Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack
2026-04-29T19:24:05Z•c5d872889e0beaf05bf582eeda2f14a0f3738caaa18d5929709597615885dda4
adt breachcarnivalcheckmarxcisaclawhub crypto miningdata breachexchange onlinefederal agency compromisefirestarter backdoorgithub infrastructuregoDaddy domain transfergrassmarlinlapsus$medtronic breachmicrosoftnsapitney bowesransomware (wiper)rdp securityremote desktopshinyhunterssupply-chain attacktls 1.0 1.1 deprecationvect wiperwindows zero-click
What happened
A bundle of active threats and high-impact disclosures: Microsoft is wrestling with a zero-click Windows 0-day (reportedly exploited by Russian actors) where an initial patch left systems still at risk. CISA flagged a data-exfiltration vulnerability in the NSA-built OT tool GrassMarlin, and researchers disclosed a critical GitHub infrastructure flaw that allowed remote read/write of private repos. Multiple supply‑chain and extortion incidents continue — Checkmarx and other security/dev tooling vendors were targeted (Lapsus$ claims), ShinyHunters and others alleged large data dumps (Pitney Bowe
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- c5d872889e0beaf05bf582eeda2f14a0f3738caaa18d5929709597615885dda4
- Enrichment time
- 2026-04-29T19:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.