04/24

Patch Diffing CVE-2026-21509: Microsoft Office OLE Security Bypass

https://blog.78researchlab.com/34cdb461-3e5b-808d-a9c9-dc1338adaccc
Patch Diffing CVE-2026-21509: Microsoft Office OLE Security Bypass

Mark Dowd on the zero-day exploit marketplace - YouTube

https://youtu.be/NEDlOKHG8nY?si=YmyMWlDMWUb67dtr
Mark Dowd on the zero-day exploit marketplace - YouTube

Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet | WIRED

https://www.wired.com/story/fast16-malware-stuxnet-precursor-iran-nuclear-attack/
Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet | WIRED

LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

https://thehackernews.com/2026/04/lmdeploy-cve-2026-33626-flaw-exploited.html
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure

GopherWhisper: A burrow full of malware

https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/
GopherWhisper: A burrow full of malware