Daily Digest

Microsoft Patches Two Zero-Days Amid Wave of Breaches and State-Sponsored Cyberespionage Campaigns

Microsoft Patches Two Zero-Days Amid Wave of Breaches and State-Sponsored Cyberespionage Campaigns

March 11, 2026
8 articles (8 new)
24 min read

Summary

This 24-hour period saw Microsoft release its March 2026 Patch Tuesday, addressing 79 vulnerabilities including two publicly known zero-days in SQL Server and .NET. Concurrently, major data breaches were disclosed by Ericsson and Canadian retailer Loblaw, both highlighting different facets of cyber risk. State-sponsored activity remains high, with reports detailing a sustained two-year campaign by Russia's APT28 against Ukraine and a surge in espionage targeting the Middle East by actors linked to China, Iran, and Belarus. Law enforcement also scored a win by disrupting the 'Tycoon 2FA' phishing platform, while new reports detailed sophisticated supply chain attacks against the npm ecosystem and a critical flaw in Nginx UI.

Filter by Category

New Articles (8)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.