Zero Day Vulnerabilities
The latest Zero Day Vulnerabilities coverage — news, analysis, and updates from the WindowsNews.AI desk.
Stealth Falcon APT Exploits Windows WebDAV RCE Flaw for Spy Campaigns
A newly discovered zero-day vulnerability in Microsoft Windows' WebDAV implementation (CVE-2025-33053) is being actively exploited by the advanced persistent threat group Stealth Falcon in a...
Microsoft June 2025 Patch Tuesday: 75 Fixes, Critical Netlogon & WebDAV Zero-Day
Microsoft's June 2025 Patch Tuesday has arrived with a slew of critical security updates, addressing vulnerabilities that could leave systems exposed to remote code execution, privilege escalation,...
Microsoft June Patch Tuesday: Patch 66 flaws including 6 critical RCE and 1 actively exploited zero-day
Microsoft's June Patch Tuesday has arrived with a substantial security payload, addressing 66 documented vulnerabilities across Windows, Office, and other core products. Among these fixes are six...
EchoLeak Zero-Click Vulnerability in Microsoft 365 Copilot: Risks & Mitigation
A newly discovered zero-click vulnerability in Microsoft 365 Copilot, named EchoLeak, has sent shockwaves through the enterprise security community. Security researchers at Aim Labs uncovered this...
Microsoft patches critical Task Scheduler flaw allowing SYSTEM-level privilege escalation
In early June, cybersecurity professionals and IT administrators were confronted with a newly disclosed vulnerability in a core component of the Windows operating system that has raised significant...
Windows 11 24H2 Update: Microsoft's Compatibility Challenges Explained
Microsoft's decision to release a separate Windows 11 24H2 update has raised eyebrows among IT professionals and enthusiasts alike. This unusual move highlights the growing complexity of maintaining...
Zero-day CVE-2025-33055 WebDAV flaw grants SYSTEM access in 78-vulnerability June Patch Tuesday
Microsoft's June Patch Tuesday has delivered urgent security updates addressing 78 vulnerabilities, including a critical zero-day exploit (CVE-2025-33053) actively weaponized by advanced threat...
Microsoft June 2025 Patch Tuesday: 76 fixes, 3 zero-days, SMBv3 critical flaw
Microsoft’s latest June Patch Tuesday for 2025 has arrived, delivering a comprehensive set of security updates and performance improvements across its ecosystem. This month’s release addresses 76...
Patch CVE-2025-33053 now—Microsoft confirms active WebDAV zero-day exploits.
Microsoft has issued an emergency security update to patch a critical zero-day vulnerability, CVE-2025-33053, which is currently being exploited by cybercriminals. This flaw affects multiple Windows...
Emergency Microsoft Patch Released for Critical Windows RDS Zero-Day CVE-2025-32710
A critical vulnerability in Windows Remote Desktop Services (RDS), designated as CVE-2025-32710, has sent shockwaves through the cybersecurity community. This flaw, rated 9.8 on the CVSS severity...
78 flaws fixed, 3 zero-days exploited: June Patch Tuesday urges immediate action
Microsoft's June 2025 Patch Tuesday has arrived with a mix of urgent fixes and sobering reminders about the evolving threat landscape. This month's security update addresses 78 vulnerabilities across...
Critical WebDAV & SMB flaws patched June 2025—exploits active, CVSS 9.8
Microsoft’s June 2025 Patch Tuesday addresses two critical vulnerabilities—CVE-2025-XXXX in Windows WebDAV and CVE-2025-YYYY in SMB—that could allow remote code execution and privilege...