Security News

Patch Tuesday: Microsoft Patches Two Actively Exploited Zero-Day Flaws
2025-02-12 20:25

February’s report on Microsoft patches includes 56 vulnerabilities, two of which are zero-day flaws that have been exploited.

Microsoft Uncovers Sandworm Subgroup's Global Cyber Attacks Spanning 15+ Countries
2025-02-12 17:02

A subgroup within the infamous Russian state-sponsored hacking group known as Sandworm has been attributed to a multi-year initial access operation dubbed BadPilot that stretched across the globe....

Microsoft’s Patch Tuesday Fixes 63 Flaws, Including Two Under Active Exploitation
2025-02-12 09:38

Microsoft on Tuesday released fixes for 63 security flaws impacting its software products, including two vulnerabilities that it said has come under active exploitation in the wild. Of the 63...

February's Patch Tuesday sees Microsoft offer just 63 fixes
2025-02-12 02:58

Don't relax just yet: Redmond has made some certificate-handling changes that could trip unprepared admins Patch Tuesday Microsoft’s February patch collection is mercifully smaller than January’s...

Microsoft fixes two actively exploited zero-days (CVE-2025-21418, CVE-2025-21391)
2025-02-11 20:15

February 2025 Patch Tuesday is here, and Microsoft has delivered fixes for 56 vulnerabilities, including two zero-days – CVE-2025-21418 and CVE-2025-21391 – under active exploitation....

Windows 10 KB5051974 update force installs new Microsoft Outlook app
2025-02-11 19:32

Microsoft has released the KB5051974 cumulative update for Windows 10 22H2 and Windows 10 21H2, which automatically installs the new Outlook for Windows app and fixes a memory leak bug. [...]

Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws
2025-02-11 18:56

Today is Microsoft's February 2025 Patch Tuesday, which includes security updates for 55 flaws, including four zero-day vulnerabilities, with two actively exploited in attacks. [...]

Microsoft raises rewards for Copilot AI bug bounty program
2025-02-10 15:00

​Microsoft announced over the weekend that it has expanded its Microsoft Copilot (AI) bug bounty program and increased payouts for moderate severity vulnerabilities. [...]

Hackers exploit Cityworks RCE bug to breach Microsoft IIS servers
2025-02-07 18:42

Software vendor Trimble is warning that hackers are exploiting a Cityworks deserialization vulnerability to remotely execute commands on IIS servers and deploy Cobalt Strike beacons for initial...

Microsoft shares workaround for Windows security update issues
2025-02-07 13:53

Microsoft has shared a workaround for users affected by a known issue that blocks Windows security updates from deploying on some Windows 11 24H2 systems. [...]