CVE-2026-32202: APT28 Exploits Incomplete Windows Patch to Steal NTLM Hashes Zero-Click
Microsoft confirmed active exploitation of CVE-2026-32202, a Windows Shell spoofing flaw leaking NTLM hashes via malicious LNK files. CISA set a May 12 patch deadline.

