Microsoft Vulnerabilities Drop, But Critical Flaws Double, Report Warns
2026-04-21T20:51:39Z•1c17d21afb92191cd3ba4394122358c641548dcb8173d18a88f9bb2b225e0af2
Microsoftazurebrowser-extensioncloudcryptocurrency-exchangedata-breachincident-responsemalwarenpmofficeprotobuf.jsrcescattered-spidershinyhunterssupply-chainthreat-actorvulnerability
What happened
Feed of security news: Microsoft reported fewer overall vulnerabilities but a doubling of critical flaws affecting Office, Azure and cloud components; a critical RCE in the widely used protobuf.js (52M downloads) allows remote code execution via malicious schemas; malicious Chrome/Edge TikTok downloader extensions are spying on ~130,000 users; Vercel confirmed a breach linked to Context.ai with data being sold; Grinex crypto exchange shut down after a $13.7M incident and exit-scam/sanctions-evasion concerns; and other industry updates including a guilty plea by a Scattered Spider-linked actor.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 1c17d21afb92191cd3ba4394122358c641548dcb8173d18a88f9bb2b225e0af2
- Enrichment time
- 2026-04-21T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.