Microsoft News Articles
Recent news articles refferecing the vendors vulnerabilities.
Microsoft patches two zero-days for Valentineâs Day | Computer Weekly
Two security feature bypasses impacting Microsoft SmartScreen are on the February Patch Tuesday docket, among over 70 issues.
2 days ago
Week in review: Microsoft fixes two actively exploited 0-days, PAN-OS auth bypass hole plugged - Help Net Security
Hereâs an overview of some of last weekâs most interesting news, articles, interviews and videos: Microsoft fixes two actively exploited zero-days
3 days ago
February's Patch Tuesday Fixes Dozens Of Windows Security Flaws And Most Are Critical
Microsoft's latest updates fix 63 vulnerabilities of varying severity, so prep your system, save your personal data, and patch that PC.
5 days ago
Microsoftâs February 2025 Patch Tuesday corrects 57 bugs, three cri...
Microsoft is correcting 57 vulnerabilities in its February Patch Tuesday, two of which are being actively exploited in the wild, and three of which are âcriticalâ.
5 days ago
Microsoftâs Patch Tuesday Fixes 63 Flaws, Including Two Under Active Exploitation
Microsoft patches 63 flaws, including two exploited Windows vulnerabilities (CVE-2025-21391, CVE-2025-21418). CISA requires fixes by March 4.
5 days ago
Microsoft Patch Tuesday, February 2025 Edition
Microsoft today issued security updates to fix at least 56 vulnerabilities in its Windows operating systems and supported software, including two zero-day flaws that are being actively exploited.
5 days ago
February 2025 Patch Tuesday: Updates and Analysis | CrowdStrike
Microsoft has released security updates for 67 vulnerabilities, including 4 zero-days and 3 critical, in its February 2025 Patch Tuesday rollout.
6 days ago

Patch Tuesday: A âwormableâ LDAP bug and two EOP zero days fixed
Lighter than last month, mercifully, but still some urgent fixes.
6 days ago
Microsoft fixes two actively exploited zero-days (CVE-2025-21418, CVE-2025-21391) - Help Net Security
On February 2025 Patch Tuesday, Microsoft has fixed 56 vulnerabilities, including two exploited zero-days: CVE-2025-21418 and CVE-2025-21391.
6 days ago

Homeland Security AlertâOngoing Critical Microsoft Outlook Attack
The Department of Homeland Security has warned that Microsoft Outlook is subject to an ongoing hack attack.
1 week ago

Critical Microsoft Outlook Vulnerability (CVE-2024-21413) Actively Exploited in Attacks - CISA Warns
CISA has issued an urgent warning to federal agencies regarding active exploitation of a critical Microsoft Outlook vulnerability.
2 weeks ago
Critical RCE bug in Microsoft Outlook now exploited in attacks
CISA warned U.S. federal agencies on Thursday to secure their systems against ongoing attacks targeting a critical Microsoft Outlook remote code execution (RCE) vulnerability.
2 weeks ago
New Microsoft script updates Windows media with bootkit malware fixes
Microsoft has released a PowerShell script to help Windows users and admins update bootable media so it utilizes the new
2 weeks ago
Microsoft script updates bootable media for BlackLotus bootkit fixes
Microsoft has released a PowerShell script to help Windows users and admins update bootable media so it utilizes the new
2 weeks ago
CISA tags Microsoft .NET and Apache OFBiz bugs as exploited in attacks
The US Cybersecurity & Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies and large organizations to apply the available security updates as soon as possible.
2 weeks ago
Microsoft fixes CVSS 9.9 vulnerability in Azure AI Face service
The flaw enabled authentication bypass by spoofing, with a proof-of-concept exploit available.
2 weeks ago

CISA Adds Apache, Microsoft Vulnerabilities to Its Database that Are Actively Exploited in the Wild
CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog, adding Apache, Microsoft, and Paessler vulnerabilities.
2 weeks ago

CISA Adds Four Actively Exploited Vulnerabilities to KEV Catalog, Urges Fixes by Feb 25
CISA adds four exploited vulnerabilities to its KEV catalog, urging fixes by Feb 25, 2025, to counter active threats
2 weeks ago
February 2024 Patch Tuesday: Updates and Analysis
Microsoft has released security updates for 73 vulnerabilities, including two zero-days, for its February 2024 Patch Tuesday rollout.
2 weeks ago

Critical New Microsoft Account Takeover Bypassed Authentication
Microsoft has confirmed that Microsoft Accounts have been left with missing authentication mechanisms that could lead to a hacker takeover. Hereâs what you need to know.
2 weeks ago

Critical Windows OLE Zero-Click Vulnerability Let Attacker to Execute Arbitrary Code
A critical security flaw, identified as CVE-2025-21298, has been disclosed in Microsoftâs Windows Object Linking and Embedding (OLE) technology.Â
2 weeks ago

Microsoft Azure AI Face Service Elevation of Privilege Vulnerability Let Attackers Gain Network Access
Microsoft has disclosed a critical vulnerability, CVE-2025-21415, impacting the Azure AI Face Service, which is classified as an Elevation of Privilege issue,
2 weeks ago
Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score
Microsoft fixes CVE-2025-21415 (CVSS 9.9) and CVE-2025-21396 flaws, addressing privilege escalation risks in Azure AI Face Service and Microsoft Accou
2 weeks ago

PoC Exploit Released for Active Directory Domain Services Privilege Escalation Vulnerability
A proof-of-concept (PoC) exploit code has been released for CVE-2025-21293, a critical Active Directory Domain Services Elevation of Privilege vulnerability.
2 weeks ago

PoC Exploit Released for Actively Exploited Windows CLFS Buffer Overflow
A proof-of-concept (PoC) exploit for the actively exploited Windows Common Log File System (CLFS) vulnerability tracked as CVE-2024-49138, has been released.
3 weeks ago

Windows CLFS Buffer Overflow Vulnerability CVE-2024-49138 - PoC Released
 A recently disclosed Windows kernel-level vulnerability, identified as CVE-2024-49138, has raised significant security concerns in the cybersecurity community.
3 weeks ago
Technical Analysis: CVE-2024-38021
In this blog Morphisec researchers provide technical analysis of CVE-2024-38021, a vulnerability impacting Microsoft Outlook.
3 weeks ago

Microsoft Windows BitLocker Vulnerability Exposes PasswordsâAct Now
Security experts have warned Windows BitLocker vulnerability could expose sensitive data in RAM, including passwordsâwhat you need to do.
3 weeks ago

Payment card NFC relay attacks spread across Russia
In other news: Hacker Pompompourin to be resentenced; a Chinese APT pulls off another supply chain attack; new cookie sandwich technique.
3 weeks ago


Zero-Click Outlook RCE Vulnerability (CVE-2025-21298), PoC Released
Microsoft issued a critical patch to address CVE-2025-21298, a zero-click Remote Code Execution (RCE) vulnerability in Windows Object Linking and Embedding (OLE).
3 weeks ago

PoC Exploit Released For Critical Microsoft Outlook (CVE-2025-21298) Zero-Click RCE Vulnerability
A new proof-of-concept (PoC) has been released for Microsoft Outlook zero-click remote code execution (RCE) vulnerability in Windows Object Linking and Embedding (OLE), identified as CVE-2025-21298.
4 weeks ago

Windows BitLocker Vulnerability(CVE-2025-21210) Exploited in Randomization Attack
BitLocker, a widely used full-disk encryption tool in Microsoft Windows, relies on AES-XTS for encrypting storage devices.Â
1 month ago

How to Address CVE-2025-21307 Without a Patch Before the Weekend | Qualys Security Blog
Microsoftâs January 2025 Patch Tuesday release addresses a critical vulnerabilityâCVE-2025-21307âin the Windows Reliable Multicast Transport Driver (RMCAST).
1 month ago

Critical Microsoft Outlook Vulnerability Rated 9.8/10 ConfirmedâUpdate Now
A critical-rated Outlook vulnerability has been confirmed by Microsoft which has warned that exploitation is likelyâhereâs what you need to know and do.

Microsoft Patches Outlook Zero-Click RCE Exploited Via Email - Patch Now!
Microsoft issued a critical security patch addressing a newly discovered vulnerability in Outlook, designated as CVE-2025-21298.

Critical Windows OLE Remote Code Execution Vulnerability Could Be Exploited Via Email
Microsoft has disclosed a newly identified critical security vulnerability (CVE-2025-21298) affecting Object Linking and Embedding (OLE)

Windows Line Printer Daemon (LPD) Vulnerability Exposes Systems to Remote Code Execution
Microsoft has disclosed a significant security vulnerability in its Windows Line Printer Daemon (LPD) service, tracked as CVE-2025-21224. This flaw could allow attackers to execute remote code on affected systems, posing a serious risk to organizations relying on the LPD service for network printing...
Microsoft fixes 159 vulnerabilities in first Patch Tuesday of 2025
Microsoft has addressed a total of 159 vulnerabilities in the first Patch Tuesday of 2025, covering a broad spectrum of products.
Infostealer Masquerades as PoC Code Targeting Recent LDAP Vulnerability
A fake proof-of-concept (PoC) exploit for a recent LDAP vulnerability distributes information stealer malware.

Fake PoC Exploit Targets Cybersecurity Researchers with Malware
The attackers have set up a malicious repository containing the fake PoC, leading to the exfiltration of sensitive computer and network information.

CrowdStrike Warns of Phishing Scam Targeting Job Seekers with XMRig Cryptominer
Phishing exploits CrowdStrike branding to deliver XMRig cryptominer via fake CRM app, evading detection.

Weaponized LDAP PoC Exploit Installing Information-Stealing Malware
Security researchers are tricked into downloading and executing information-stealing malware by a fake proof-of-concept (PoC) exploit for CVE-2024-49113, dubbed LDAPNightmare.
Patch Alert: Remotely Exploitable LDAP Flaws in Windows
Security experts are urging all organizations that use Microsoft Windows to ensure they install patches, released last month, to fix Lightweight Directory Access
Security pros baited by fake Windows LDAP exploits
Security researchers are once again being lured into traps by attackers, this time with fake exploits of serious Microsoft security flaws. Trend Micro spotted what appears to be a fork of the legitimate...
Information Stealer Masquerades as LDAPNightmare (CVE-2024-49113) PoC Exploit
Our blog entry discusses a fake PoC exploit for LDAPNightmare (CVE-2024-49113) that is being used to distribute information-stealing malware.

PoC Exploit Released for Windows Registry Privilege Elevation Vulnerability
A proof-of-concept (PoC) exploit for a critical Windows Registry Elevation of Privilege vulnerability, identified as CVE-2024-43641.
TheCyberThrone Security Weekly Review â January 04, 2025
Welcome to TheCyberThrone cybersecurity week in review will be posted covering the important security happenings. This review is for the week ending Saturday, January 04, 2025. CVE-2024-56512 impacts Apache NiFi CVE-2024-56512 is a security vulnerability identified in Apache NiFi, specifically affec...
What We Know About CVE-2024-49112 and CVE-2024-49113
In December 2024, two Windows Lightweight Directory Access Protocol (LDAP) vulnerabilities were identified by independent security researcher Yuki Chen: CVE-2024-49112, a remote code execution (RCE) flaw with...
What We Know About CVE-2024-49112 and CVE-2024-49113
In December 2024, two Windows Lightweight Directory Access Protocol (LDAP) vulnerabilities were identified by independent security researcher Yuki Chen: CVE-2024-49112, a remote code execution (RCE) flaw with...

Hacking Active Directory: Learn How LDAPNightmare Flaw Shuts Down AD Services
Hacking Active Directory: Learn How LDAPNightmare Flaw Shuts Down AD Services - Vulnerabilities - Information Security Newspaper | Hacking News