01 Oct, 2026

Microsoft working on Defender patch for ShieldBreak zero-day

On Friday, Microsoft confirmed it has begun working on a security patch for a Defender zero-day vulnerability named “ShieldBreak.” A security researcher who uses the “Nightmare Eclipse” handle disclosed this privilege escalation vulnerability after Microsoft released the August 2026 Patch Tuesday security updates. ​”Microsoft is aware of the reported vulnerability and is actively investigating the […]

3 mins read

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has released security patches to address a Windows zero-day vulnerability known as “LegacyHive,” disclosed after the July 2026 Patch Tuesday. The security flaw was disclosed by a security researcher who uses the “Nightmare Eclipse” handle in protest of Microsoft’s bug bounty and vulnerability disclosure practices. Nightmare Eclipse published a LegacyHive proof-of-concept (PoC) exploit hours […]

2 mins read

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have disclosed new “Plug and Pwn” attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. The research, presented at DEF CON 34 by security researchers Alejandro Hernando and Borja Martínez, exploits how Windows automatically identifies new connected hardware, locates matching driver packages, and installs […]

8 mins read

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. Microsoft addressed the flaw in this month’s Patch Tuesday security updates, marking it as actively exploited in the wild. Researchers found that the Lazarus threat group has been leveraging it since early July. Microsoft […]

3 mins read

New Certighost PoC exploit lets attackers hijack Windows domains

A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. Tracked as CVE-2026-54121, the vulnerability was fixed by Microsoft as part of the July 2026 Patch Tuesday security updates. “An authenticated attacker could manipulate attributes associated with a machine account and obtain […]

4 mins read

Microsoft shares manual fix for WSUS sync delays and timeouts

Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. This known WSUS sync issue affects both client (Windows 10, version 1607 and later) and server (Windows Server 2012 and later) platforms. On impacted WSUS servers, […]

2 mins read

Windows LegacyHive zero-day flaw gets free, unofficial patches

Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. The vulnerability (dubbed LegacyHive and without a CVE ID for easy tracking) was found by a security researcher using the “Nightmare Eclipse” handle in the Windows User Profile Service. Nightmare Eclipse disclosed it the day […]

3 mins read

Microsoft confirms Windows Server Update Services sync delays

Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. WSUS was introduced almost twenty years ago to help IT administrators schedule updates for Microsoft products on enterprise networks from a single local update server, rather than updating each endpoint […]

2 mins read

Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

Microsoft has released emergency updates to fix a known issue causing some Dell PCs to experience performance issues or shut down after installing the July 2026 Windows 11 security updates. As detailed when Microsoft acknowledged the issue on Tuesday, it affects only Dell systems that have installed the KB5101650 cumulative update on Windows 11 25H2 and 24H2 devices. […]

2 mins read

New Windows LegacyHive zero-day gives hackers admin privileges

A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. Nightmare Eclipse published a proof-of-concept (PoC) exploit hours after Microsoft released its July 2026 Patch Tuesday updates, saying that it abuses a security vulnerability in the Windows User Profile […]

2 mins read