Microsoft Vulnerabilities Drop, But Critical Flaws Double, Report Warns

2026-04-21T20:51:39Z1c17d21afb92191cd3ba4394122358c641548dcb8173d18a88f9bb2b225e0af2
Microsoftazurebrowser-extensioncloudcryptocurrency-exchangedata-breachincident-responsemalwarenpmofficeprotobuf.jsrcescattered-spidershinyhunterssupply-chainthreat-actorvulnerability

What happened

Feed of security news: Microsoft reported fewer overall vulnerabilities but a doubling of critical flaws affecting Office, Azure and cloud components; a critical RCE in the widely used protobuf.js (52M downloads) allows remote code execution via malicious schemas; malicious Chrome/Edge TikTok downloader extensions are spying on ~130,000 users; Vercel confirmed a breach linked to Context.ai with data being sold; Grinex crypto exchange shut down after a $13.7M incident and exit-scam/sanctions-evasion concerns; and other industry updates including a guilty plea by a Scattered Spider-linked actor.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
1c17d21afb92191cd3ba4394122358c641548dcb8173d18a88f9bb2b225e0af2
Enrichment time
2026-04-21T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft Vulnerabilities Drop, But Critical Flaws Double, Report Warns · Baitaphish