The greatest security risks do not stem from zero-day exploits, but from lack of asset visibility, behavior-based social engineering, and token compromise.
Gentlemen gang uses at least eight variants of GentleKiller to disable EDR protection from 48 different security vendors before executing ransomware attacks.
ACROS Security has released a 0patch micropatch for a spoofing vulnerability in Windows Shell that can be exploited via links; Microsoft patched the flaw in March 2026, and the micropatch enables rapid remediation without a restart.