Tag: zero-day
-
Kernel-Schwachstelle: Zero-Day-Lücke in Windows wird seit 2023 aktiv ausgenutzt
Forscher haben schon vor zwei Jahren die Ausnutzung einer Schwachstelle im Windows-Kernel beobachtet. Einen Patch liefert Microsoft erst jetzt. First seen on golem.de Jump to article: www.golem.de/news/kernel-schwachstelle-zero-day-luecke-in-windows-wird-seit-2023-aktiv-ausgenutzt-2503-194259.html
-
Patch Tuesday Update March 2025
In total, including third-party CVEs, in this Patch Tuesday edition, Microsoft published 57 CVEs, and republished 10 additional CVEs, including 6 Zero-Day, 6 Critical, and 50 Important”, with 6 Zero-Days actively exploited in the wild. From an Impact perspective, Escalation of Privilege (EoP) vulnerabilities accounted for 46%, followed by Remote Code Execution (RCE) at 41%…
-
Apple Drops Another WebKit Zero-Day Bug
A threat actor leveraged the vulnerability in an extremely sophisticated attack on targeted iOS users, the company says. First seen on darkreading.com Jump to article: www.darkreading.com/mobile-security/apple-drops-another-webkit-zero-day-bug
-
Apple Addresses Actively-Exploited Zero-Day In WebKit Browser Engine
First seen on scworld.com Jump to article: www.scworld.com/brief/apple-addresses-actively-exploited-zero-day-in-webkit-browser-engine
-
Actively exploited Apple zero-day addressed
First seen on scworld.com Jump to article: www.scworld.com/brief/actively-exploited-apple-zero-day-addressed
-
Microsoft’s March Patch Tuesday fixes 67 flaws, including 6 zero-days
First seen on scworld.com Jump to article: www.scworld.com/news/microsofts-march-patch-tuesday-fixes-67-flaws-including-6-zero-days
-
March Patch Tuesday fixes 6 Windows zero-day exploits
All the vulnerabilities that had been actively exploited in the wild will get resolved quickly by deploying the Windows cumulative update for this month. First seen on techtarget.com Jump to article: www.techtarget.com/searchwindowsserver/news/366620391/March-Patch-Tuesday-fixes-6-Windows-zero-day-exploits
-
March Patch Tuesday brings 57 fixes, multiple zero-days
The third Patch Tuesday of 2025 brings fixes for 57 flaws and a hefty number of zero-days First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366620545/March-Patch-Tuesday-brings-57-fixes-multiple-zero-days
-
Patch Tuesday: Microsoft Fixes 57 Security Flaws Including Active Zero-Days
Microsoft’s March 2025 Patch Tuesday includes six actively exploited zero-day vulnerabilities. Learn about the critical vulnerabilities and why immediate updates are essential. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-patch-tuesday-march-2025/
-
Microsoft Patch Tuesday security updates for March 2025 fix six actively exploited zero-days
Microsoft Patch Tuesday security updates for March 2025 address 56 security vulnerabilities in its products, including six actively exploited zero-days. Microsoft Patch Tuesday security updates for March 2025 addressed 56 vulnerabilities in Windows and Windows Components, Office and Office Components, Azure, .NET and Visual Studio, Remote Desktop Services, DNS Server, and Hyper-V Server. This Patch…
-
CVE-2025-24201: Apple Addresses Zero-Day Exploit in WebKit
Apple has released an important security update to fix a newly discovered zero-day vulnerability that has reportedly been exploited in >>extremely sophisticated
-
March 2025 Patch Tuesday: Microsoft Fixes 57 Vulnerabilities, 7 Zero-Days
Microsoft’s March 2025 Patch Tuesday fixes six actively exploited zero-day vulnerabilities, including critical RCE and privilege escalation flaws. Learn how these vulnerabilities impact Windows systems and why immediate patching is essential. First seen on hackread.com Jump to article: hackread.com/march-2025-patch-tuesday-microsoft-fixes-vulnerabilities-zero-days/
-
Newly Patched Windows Zero-Day Exploited for Two Years
Microsoft on Tuesday patched a zero-day vulnerability in the Windows Win32 kernel that has been exploited since March 2023. The post Newly Patched Windows Zero-Day Exploited for Two Years appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/newly-patched-windows-zero-day-exploited-for-two-years/
-
Microsoft patches Windows Kernel zero-day exploited since 2023
Slovak cybersecurity company ESET says a newly patched zero-day vulnerability in the Windows Win32 Kernel Subsystem has been exploited in attacks since March 2023. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-patches-windows-kernel-zero-day-exploited-since-2023/
-
Whopping Number of Microsoft Zero-Days Under Attack
The number of zero-day vulnerabilities getting patched in Microsoft’s March update is the company’s second-largest ever. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/whopping-number-microsoft-zero-days-under-attack
-
Apple Releases Patch for WebKit Zero-Day Vulnerability Exploited in Targeted Attacks
Apple on Tuesday released a security update to address a zero-day flaw that it said has been exploited in “extremely sophisticated” attacks.The vulnerability has been assigned the CVE identifier CVE-2025-24201 and is rooted in the WebKit web browser engine component.It has been described as an out-of-bounds write issue that could allow an attacker to craft…
-
Microsoft Patches a Whopping Seven Zero-Days in March
Microsoft has fixed seven zero-days this Patch Tuesday, including one not currently being actively exploited First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/microsoft-patches-seven-zerodays/
-
URGENT: Microsoft Patches 57 Security Flaws, Including 6 Actively Exploited Zero-Days
Microsoft on Tuesday released security updates to address 57 security vulnerabilities in its software, including a whopping six zero-days that it said have been actively exploited in the wild.Of the 56 flaws, six are rated Critical, 50 are rated Important, and one is rated Low in severity. Twenty-three of the addressed vulnerabilities are remote code…
-
Apple patches zero-day bugs used in targeted iPhone attacks
Three zero-days within months: This marks Apple’s third zero-day fix since the start of the year, following patches for CVE-2025-24085 in January and CVE-2025-24200 in February.Apple’s leading market share attracts frequent adversarial interest, making a development or configurational mishap extremely punishing. The company suffered a total of twenty bugs in 2023, including the RCE bugs,…
-
Microsoft patches privilege escalation flaw exploited since 2023
Vulnerabilities in file system drivers: Several of the other zero-day vulnerabilities are related to the Windows NT File System (NTFS) driver. One is a remote code execution flaw that can be triggered by the user mounting a specially crafted VHD (virtual hard disk) that triggers a buffer overflow (CVE-2025-24993).A similar vulnerability, CVE-2025-24985, that can be…
-
Ivanti EPM vulnerabilities actively exploited in the wild, CISA warns
Tags: apt, china, cisa, cyberespionage, exploit, flaw, group, ivanti, remote-code-execution, vpn, vulnerability, zero-dayIvanti products in attackers’ crosshairs: Multiple Ivanti products have been targeted by attackers over the past year, especially by state-sponsored cyberespionage groups who developed zero-day exploits for them.Back in January Ivanti patched a critical remote code execution flaw in its Connect Secure SSL VPN appliance that a Chinese APT group had exploited as a zero-day…
-
Microsoft patches 57 vulnerabilities, including 6 zero-days
More than three-quarters of the vulnerabilities covered in the vendor’s monthly Patch Tuesday update are high-severity flaws. First seen on cyberscoop.com Jump to article: cyberscoop.com/microsoft-patch-tuesday-march-2025/
-
Microsoft Security Update Summary (11. März 2025)
Microsoft hat am 11. März 2025 Sicherheitsupdates für Windows-Clients und -Server, für Office sowie für weitere Produkte veröffentlicht. Die Sicherheitsupdates beseitigen 56 Schwachstellen (CVEs), sieben davon wurden als 0-day klassifiziert. Sechs Schwachstellen werden bereits angegriffen. Nachfolgend findet sich … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/03/12/microsoft-security-update-summary-11-maerz-2025/
-
Apple fixed the third actively exploited zero-day of 2025
Apple addressed a zero-day vulnerability, tracked as CVE-2025-24201, that has been exploited in >>extremely sophisticated>extremely sophisticated
-
Apple patches 0-day exploited in “extremely sophisticated attack”
0-day exploited by maliciously crafted Web content to break out of security sandbox. First seen on arstechnica.com Jump to article: arstechnica.com/security/2025/03/apple-patches-0-day-exploited-in-extremely-sophisticated-attack/
-
Microsoft Flags Six Active Zero-Days, Patches 57 Flaws: Patch Tuesday
Redmond ships major security updates with warnings that a half-dozen Windows vulnerabilities have already been exploited in the wild. The post Microsoft Flags Six Active Zero-Days, Patches 57 Flaws: Patch Tuesday appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/patch-tuesday-microsoft-patches-57-flaws-flags-six-active-zero-days/
-
Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks
Apple has released emergency security updates to patch a zero-day bug the company describes as exploited in “extremely sophisticated” attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/apple/apple-fixes-webkit-zero-day-exploited-in-extremely-sophisticated-attacks/

