Vulnerability
The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft's December 2024 Patch Tuesday: Addressing 72 Vulnerabilities, Including Critical Zero-Day Flaws
In December 2024, Microsoft released its final Patch Tuesday update, addressing a total of 72 vulnerabilities across various products. Among these, one actively exploited zero-day vulnerability...
CISA: Patch ThreatQ Now – Critical RCE Bug CVE-2024-39703 Exploited in Wild
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding CVE-2024-39703, a severe vulnerability in ThreatQuotient's ThreatQ Platform that could allow remote...
Critical BD Diagnostic Flaw CVE-2024-10476 Threatens Patient Data and Hospital Safety
The healthcare sector faces a new cybersecurity threat as BD Diagnostic Solutions reports critical vulnerabilities in its diagnostic software systems. Identified as CVE-2024-10476, this flaw exposes...
Schneider Electric Modicon PLC Zero-Day Threatens Critical Infrastructure
A newly discovered critical vulnerability in Schneider Electric's Modicon programmable logic controllers (PLCs) has raised alarms across industrial control system (ICS) environments. Tracked as...
CISA Warns of Critical 9.8-Rated Siemens PLC Flaw in Latest ICS Alerts
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a new batch of Industrial Control System (ICS) advisories, highlighting severe vulnerabilities that could compromise critical...
Microsoft confirms Dirty DAG flaws in Azure Data Factory Airflow allow code injection; patches released
Microsoft's Azure Data Factory (ADF) has become a cornerstone for enterprise data orchestration, particularly with its integration of Apache Airflow for workflow management. However, recent...
CISA Updates KEV Catalog: Critical Vulnerabilities in Adobe ColdFusion & Windows Kernel Demand Immediate Patching
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog to include two critical security flaws affecting Adobe ColdFusion and the...
Microsoft warns 400M users to pause updates after critical Patch Tuesday
Microsoft Warns 400 Million: To Update or Not in 2024's Patch Tuesday? In a surprising and unprecedented move during the final Patch Tuesday of 2024, Microsoft issued a stark warning to about 400...
AuthQuake flaw let attackers brute-force Microsoft 365 MFA on 400M accounts
In December 2024, Oasis Security researchers uncovered a critical vulnerability in Microsoft's Multi-Factor Authentication (MFA) system, known as "AuthQuake." This flaw allowed attackers to bypass...
Exploit kits weaponize CVE-2024-12381; patch Edge now as attacks surge.
A newly discovered critical vulnerability in Chromium (CVE-2024-12381) has put millions of Microsoft Edge users at risk of remote code execution attacks. This zero-day flaw, which affects all...
AuthQuake attack exploits MFA token flaws; Microsoft urges Conditional Access and FIDO2 keys now.
A newly discovered cybersecurity threat named AuthQuake has emerged, capable of bypassing Microsoft's Multi-Factor Authentication (MFA) protections. This sophisticated attack vector poses significant...
Microsoft December 2024 Patch Tuesday: 71 Fixes, 6 Zero-Days, 3 Exploited
Microsoft's December 2024 Patch Tuesday has arrived, addressing a total of 71 vulnerabilities across its product ecosystem, including critical fixes for Windows, Office, and Azure. This month's...