Microsoft patches Windows zero-day exploited in attacks on Ukraine

November 13, 2024 at 04:37PM Suspected Russian hackers exploited a recently patched Windows vulnerability (CVE-2024-43451) targeting Ukrainian entities. This NTLM Hash Disclosure flaw allows attackers to steal user login credentials via phishing emails. Microsoft confirmed the vulnerability’s exploitation requires minimal user interaction and has affected all supported Windows versions, prompting CISA to issue a security … Read more

Recurring Windows Flaw Could Expose User Credentials

October 29, 2024 at 06:05PM A recently reported 0-day vulnerability affects all Windows versions from 7 to 11, allowing attackers to capture NTLM authentication hashes via authentication coercion attacks. Discovered by ACROS Security while addressing another vulnerability, the flaw requires user interaction and could be exploited through manipulated Windows themes. Microsoft is aware and may … Read more

Critical Flaws Discovered in Veeam ONE IT Monitoring Software – Patch Now

November 7, 2023 at 12:36AM Veeam has released security updates to address four vulnerabilities in its ONE IT monitoring and analytics platform. Two of the flaws are rated critical and can lead to remote code execution and obtaining sensitive information. The affected versions are 11, 11a, and 12, and users are advised to install the … Read more