Security News

Apple fixes two zero-days exploited in targeted iPhone attacks
2025-04-16 18:06

Apple released emergency security updates to patch two zero-day vulnerabilities that were used in an "extremely sophisticated attack" against specific targets' iPhones. [...]

Patch Tuesday: Microsoft Fixes 134 Vulnerabilities, Including 1 Zero-Day
2025-04-09 21:24

One CVE was used against “a small number of targets.” Windows 10 users needed to wait a little bit for their patches.

CentreStack RCE exploited as zero-day to breach file sharing servers
2025-04-09 15:38

Hackers exploited a vulnerability in Gladinet CentreStack's secure file-sharing software as a zero-day since March to breach storage servers [...]

PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware
2025-04-09 08:04

Microsoft has revealed that a now-patched security flaw impacting the Windows Common Log File System (CLFS) was exploited as a zero-day in ransomware attacks aimed at a small number of targets....

Microsoft fixes actively exploited Windows CLFS zero-day (CVE-2025-29824)
2025-04-08 19:13

April 2025 Patch Tuesday is here, and Microsoft has delivered fixes for 120+ vulnerabilities, including a zero-day (CVE-2025-29824) that’s under active attack. CVE-2025-29824 CVE-2025-29824 is a...

Microsoft: Windows CLFS zero-day exploited by ransomware gang
2025-04-08 19:05

Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw in the Windows Common Log File System to gain SYSTEM privileges on victims' systems. [...]

Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws
2025-04-08 17:50

Today is Microsoft's April 2025 Patch Tuesday, which includes security updates for 134 flaws, including one actively exploited zero-day vulnerability. [...]

Google fixes Android zero-days exploited in attacks, 60 other flaws
2025-04-07 17:55

Google has released patches for 62 vulnerabilities in Android's April 2025 security update, including two zero-days exploited in targeted attacks. [...]

Ivanti patches Connect Secure zero-day exploited since mid-March
2025-04-03 17:43

Ivanti has released security updates to patch a critical Connect Secure remote code execution vulnerability exploited by a China-linked espionage actor to deploy malware since at least mid-March...

Apple backports zero-day patches to older iPhones and Macs
2025-04-01 13:35

Apple has released security updates that backport fixes for actively exploited vulnerabilities that were exploited as zero-days to older versions of its operating systems. [...]