Find notable cyber news and cases, enriched with sources, timelines, and signals.

Bing image search SVG command injection (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

A crafted SVG in Bing image search triggered OS command injection in Bing image-processing workers, causing code execution as NT AUTHORITY\SYSTEM on Windows and root on Linux through CVE-2026-32194 and CVE-2026-32191.

Related Happenings

DRILLAPP JavaScript backdoor through Microsoft Edge

Malware Activity
H score24 First: 16.03.2026 11:07 Last: 16.03.2026 11:07 Sources 1

About this happening: Observed in February 2026, the DRILLAPP backdoor now runs through Microsoft Edge, giving it file access plus access to the microphone, webcam, and screen...

Python-based malware deployment with XWorm and Cobalt Strike tooling

Malware Activity
H score28 First: 23.02.2026 17:30 Last: 23.02.2026 17:30 Sources 1

About this happening: A Python-based malware deployment was uncovered on a compromised Windows system, exposing persistence, obfuscation, and credential-theft activity tied to PayPal abuse...

Visual Studio Code extension malware operation hiding payloads in dependency folders

Malware Activity
H score31 First: 11.12.2025 18:00 Last: 11.12.2025 18:00 Sources 1

About this happening: The discovery of 19 malicious Visual Studio Code extensions now shows attackers hiding malware inside trusted developer tools, increasing the risk of covert code execution...

BigBlack VS Code Marketplace stealer extensions

Malware Activity
H score30 First: 09.12.2025 10:07 Last: 09.12.2025 10:07 Sources 1

About this happening: The discovery of malicious VS Code Marketplace extensions matters because they can quietly turn a developer workstation into a stealer platform and exfiltrate sensitive da...

Timeline

  1. 24.07.2026 03:00 1 articles · 19h ago

    CVE records still show no exploitation for the Bing image-search flaws

    Untyped Phase

    The Hacker News checked both CVE records on July 24 and found Microsoft still listing CVE-2026-32194 and CVE-2026-32191 as not exploited. The March advisories had still recorded no public disclosure, so the public status remained unchanged after XBOW's writeup.

    Show sources
  2. 23.07.2026 03:00 2 articles · 1d ago

    XBOW publishes exploit mechanics for Bing's SVG command injection

    Technical Analysis Update

    XBOW released the exploit mechanics for the Bing image-search SVG path after holding them back at Microsoft's request until remediation had landed. The writeup shows a crafted SVG reaching an ImageMagick delegate path and running commands as NT AUTHORITY\SYSTEM on Windows and root on Linux in Microsoft's image-processing workers.

    Show sources
  3. 19.03.2026 02:00 1 articles · 4mo ago

    Microsoft issues Bing image-search command-injection CVEs

    Initial Disclosure

    Microsoft issued critical CVE-2026-32194 and CVE-2026-32191 for Bing's image-search image-processing tier and rated both 9.8 on the CVSS scale. The records said there was no public disclosure or exploitation when they went up on March 19, and that Microsoft had already fixed both server-side with no customer action required.

    Show sources