 2026-06-17https://thehackernews.com/2026/06/fake-microsoft-alerts-used-to-deploy.html
- thehackernews.cominlineThe Hacker News, 2026-06-23https://thehackernews.com/2026/06/malicious-npm-packages-pose-as-postcss.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/miasma-worm-hits-73-microsoft-github.html
- thehackernews.cominlineThe Hacker News, 2026-06-03https://thehackernews.com/2026/06/microsoft-365-android-apps-let-any-app.html
- thehackernews.cominlineThe Hacker News, 2026-06-17https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html
- thehackernews.cominlineThe Hacker News, 2026-06-18https://thehackernews.com/2026/06/microsoft-details-windows-clipper.html
- thehackernews.cominlineThe Hacker News, 2026-06-04https://thehackernews.com/2026/06/one-click-github-dev-attack-lets.html
- thehackernews.cominlineThe Hacker News, 2026-06-15https://thehackernews.com/2026/06/one-click-microsoft-365-copilot-flaw.html
- thehackernews.cominlineThe Hacker News, 2026-06-02https://thehackernews.com/2026/06/pakistan-linked-sidecopy-targets.html
- thehackernews.cominlineThe Hacker News, 2026-06-11https://thehackernews.com/2026/06/the-gentlemen-ransomware-claims-478.html
- thehackernews.cominlineThe Hacker News, 2026-06-03https://thehackernews.com/2026/06/unpatched-windows-search-uri.html
- thehackernews.cominlineThe Hacker Newshttps://thehackernews.com/2026/06/verdantbamboo-deploys-bsd-variant-of.html
- thehackernews.cominlineThe Hacker News, 2026-06-23https://thehackernews.com/2026/06/whatsapp-vbscript-campaign-uses-fake.html
- therecord.mediainlineThe Record, 2026-05-22https://therecord.media/fbi-warns-of-kali365-phishing-attacks
- therecord.mediainlineThe Record, 2026-05-20https://therecord.media/github-confirms-teampcp-hack-customers-unaffected
- therecord.mediainlineRecorded Future News, 2026-05-19https://therecord.media/huawei-zero-day-behind-last-year-luxembourg-telecom-outage
- therecord.mediainlineThe Recordhttps://therecord.media/microsoft-calls-zero-day-releases-never-justifiable-as-researcher-threatens-more
- therecord.mediainlineThe Record, 2026-05-19https://therecord.media/microsoft-disrupts-fox-tempest-malware-signing-service
- therecord.mediainlineThe Record, 2026-06-11https://therecord.media/university-of-nottingham-cyber-incident-shiny-hunters
- theregister.cominlineThe Register, 2026-02-27https://www.theregister.com/2026/02/27/odido_shinyhunters_leaks/
- theregister.cominlineThe Register, 2026-05-22https://www.theregister.com/cyber-crime/2026/05/22/fbi-warns-of-kali365-as-device-code-phishing-soars/5245024
- theregister.cominlineThe Register, 2026-05-13https://www.theregister.com/patches/2026/05/13/doozy-of-a-patch-tuesday-includes-30-critical-microsoft-cves/5239224
- theregister.cominlineThe Register, 2026-05-13https://www.theregister.com/security/2026/05/13/disgruntled-researcher-releases-two-more-microsoft-zero-days/5239758
- theregister.cominlineThe Register, 2026-06-11https://www.theregister.com/security/2026/06/11/nightmare-eclipse-drops-claimed-bitlocker-bypass-for-microsoft-windows/5254371
- thezdi.cominlineZDI, 2026-05-12https://www.thezdi.com/blog/2026/5/12/the-may-2026-security-update-review
- thezdi.cominlineZDI, 2026-05-13https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-day-one-results
- thezdi.cominlineZDI Pwn2Own Day Twohttps://www.thezdi.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results
- thezdi.cominlineZDI, 2026-05-16https://www.thezdi.com/blog/2026/5/16/pwn2own-berlin-2026-day-three-results-and-master-of-pwn
- threatlocker.cominlineThreatLocker — exploitation on fully-patched systemshttps://www.threatlocker.com/blog/miniplasma-windows-privilege-escalation-zero-day-affects-fully-patched-systems
- unit42.paloaltonetworks.cominlineUnit 42, 2026-05-11https://unit42.paloaltonetworks.com/active-directory-certificate-services-exploitation/
- unit42.paloaltonetworks.cominlineUnit 42, 2026-06-22https://unit42.paloaltonetworks.com/cloud-bucket-hijacking-risks/
- unit42.paloaltonetworks.cominlineUnit 42 — Copy Failhttps://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/
- unit42.paloaltonetworks.cominlineUnit 42https://unit42.paloaltonetworks.com/hijacking-vertex-ai-model/
- unit42.paloaltonetworks.cominlineUnit 42, 2026-06-08https://unit42.paloaltonetworks.com/microsoft-teams-phishing/
- unit42.paloaltonetworks.cominlineUnit 42 — ROADtools cloud attackshttps://unit42.paloaltonetworks.com/roadtools-cloud-attacks/
- unit42.paloaltonetworks.cominlineUnit 42, 2026-05-22https://unit42.paloaltonetworks.com/tracking-iran-apt-screening-serpens/
- varonis.cominlineVaronishttps://www.varonis.com/blog/searchleak
- veeam.cominlineVeeam shipped KB4852 / Backup & Replication patch version 13.0.2.29 on 2026-05-27https://www.veeam.com/kb4852
- volexity.cominlineVolexity — OAuth device-code backgroundhttps://www.volexity.com/blog/2025/04/22/phishing-for-codes-russian-threat-actors-target-microsoft-365-oauth-workflows/
- volexity.cominlineVolexityhttps://www.volexity.com/blog/2026/06/04/verdantbamboo-just-another-brickstorm-in-the-firewall/
- welivesecurity.cominlineESET, 2026-06-24https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/
- welivesecurity.cominlineESET WeLiveSecurityhttps://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/
- welivesecurity.cominlineESET, 2026-06-18https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/
- welivesecurity.cominlineESET WeLiveSecurity, 2026-06-11https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/
- welivesecurity.cominlineESET Research, 2026-05-20https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/
- wid.cert-bund.deinlineBSI WID-SEC-2026-1536, 2026-05-14https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1536
- wiz.ioinlineWiz Researchhttps://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc
- wiz.ioinlineWiz, 2026-05-20https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack
- wiz.ioinlineWiz Researchhttps://www.wiz.io/blog/miasma-supply-chain-attack-targeting-redhat-npm-packages
- wpscan.cominlineWPScan, 2026-06-11https://wpscan.com/vulnerability/68addf8c-9ea6-4b62-9f85-e95350b3992e/
- xenbits.xen.orginlineXSA-490https://xenbits.xen.org/xsa/advisory-490.html
- zerodayinitiative.cominlineZero Day Initiative, 2026-05-15https://www.zerodayinitiative.com/blog/2026/5/15/pwn2own-berlin-2026-day-two-results
- zscaler.cominlineZscaler, 2026-06-23https://www.zscaler.com/blogs/security-research/payouts-king-ransomware-initial-access-broker-deploys-new-edgecution
Items in briefs about Microsoft Office Equation Editor RCE (cited as veteran exploit by Kaspersky Q1 2026 exploit report)
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.