Zero Day Vulnerabilities
The latest Zero Day Vulnerabilities coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows 11 KTM Cookies: Uncovering Hidden Privilege Escalation Threats
Windows 11's Kernel Transaction Manager (KTM) has quietly become a potential attack vector through its cookie-based transaction tokens, exposing systems to privilege escalation risks that many...
Attackers Exploit Unpatched CVE-2025-30397 in Windows Legacy MSHTML Engine
A newly discovered zero-day vulnerability (CVE-2025-30397) in Microsoft's legacy MSHTML scripting engine is being actively exploited in the wild, putting millions of Windows users at risk of remote...
CVE-2025-5280: Critical Chromium V8 Engine Flaw and How to Protect Your Browser
A newly discovered critical vulnerability, CVE-2025-5280, has sent shockwaves through the cybersecurity community, exposing a severe out-of-bounds write flaw in Chromium’s V8 JavaScript engine....
Emergency Chrome Update: Patch 8 Critical Zero-Day Flaws Now Exploited in 2025
Google has issued an urgent Chrome update to address multiple critical vulnerabilities discovered in early 2025, including several zero-day exploits already being actively weaponized by...
Microsoft Urgently Releases KB5061977 Security Update for Windows 11 24H2 Amid Active Cyber Threats
On May 27, 2025, in the midst of escalating cyber threats and widespread reports of exploitation, Microsoft issued an urgent out-of-band security update for Windows 11—designated KB5061977. This...
Commvault Metallic Breach Exposes SaaS Security Risks for Windows Users
In a digital era where data is the lifeblood of organizations, the reliance on Software-as-a-Service (SaaS) solutions for critical functions like cloud backup and disaster recovery has skyrocketed....
Microsoft's Emergency KB5061977 Update: Critical Windows 11 24H2 Security Fix
Microsoft's surprise release of out-of-band security update KB5061977 on May 27, 2025, represents a critical response to an actively exploited vulnerability in Windows 11 version 24H2, elevating...
Microsoft Patches Five Actively Exploited Zero-Days in May 2025 Update
Microsoft's May 2025 Patch Tuesday landed with unprecedented force, delivering fixes for 77 vulnerabilities—19 of them rated critical or important—and five zero-days that attackers were actively...
Commvault Zero-Day CVE-2025-3928 Exposes SaaS Customers to Nation-State Attack, CISA Orders Patching
Commvault, the data protection giant, has confirmed that a sophisticated nation-state threat actor exploited a previously unknown vulnerability in its Web Server component to breach its Microsoft...
Commvault Zero-Day CVE-2025-3928 Exploited in Azure to Steal Credentials
Introduction The recent breach involving Commvault's SaaS platform has raised significant alarms in the cybersecurity landscape, particularly emphasizing the vulnerabilities inherent in cloud-based...
CERT-In Warns of Active Exploits: Critical Microsoft Vulnerabilities Threaten Millions of Indian Windows Users
On May 15, 2025, the Indian Computer Emergency Response Team (CERT-In) issued a stark warning to millions of Windows users across the country: multiple critical vulnerabilities in Microsoft’s...
2025 Cybersecurity Incidents Highlight Critical Cloud Security Vulnerabilities in Commvault Systems
Commvault, a prominent provider of enterprise data protection and information management solutions, has recently experienced a series of significant cybersecurity incidents in 2025, highlighting key...