Zero Day Room
Live

Windows Server

Everything filed under microsoft in our cybersecurity coverage, the 18 reports filed on it so far.

Microsoft confirms the optional September 2026 KB5124010 preview update for Windows 11 causes crashes in some games and...

Windows 11 KB5124010 update crashes apps using AC-3 audio

Microsoft confirms the optional September 2026 KB5124010 preview update for Windows 11 causes crashes in some games and applications that use AC-3...

2026-10-05
Kiteworks advised customers worldwide to shut down servers for a six-hour window on Saturday, September 26, based on...

Kiteworks issues global server shutdown advisory

Kiteworks advised customers worldwide to shut down servers for a six-hour window on Saturday, September 26, based on credible threat intelligence.

2026-09-26
Tech: F5 has released hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in BIG-IP APM

F5 Patches Critical BIG-IP APM Zero-Day Exploited for RCE

F5 has released hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in BIG-IP APM. The flaw, a heap-based buffer overflow with a CVSS...

2026-09-23
Check Point has disclosed that a critical zero-day vulnerability in its Security Management Server was exploited in...

Check Point Zero-Day Exploited in Targeted July Attacks

Check Point has disclosed that a critical zero-day vulnerability in its Security Management Server was exploited in targeted attacks in July.

2026-09-22
A new exploit kit called BlueMoon, which chains three recent zero-day vulnerabilities in Chrome and Windows, has been...

BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days

A new exploit kit called BlueMoon, which chains three recent zero-day vulnerabilities in Chrome and Windows, has been rapidly adopted by multiple...

2026-09-13
Tech: Four espionage groups, including APT31, used the new BlueMoon exploit kit in late August and early September 2026

APT31 and Three Spy Groups Deploy BlueMoon Chrome-Windows Exploit Kit

Four espionage groups, including APT31, used the new BlueMoon exploit kit in late August and early September 2026.

2026-09-10
Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two Windows zero-days under...

Microsoft Patches Record 974 Flaws, Two Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two Windows zero-days under active exploitation. The U.S.

2026-09-09
Stacklok has released ToolHive, an open-source platform for securely running Model Context Protocol servers inside...

Stacklok releases open-source ToolHive for secure MCP server

Stacklok has released ToolHive, an open-source platform for securely running Model Context Protocol servers inside isolated containers.

2026-09-07
Elastic Security Labs has identified four new programs linked to the REVSTEALER infostealer that persist after the main...

REVSTEALER Leaves Four Modules to Disable Windows Security

Elastic Security Labs has identified four new programs linked to the REVSTEALER infostealer that persist after the main malware deletes itself.

2026-09-06
Group-IB researchers detail the BraZetsu malware framework, used by the Exilware group to compromise Windows hosts and...

BraZetsu Malware Fuels Criminal Access Marketplace

Group-IB researchers detail the BraZetsu malware framework, used by the Exilware group to compromise Windows hosts and sell access on an underground...

2026-09-03
A Chinese threat group dubbed Silver Fox is running a malware campaign using counterfeit software download sites to...

Silver Fox Campaign Cripples Windows Security

A Chinese threat group dubbed Silver Fox is running a malware campaign using counterfeit software download sites to deliver malicious installers.

2026-09-02
Q2 2026 saw unprecedented CVE registrations driven by AI adoption, with critical vulnerabilities spiking and exploits for...

CISA Advisory Critical Vulnerability CVE-2026-44772

Q2 2026 saw unprecedented CVE registrations driven by AI adoption, with critical vulnerabilities spiking and exploits for unpatched flaws published...

2026-08-27
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery...

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert...

2026-08-21
Adversa AI discloses a new attack technique that can cause xAI's Grok chatbot to send user data to an attacker-controlled...

New Cryptographic Context Injection Attack Puts Grok Chat Data at Risk

Adversa AI discloses a new attack technique that can cause xAI's Grok chatbot to send user data to an attacker-controlled server.

2026-08-20
Cybersecurity researchers have discovered a new typosquatting campaign targeting RubyGems users with a Windows-based...

Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

Cybersecurity researchers have discovered a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. The...

2026-08-19
Microsoft has released its monthly security updates, addressing 398 flaws, including a Windows driver zero-day under...

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack

Microsoft has released its monthly security updates, addressing 398 flaws, including a Windows driver zero-day under active attack.

2026-08-17
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter...

Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access

Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from...

2026-08-16
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched...

Lazarus Group Exploits Windows Zero-Day Vulnerability to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting...

2026-08-16