Cybersecurity
The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows 11 Zero-Day Vulnerability Exposes User Credentials via NTLM Exploit
Microsoft Windows 11 is currently facing a critical zero-day vulnerability that could allow attackers to steal user credentials through the NT LAN Manager (NTLM) protocol. This security flaw,...
CISA and CrowdStrike Join Forces: How Public-Private Partnerships Are Resolving IT Outage Crises
The recent collaboration between the Cybersecurity and Infrastructure Security Agency (CISA) and CrowdStrike represents a landmark moment in public-private cybersecurity partnerships. This joint...
Patch Delta InfraSuite Device Master to 1.0.5 for Critical RCE Bug
Critical Vulnerability in Delta Electronics InfraSuite Software: CVE-2024-10456 A critical security vulnerability, identified as CVE-2024-10456, has been discovered in Delta Electronics' InfraSuite...
Apple Security Updates Signal Cross-Platform Danger for Windows Users
Apple recently rolled out critical security updates addressing multiple vulnerabilities across its ecosystem. While these patches primarily target macOS, iOS, and iPadOS, Windows users should...
CISA Warns of Critical ICS Flaws Exploiting Windows Systems
CISA's Advisories on Industrial Control Systems: Key Vulnerabilities Explored Industrial Control Systems (ICS) form the backbone of critical infrastructure, from power grids to water treatment...
CISA warns Solar-Log Base 15 bug in firmware 15.0.25 allows XSS attacks on Windows networks.
A critical vulnerability has been identified in Solar-Log Base 15 energy monitoring systems that could expose Windows users to cross-site scripting (XSS) attacks. The Cybersecurity and Infrastructure...
CISA Warns of Critical Siemens InterMesh Flaws in Industrial Systems
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical advisory regarding multiple vulnerabilities in Siemens' InterMesh software, urging organizations to take immediate...
CVE-2023-6112: Critical Use-After-Free Vulnerability Threatens Chromium Browsers
CVE-2023-6112: Critical Vulnerability in Chromium Browsers A newly discovered critical vulnerability designated as CVE-2023-6112 has sent shockwaves through the cybersecurity community, affecting all...
Windows 11 Patch Fixes Critical ksthunk.sys Driver Downgrade Flaw
Microsoft has confirmed a critical security vulnerability in Windows 11 that allows attackers to downgrade system security components, potentially leading to privilege escalation attacks. The flaw,...
Windows 11 CLFS Bug Lets Local Attackers Seize Full System Control
Windows 11 CLFS Driver Vulnerability: Privilege Escalation Risk Explained Introduction A critical security vulnerability has recently surfaced in the Windows 11 Common Log File System (CLFS) driver,...
CERT-UA: RDP Phishing Attack Hits Ukraine, Global Risks Rise
A sophisticated phishing campaign is actively targeting Remote Desktop Protocol (RDP) users across Ukraine and other regions, according to a recent alert from CERT-UA. This cyberattack poses...
Cisco patches critical RCE and DoS bugs in ASA, FMC, and FTD devices.
Cisco has released its October 2024 security advisory, addressing multiple critical vulnerabilities affecting Adaptive Security Appliances (ASA), Firepower Management Center (FMC), and Firepower...