Gist: Akamai reports an incomplete patch for an APT28 exploit leaves a new zero-click authentication coercion flaw, CVE-2026-32202. The analysis explains how a malicious LNK file can still trigger remote DLL loading and bypass expected Windows security checks.
Signal reason: It documents a security research finding tied to a specific threat actor and disclosure to Microsoft.
