Загрузка...

i got owned with zero clicks (outlook, 6 hrs) #Shorts

Microsoft's April 2026 Patch Tuesday silently patched a zero-click Outlook RCE — no user interaction, no attachment, no link required. A malformed MIME header triggers pre-auth code execution before the preview pane renders, hitting the Exchange mailbox service account directly. My EDR flagged lateral movement only post-execution, meaning detection lag is a real problem even with endpoint coverage. KB5055523 closes the gap, but unpatched tenants right now are fully exposed to a pre-auth deserialization chain over a trusted mail protocol. Has your team already pushed this patch, or is it sitting in a change-freeze queue?

Full story: https://krebsonsecurity.com/2026/04/patch-tuesday-april-2026-edition/

▶ Previous: i sold zero-days to nations ($1.5m, fbi found me) #Shorts — https://youtube.com/shorts/gXzLvQnRAlM

---

Protect your accounts with a YubiKey: https://amzn.to/4sHWviK
Free website vulnerability scanner: https://websec.pfdatastack.com

Episode 204 | New cybersecurity short every day.
🌐 https://cybershorts.pfdatastack.com

#Shorts #cybersecurity #hacking #infosec #ethicalhacking #cyberattack #realhacking #privacy #techeducation #phishing #microsoft

Видео i got owned with zero clicks (outlook, 6 hrs) #Shorts канала CyberShorts
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять