Microsoft confirms ‘live attacks’ by hackers targeting Windows Shell, Office users

19 hours ago 2
Microsoft has issued urgent security updates for multiple vulnerabilities in Windows and Office that the company says are already being exploited in real-world attacks. The flaws, classified as zero-days, were abused by hackers before patches were available, raising the risk level for millions of users worldwide.

The exploits are described as “one-click” attacks. In practical terms, this means a victim can be compromised simply by clicking a malicious link or opening a specially crafted Office file. With minimal user interaction, attackers can plant malware, bypass security protections, and gain control of a target system.

One of the most serious flaws, tracked as CVE-2026-21510, affects the Windows shell—the component responsible for much of the operating system’s user interface. Microsoft said the vulnerability allows attackers to bypass the built-in SmartScreen protection, which is designed to warn users about malicious links and files. Once bypassed, malware can be silently executed on the victim’s machine.

Security expert Dustin Childs noted that while the attack still requires a user to click a link or shortcut file, the ability to achieve remote code execution with a single click is unusual and dangerous. Google’s Threat Intelligence Group, which helped uncover the flaw, confirmed the bug was under “widespread, active exploitation,” warning that successful attacks could lead to ransomware deployment or deeper system compromise.

READ ALSO: Elon Musk demands $134B from Microsoft over alleged non-profit breach

A second Windows vulnerability, CVE-2026-21513, was found in MSHTML, Microsoft’s legacy browser engine originally tied to Internet Explorer. Although Internet Explorer has been discontinued, the engine remains embedded in modern versions of Windows for compatibility with older applications. This flaw also allows attackers to bypass security safeguards and install malware.

Microsoft acknowledged that technical details about how to exploit the bugs have already been published, increasing the likelihood of further attacks. While the company did not specify where the exploit information appeared, this disclosure often accelerates the pace of malicious activity before users apply patches.

According to independent security reporter Brian Krebs, Microsoft also fixed three additional zero-day vulnerabilities that were being actively exploited. The company is urging Windows and Office users to install the latest updates immediately to close the security gaps and reduce the risk of compromise.

The post Microsoft confirms ‘live attacks’ by hackers targeting Windows Shell, Office users appeared first on Latest Nigeria News | Top Stories from Ripples Nigeria.

Read Entire Article
All trademarks and copyrights on this page are owned by their respective owners Copyright © 2024. Naijasurenews.com - All rights reserved - info@naijasurenews.com -FOR ADVERT -Whatsapp +234 9029467326 -Owned by Gimo Internet Tech.