Trend Micro users beware - dangerous Apex One zero-day exploited in the wild

https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-2560-80.jpg
  • Trend Micro patches CVE‑2026‑34926, a medium‑severity directory traversal flaw in Apex One (on‑prem) that lets local admins inject malicious code
  • Despite requiring prior admin access, the bug is already being exploited in the wild, prompting urgent patching guidance
  • CISA adds it to the KEV catalog, giving federal agencies until June 4 2026 to update or discontinue use per BOD 22‑01 directives

A dangerous vulnerability in Trend Micro’s Apex One product is being actively abused in the wild, researchers have warned, urging users to apply the provided patch as soon as possible.

Apex One is Trend Micro’s endpoint protection platform (EPP) built to protect enterprise devices from malware, ransomware, fileless attacks, and various other cyber-threats. It uses a combination of antivirus capabilities, behavioral analysis, machine learning, and EDR/XDR. It appears to be rather popular, with some sources counting the number of customers in the thousands.

The company has now issued a...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/CT482eMSRL8PagRtuBVYNd-2000-80.jpeg

FBI warns of Kali phishing scam hitting Microsoft OAuth tokens — warns 'Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures'

* FBI flags Kali365, a phishing kit sold on Telegram which steals Microsoft 365 OAuth tokens and bypasses MFA * Victims are tricked into entering device codes on legitimate Microsoft pages, unknowingly authorizing attacker access to Outlook, Teams, and OneDrive * Mitigation steps include restricting device code flow, enforcing conditional access policies, auditing