Author
Guardian Research Team

Jun 3, 2026
Critical Netlogon RCE on domain controllers (CVE-2026-41089)
A critical, unauthenticated remote code execution vulnerability in Windows Netlogon (CVE-2026-41089, CVSS 9.8) lets a remote attacker run code as SYSTEM on a domain controller. Patch all domain controllers in the same maintenance window with the May 2026 security updates.

Feb 2, 2026
A Supply Chain Attack in Notepad++
The Notepad++ update process was compromised by a supply chain attack, and users are strongly advised to upgrade to version 8.8.9 or later to ensure their security.