New Windows Zero-Click Vulnerability Exploited to Bypass Defender SmartScreen
Microsoft has patched a dangerous zero-click Windows vulnerability, tracked as CVE-2026-32202, that was actively exploited by Russian-linked APT28 hackers. The flaw allowed attackers to bypass Defender SmartScreen and trigger hidden authentication requests simply by opening a folder containing a malicious shortcut (.LNK) file.


The attack used specially crafted Windows shortcut files that forced systems to connect to attacker-controlled servers automatically. This could leak NTLM authentication hashes without any click from the victim, enabling credential theft, relay attacks, or further network compromise. Researchers said the issue was linked to an incomplete earlier patch.
Microsoft fixed the flaw in its April 2026 Patch Tuesday updates and urged users to install updates immediately. Security teams should also monitor suspicious outbound SMB traffic, restrict NTLM usage, and prioritize patching systems that use shared folders or network drives.
Don't trust a single layer. Upgrade to NPAV EPS — Because your Defender can't defend itself.
- Other (43)
- Ransomware (179)
- Events and News (28)
- Features (45)
- Security (505)
- Tips (83)
- Google (45)
- Achievements (13)
- Products (37)
- Activation (7)
- Dealers (1)
- Bank Phishing (61)
- Malware Alerts (297)
- Cyber Attack (381)
- Data Backup (15)
- Data Breach (227)
- Phishing (192)
- Securty Tips (9)
- Browser Hijack (30)
- Adware (15)
- Email And Password (90)
- Android Security (96)
- Knoweldgebase (37)
- Botnet (20)
- Updates (12)
- Alert (72)
- Hacking (88)
- Social Media (11)
- vulnerability (129)
- Hacker (105)
- Spyware (18)
- Windows (28)
- Microsoft (45)
- Uber (1)
- YouTube (4)
- Trojan (7)
- Website hacks (17)
- Paytm (1)
- Credit card scam (4)
- Telegram (9)
- RAT (12)
- Bug (4)
- Twitter (3)
- Facebook (13)
- Banking Trojan (17)
- Mozilla (2)
- COVID-19 (5)
- Instagram (5)
- NPAV Announcement (18)
- IoT Security (4)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- Amazon (5)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (4)
- Cloud malware (5)
- Cloud storage (2)
- Financial fraud (113)
- Impersonation phishing (3)
- DDoS (12)
- Smishing (2)
- Whale (0)
- Whale phishing (6)
- WINRAR (3)
- ZIP (2)
- Fraud Protector (99)
-
Mobile Frauds
(78)
- WhatsApp (20)
- AI (39)