Live
CISA: Patch ThreatQ Now – Critical RCE Bug CVE-2024-39703 Exploited in Wild·MSFT +2.1%Critical BD Diagnostic Flaw CVE-2024-10476 Threatens Patient Data and Hospital Safety·NVDA +0.2%Schneider Electric Modicon PLC Zero-Day Threatens Critical Infrastructure·GOOGL +1.7%CISA Warns of Critical 9.8-Rated Siemens PLC Flaw in Latest ICS Alerts·AMZN +1.1%Microsoft confirms Dirty DAG flaws in Azure Data Factory Airflow allow code injection; patches released·MSFT +2.1%CISA Updates KEV Catalog: Critical Vulnerabilities in Adobe ColdFusion & Windows Kernel Demand Immediate Patching·NVDA +0.2%Microsoft warns 400M users to pause updates after critical Patch Tuesday·GOOGL +1.7%AuthQuake flaw let attackers brute-force Microsoft 365 MFA on 400M accounts·AMZN +1.1%CISA: Patch ThreatQ Now – Critical RCE Bug CVE-2024-39703 Exploited in Wild·MSFT +2.1%Critical BD Diagnostic Flaw CVE-2024-10476 Threatens Patient Data and Hospital Safety·NVDA +0.2%Schneider Electric Modicon PLC Zero-Day Threatens Critical Infrastructure·GOOGL +1.7%CISA Warns of Critical 9.8-Rated Siemens PLC Flaw in Latest ICS Alerts·AMZN +1.1%Microsoft confirms Dirty DAG flaws in Azure Data Factory Airflow allow code injection; patches released·MSFT +2.1%CISA Updates KEV Catalog: Critical Vulnerabilities in Adobe ColdFusion & Windows Kernel Demand Immediate Patching·NVDA +0.2%Microsoft warns 400M users to pause updates after critical Patch Tuesday·GOOGL +1.7%AuthQuake flaw let attackers brute-force Microsoft 365 MFA on 400M accounts·AMZN +1.1%

Vulnerability

The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 5:11 PM
Latest Most Read Breaking
Sort
Cisa · Cve-2024-39703

CISA: Patch ThreatQ Now – Critical RCE Bug CVE-2024-39703 Exploited in Wild

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding CVE-2024-39703, a severe vulnerability in ThreatQuotient's ThreatQ Platform that could allow remote...

Advertisement
Apache Airflow · Azure Data Factory

Microsoft confirms Dirty DAG flaws in Azure Data Factory Airflow allow code injection; patches released

Microsoft's Azure Data Factory (ADF) has become a cornerstone for enterprise data orchestration, particularly with its integration of Apache Airflow for workflow management. However, recent...

SE Security Desk·84w ago
Adobe Coldfusion · Cisa

CISA Updates KEV Catalog: Critical Vulnerabilities in Adobe ColdFusion & Windows Kernel Demand Immediate Patching

The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog to include two critical security flaws affecting Adobe ColdFusion and the...

SE Security Desk·84w ago
Microsoft · Patch

Microsoft warns 400M users to pause updates after critical Patch Tuesday

Microsoft Warns 400 Million: To Update or Not in 2024's Patch Tuesday? In a surprising and unprecedented move during the final Patch Tuesday of 2024, Microsoft issued a stark warning to about 400...

SE Security Desk·84w ago
Cybersecurity · Data Security

AuthQuake flaw let attackers brute-force Microsoft 365 MFA on 400M accounts

In December 2024, Oasis Security researchers uncovered a critical vulnerability in Microsoft's Multi-Factor Authentication (MFA) system, known as "AuthQuake." This flaw allowed attackers to bypass...

SE Security Desk·84w ago
Chromium · Cve-2024-12381

Exploit kits weaponize CVE-2024-12381; patch Edge now as attacks surge.

A newly discovered critical vulnerability in Chromium (CVE-2024-12381) has put millions of Microsoft Edge users at risk of remote code execution attacks. This zero-day flaw, which affects all...

SE Security Desk·84w ago
Authquake · Cybersecurity

AuthQuake attack exploits MFA token flaws; Microsoft urges Conditional Access and FIDO2 keys now.

A newly discovered cybersecurity threat named AuthQuake has emerged, capable of bypassing Microsoft's Multi-Factor Authentication (MFA) protections. This sophisticated attack vector poses significant...

SE Security Desk·84w ago
2024 · Cybersecurity

Microsoft December 2024 Patch Tuesday: 71 Fixes, 6 Zero-Days, 3 Exploited

Microsoft's December 2024 Patch Tuesday has arrived, addressing a total of 71 vulnerabilities across its product ecosystem, including critical fixes for Windows, Office, and Azure. This month's...

SE Security Desk·84w ago
Cve-2024-49071 · Cybersecurity

CVE-2024-49071: Critical Windows Defender Vulnerability Puts Systems at Risk

A newly discovered vulnerability in Windows Defender, tracked as CVE-2024-49071, has raised serious concerns among cybersecurity experts. This critical flaw could allow attackers to bypass...

SE Security Desk·84w ago