Windows
3 articles

Active Zero-Day Alert: Microsoft Confirms Exploitation of CVSS 10.0 Entra ID Flaw Prior to Patch
On Thursday, Microsoft revealed that a critical remote code execution (RCE) vulnerability in Entra ID—the identity engine powering Microsoft 365, Azure, and Dynamics 365—was actively exploited in the wild prior to server-side mitigations. Tracked as CVE-2026-69836 and assigned a maximum CVSS score of 10.0, the flaw allows unauthenticated remote code execution. While Microsoft has patched the infrastructure, the lack of published indicators of compromise (IOCs) leaves enterprise defenders

Understanding What IP, Port, and Protocol Is
This topic focuses on understanding the definitions of IP addresses, ports, and protocols, the differences between each of them, as well as commonly used standard ports and the network services that operate on those ports.

EternalBlue Exploit Analysis – Runbook
This runbook details a hands-on simulation of exploiting the EternalBlue vulnerability (CVE-2017-0144), targeting an unpatched Windows 7 machine in a controlled lab environment using Metasploit.
