Security Updates
The latest Security Updates coverage — news, analysis, and updates from the WindowsNews.AI desk.
Malicious .keras Models Can Steal Your Files and Cloud Credentials Despite Keras Safe Mode
A seemingly innocuous machine learning file can now be used to steal your SSH keys, cloud credentials, and other sensitive data—all without triggering any alarms. Microsoft has disclosed a critical...
CVE-2022-21698: How Prometheus Metric Cardinality Became a Critical Security Vulnerability
The cybersecurity landscape witnessed a paradigm shift in January 2022 when CVE-2022-21698 revealed how a fundamental observability tool could be weaponized against the very systems it was designed...
Go math/big SetString Vulnerability CVE-2022-23772: Memory Exhaustion Threat & Patch Analysis
A critical vulnerability discovered in Go's standard library exposed countless applications to potential denial-of-service attacks through carefully crafted input. CVE-2022-23772, affecting the...
CVE-2023-30589: The llhttp Parser Bug's Impact on Node.js, Azure, and Windows Security
The discovery and remediation of CVE-2023-30589, a critical vulnerability in the llhttp parser used by Node.js, represents a significant case study in modern software supply chain security,...
HAProxy CVE-2024-45506 Actively Exploited: Protect Windows Services with This Patch
Attackers are actively exploiting a critical vulnerability in the HAProxy load balancer that can crash proxy processes and cut off access to any web application behind it—including Windows-hosted...
PostCSS 8.4.31 Fixes Comment-Spoofing Bug That Lets Attackers Sneak Malicious CSS Past Filters
On September 30, 2023, the maintainers of PostCSS released version 8.4.31 to patch a subtle tokenizer flaw (CVE-2023-44270) that undermines how linters and sanitizers handle untrusted stylesheets....
Microsoft Flags Data-Leaking DNS Bug in Azure Linux: Update Glibc Now
Microsoft's security response team has sounded the alarm for anyone running its Azure Linux distribution: a flaw in the GNU C Library (glibc) can silently leak process memory or crash applications...
Node.js Brotli Decompression DoS Vulnerability (CVE-2024-22025): Analysis & Mitigation
A critical security vulnerability in Node.js's built-in fetch() implementation, tracked as CVE-2024-22025, has been disclosed, allowing attackers to cause Denial of Service (DoS) attacks through...
Pygments ReDoS Vulnerability: How Regex Backtracking Threatens Code Security
The Pygments syntax highlighting library, a cornerstone of Python development and documentation tools, faced a critical security vulnerability in March 2021 that exposed a fundamental weakness in how...
ARM Return Address Bug in LLVM Compiler Triggers Supply Chain Alert for Azure Linux and Beyond
Microsoft has confirmed that a compiler defect in LLVM’s ARM code generator—tracked as CVE-2024-31852—can silently corrupt return addresses in compiled software, opening the door to potential...
CVE-2022-47696: Crafted Files Can Crash objdump and Bring Down Your Automation – Here’s the Fix
A vulnerability in objdump, a staple tool for developers and security teams, can be triggered with a single crafted file to crash the utility on demand. Tracked as CVE-2022-47696, the bug affects...
That Old pip Version Could Let Local Users Sabotage Python Installs — Here’s the Fix
In November 2014, the Python packaging authority disclosed a bug in pip that allowed any local user to block package installations for everyone else on the same machine. The flaw, tracked as...