• Home
  • Privacy Policy
  • Terms and Conditions
  • DMCA
  • Disclaimer
  • Contact us
Tuesday, June 24, 2025
No Result
View All Result
NEWSLETTER defal
Lebanon Hub
NEWSLETTER
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
No Result
View All Result
Lebanon Hub
No Result
View All Result

Patch Tuesday, May 2025 Edition – Krebs on Security

May 14, 2025
in Cyber Security
0
Home Cyber Security
0
VIEWS
Share on FacebookShare on Twitter


Microsoft on Tuesday launched software program updates to repair at the least 70 vulnerabilities in Home windows and associated merchandise, together with 5 zero-day flaws which might be already seeing energetic exploitation. Including to the sense of urgency with this month’s patch batch from Redmond are fixes for 2 different weaknesses that now have public proof-of-concept exploits obtainable.

Patch Tuesday, May 2025 Edition – Krebs on Security

Microsoft and several other safety companies have disclosed that attackers are exploiting a pair of bugs within the Home windows Widespread Log File System (CLFS) driver that permit attackers to raise their privileges on a weak gadget. The Home windows CLFS is a essential Home windows part chargeable for logging providers, and is extensively utilized by Home windows system providers and third-party purposes for logging. Tracked as CVE-2025-32701 & CVE-2025-32706, these flaws are current in all supported variations of Home windows 10 and 11, in addition to their server variations.

Kev Breen, senior director of menace analysis at Immersive Labs, mentioned privilege escalation bugs assume an attacker already has preliminary entry to a compromised host, usually by way of a phishing assault or by utilizing stolen credentials. But when that entry already exists, Breen mentioned, attackers can achieve entry to the rather more highly effective Home windows SYSTEM account, which might disable safety tooling and even achieve area administration degree permissions utilizing credential harvesting instruments.

“The patch notes don’t present technical particulars on how that is being exploited, and no Indicators of Compromise (IOCs) are shared, which means the one mitigation safety groups have is to use these patches instantly,” he mentioned. “The common time from public disclosure to exploitation at scale is lower than 5 days, with menace actors, ransomware teams, and associates fast to leverage these vulnerabilities.”

Two different zero-days patched by Microsoft right this moment additionally have been elevation of privilege flaws: CVE-2025-32709, which considerations afd.sys, the Home windows Ancillary Operate Driver that permits Home windows purposes to connect with the Web; and CVE-2025-30400, a weak point within the Desktop Window Supervisor (DWM) library for Home windows. As Adam Barnett at Rapid7 notes, tomorrow marks the one-year anniversary of CVE-2024-30051, a earlier zero-day elevation of privilege vulnerability on this identical DWM part.

The fifth zero-day patched right this moment is CVE-2025-30397, a flaw within the Microsoft Scripting Engine, a key part utilized by Web Explorer and Web Explorer mode in Microsoft Edge.

Chris Goettl at Ivanti factors out that the Home windows 11 and Server 2025 updates embrace some new AI options that carry loads of baggage and weigh in at round 4 gigabytes. Stated baggage consists of new synthetic intelligence (AI) capabilities, together with the controversial Recall characteristic, which continually takes screenshots of what customers are doing on Home windows CoPilot-enabled computer systems.

Microsoft went again to the drafting board on Recall after a fountain of adverse suggestions from safety consultants, who warned it could current a gorgeous goal and a possible gold mine for attackers. Microsoft seems to have made some efforts to stop Recall from scooping up delicate monetary data, however privateness and safety considerations nonetheless linger. Former Microsoftie Kevin Beaumont has teardown on Microsoft’s updates to Recall.

In any case, windowslatest.com studies that Home windows 11 model 24H2 reveals up prepared for downloads, even for those who don’t need it.

“It would now present up for ‘obtain and set up’ mechanically for those who go to Settings > Home windows Replace and click on Examine for updates, however solely when your gadget doesn’t have a compatibility maintain,” the publication reported. “Even for those who don’t verify for updates, Home windows 11 24H2 will mechanically obtain sooner or later.”

Apple customers possible have their very own patching to do. On Might 12 Apple launched safety updates to repair at the least 30 vulnerabilities in iOS and iPadOS (the up to date model is eighteen.5). TechCrunch writes that iOS 18.5 additionally expands emergency satellite tv for pc capabilities to iPhone 13 homeowners for the primary time (beforehand it was solely obtainable on iPhone 14 or later).

Apple additionally launched updates for macOS Sequoia, macOS Sonoma, macOS Ventura, WatchOS, tvOS and visionOS. Apple mentioned there is no such thing as a indication of energetic exploitation for any of the vulnerabilities mounted this month.

As all the time, please again up your gadget and/or vital information earlier than making an attempt any updates. And please be at liberty to pontificate within the feedback for those who run into any issues making use of any of those fixes.



Source link

Tags: EditionKrebsPatchSecurityTuesday
Next Post
Change my mind: The Galaxy S25 Edge is not worth it

Change my mind: The Galaxy S25 Edge is not worth it

Beirut, LB
14°
Cloudy / Wind
05:4017:50 EET
Feels like: 13°C
Wind: 34km/h SW
Humidity: 65%
Pressure: 1012.19mbar
UV index: 0
FriSatSun
14°C / 9°C
16°C / 11°C
18°C / 12°C
powered by Weather Atlas

Recent News

Helldivers 2 Update 1.003.104 Patch Notes Reveal Balancing For Leviathans, More Bug Fixes

Helldivers 2 Update 1.003.104 Patch Notes Reveal Balancing For Leviathans, More Bug Fixes

June 24, 2025
Marvel Rivals Season 3 release date, potential characters, and more

Marvel Rivals Season 3 release date, potential characters, and more

June 24, 2025
Providing 100 free promo codes for Wizy on Google Play, no ads, no IAPs

Providing 100 free promo codes for Wizy on Google Play, no ads, no IAPs

June 24, 2025
Prince George’s £1.25 snack he sneaked into a royal engagement

Prince George’s £1.25 snack he sneaked into a royal engagement

June 24, 2025
Israel claims Iran has already breached ceasefire, vows to ‘respond forcefully’

Israel claims Iran has already breached ceasefire, vows to ‘respond forcefully’

June 24, 2025
Arsenal close in on Kepa Arrizabalaga transfer this week

Arsenal close in on Kepa Arrizabalaga transfer this week

June 24, 2025
Apple Silicon History – how Apple chips have grown since 2020

Apple Silicon History – how Apple chips have grown since 2020

June 24, 2025
NCSC Urges Experts to Join Cyber Advisor Program

NCSC Urges Experts to Join Cyber Advisor Program

June 24, 2025
Lebanon Hub

Get the Latest Lebanon News and world News on LebanonHub.com. Local News, Sports, Technology, Music, Celebrity, Gaming News and Cryptocurrency Updates.

Category

  • Altcoin
  • Australia
  • Bitcoin
  • Blockchain
  • Celebrity
  • Cyber Security
  • Ethereum
  • Exchange
  • Litecoin
  • Local News
  • Mobile
  • Movies
  • Music
  • New Released
  • PC
  • PlayStation
  • Popular
  • Reviews
  • Sports
  • Startups
  • Technology
  • TV
  • XBOX

Recent News

Helldivers 2 Update 1.003.104 Patch Notes Reveal Balancing For Leviathans, More Bug Fixes

Helldivers 2 Update 1.003.104 Patch Notes Reveal Balancing For Leviathans, More Bug Fixes

June 24, 2025
Marvel Rivals Season 3 release date, potential characters, and more

Marvel Rivals Season 3 release date, potential characters, and more

June 24, 2025
  • Home
  • DMCA
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Lebanon Hub.

No Result
View All Result
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up

Copyright © 2022 - Lebanon Hub.