Sources: 
Microsoft has confirmed the active exploitation of CVE-2026-32202, a critical zero-click vulnerability in Windows Shell, allowing cybercriminals, including the notorious APT28 group, to bypass security measures effortlessly.
Despite a patch released in April 2026,
Akamai researchers reported that victim machines continued authenticating to attackers' servers even after the update. This raises serious concerns over the effectiveness of Microsoft's fixes. The vulnerability, which enables NTLM relay attacks without user interaction, poses a significant threat as it exploits an incomplete security patch.
The flaw allows malicious actors to use a compromised file, potentially leading to severe repercussions. As threats evolve, experts warn that organizations must act swiftly to address this critical vulnerability and safeguard their systems.
Entities have been advised to apply the latest updates immediately to mitigate risks against this sophisticated method of attack. Microsoft's measures, while an attempt to resolve the issues, may still leave systems exposed to further breaches, highlighting a pressing need for ongoing vigilance in cybersecurity strategies.
Sources: 
Microsoft has confirmed that a critical zero-click vulnerability in Windows Shell, labeled CVE-2026-32202, is actively being exploited, allowing destructive cyberattacks. Despite a recent patch, threats from the APT28 cyber gang persist, underscoring the urgency for organizations to apply recommended updates immediately.