Microsoft shipped fixes for 167 vulnerabilities, including an exploited SharePoint Server zero-day (CVE-2026-32201) and a publicly disclosed Windows Defender weakness dubbed “BlueHammer.” The update wave lands alongside Google Chrome’s fourth zero-day of 2026 and an emergency Adobe Reader patch for an actively exploited RCE, underscoring a compressed window from disclosure to exploitation. Prioritize internet-exposed SharePoint, Windows networking (including IKE/IPsec), and Defender platform updates, and fast-track browser and Reader patches across fleets.
Source: KrebsOnSecurity
Adobe fixes Acrobat/Reader zero-day exploited for months
Adobe released patches for Acrobat DC, Reader DC, and Acrobat 2024 to close a PDF zero-day that attackers have abused since at least November 2025. While details are limited, evidence points to targeted exploitation in the wild; Adobe urges immediate updates to mitigate ongoing risk.
Source: TechCrunch
OpenSSL 4.0.0 lands with post-quantum support and protocol retirements
The OpenSSL 4.0.0 release drops long-deprecated SSLv3 and SSLv2 client hello and removes the legacy engine API, while adding Encrypted Client Hello and post-quantum cryptography support. The update introduces API-level changes that will require code modifications for downstream applications—teams should plan upgrade testing now to avoid breakage while adopting stronger crypto primitives.
Source: Help Net Security
FBI dismantles “W3LL” phishing service that sold turnkey kits for $500
U.S. and Indonesian authorities took down W3LL, a phishing kit operation tied to more than $20 million in attempted fraud. For roughly $500, buyers got near-perfect replicas of trusted login portals to harvest credentials at scale—another reminder that commoditized phishing tooling continues to shrink barriers for attackers.
Source: Help Net Security
Probing for AI models spikes: new scans target Claude, Hugging Face, and more
DShield sensors began logging widespread probes on March 10 for AI model endpoints (e.g., “claude,” “openclaw,” “huggingface”), with activity continuing since. The pattern suggests reconnaissance for exposed inference APIs and agent services—defenders should inventory, authenticate, and monitor AI-related endpoints like any high-value web app.
Source: SANS Internet Storm Center
OpenAI expands defender access and ships GPT-5.4-Cyber
OpenAI is scaling its Trusted Access for Cyber (TAC) program to thousands of vetted individual defenders and hundreds of blue teams, while releasing GPT-5.4-Cyber—a model tuned for vulnerability triage, exploit reproduction, and secure code assistance. The move aims to help defenders match accelerating AI-enabled offensive capability with faster finding-and-fixing workflows.
Source: Help Net Security
PHP Composer flaws allow arbitrary command execution via Perforce driver
Two high-severity command injection bugs in Composer’s Perforce VCS driver (CVE-2026-40176 and CVE-2026-40177) can enable arbitrary command execution during dependency operations. Development teams using Perforce integration should update promptly and review CI/CD pipelines for potential abuse paths in supply chain workflows.
Source: The Hacker News
You May Also Be Interested In...
Google to penalize sites that hijack the back button
Critical wolfSSL vulnerability allows forged certificates
ICS Patch Tuesday: 8 industrial giants publish new security advisories