Microsoft says hackers are exploiting critical zero-day bugs to target Windows and Office users

Microsoft says hackers are exploiting critical zero-day bugs to target Windows and Office users

Microsoft has announced the deployment of critical security updates aimed at addressing vulnerabilities in its Windows operating system and Office suite. These vulnerabilities, known to be actively exploited by cybercriminals, allow attackers to infiltrate systems with minimal user engagement. The exploits involve one-click attacks, enabling malicious actors to install malware or gain unauthorized access simply by deceiving users into clicking harmful links. Specifically, two identified flaws can be triggered when a user interacts with a malicious link on their Windows device, while another vulnerability arises from opening a compromised Office document. These vulnerabilities are classified as zero-days, meaning hackers have taken advantage of these flaws before Microsoft had the opportunity to issue fixes. The company has noted that details on how these exploits function have been publicly disclosed, which may raise the risk of further attacks. In their security reports, Microsoft acknowledged the assistance of the security researchers from Google’s Threat Intelligence Group, who played a key role in uncovering these vulnerabilities. One significant flaw, identified as CVE-2026-21510, resides within the Windows shell, which is integral to the operating system's user interface. This flaw affects all supported versions of Windows and allows hackers to bypass Microsoft's SmartScreen feature, which typically protects against malicious links and files. Security expert Dustin Childs emphasized the rarity of such one-click vulnerabilities that can lead to code execution, noting that user interaction is required, albeit minimal. A spokesperson from Google confirmed that the vulnerability in the Windows shell is currently under widespread exploitation, enabling the silent execution of malware with elevated privileges, thereby posing a serious risk of system compromise, ransomware deployment, or data theft. Additionally, another vulnerability, tracked as CVE-2026-21513, was discovered in Microsoft’s MSHTML browser engine, which is still present in newer versions of Windows for compatibility with older applications. This flaw similarly allows attackers to circumvent Windows security measures to install malware. Furthermore, reports indicate that Microsoft has patched three additional zero-day vulnerabilities that were also being actively exploited by hackers.

Sources : TechCrunch

Published On : Feb 11, 2026, 21:05

Startups
India's Workforce Faces Readiness Crisis Amidst AI Evolution

According to the recently released India Skills Gap Report 2026 by NIIT, the real issue facing India's workforce isn't a...

Business Today | Mar 31, 2026, 05:50
India's Workforce Faces Readiness Crisis Amidst AI Evolution
Startups
LiteLLM Cuts Ties with Delve Amid Security Concerns

LiteLLM, a leading provider of AI gateway solutions favored by millions of developers, has made a significant decision t...

TechCrunch | Mar 30, 2026, 23:15
LiteLLM Cuts Ties with Delve Amid Security Concerns
AI
Middle East's AI Ambitions Facing Turbulence Amid Ongoing Conflict

Last spring, President Donald Trump made a significant visit to the Middle East, aiming to position the Gulf region as a...

CNN | Mar 31, 2026, 03:40
Middle East's AI Ambitions Facing Turbulence Amid Ongoing Conflict
Startups
Whistleblower Reignites Controversy Over Delve's Compliance Practices

In a dramatic turn of events, the anonymous whistleblower known as DeepDelver has resurfaced, intensifying allegations a...

TechCrunch | Mar 30, 2026, 18:55
Whistleblower Reignites Controversy Over Delve's Compliance Practices
AI
AI Revolutionizes Operations at California's Diablo Canyon Nuclear Power Plant

California's Diablo Canyon Power Plant, the last operational nuclear facility in the state, is embracing artificial inte...

Business Insider | Mar 30, 2026, 18:45
AI Revolutionizes Operations at California's Diablo Canyon Nuclear Power Plant
View All News