Vulnerabilities
APT28's Zero-Day Got a Patch — Then Researchers Found It Left a Zero-Click Hole Open
Microsoft's February patch for a Windows zero-day actively exploited by Russia's APT28 blocked the remote code execution path — but left behind a zero-click authentication coercion flaw. Akamai researchers found it while testing the fix. That flaw is now CVE-2026-32202, confirmed exploited in the wild, and added