Microsoft Patches Zero-Day Flaw Exploited by North Korea’s Lazarus Group post, augustus 19, 2024februari 24, 2025 A newly patched security flaw in Microsoft Windows was exploited as a zero-day by Lazarus Group, a prolific state-sponsored actor affiliated with North Korea. The security vulnerability, tracked as CVE-2024-38193 (CVSS score: 7.8), has been described as a privilege escalation bug in the Windows Ancillary Function Driver (AFD.sys) for WinSock. “An attacker who… Continue Reading
Ransomware crew may have exploited Windows make-me-admin bug as a zero-day post, juni 12, 2024februari 24, 2025 The Black Basta ransomware gang may have exploited a now-patched Windows privilege escalation bug as a zero-day, according to Symantec’s threat hunters. Microsoft plugged the hole in the Windows Error Reporting Service in the March Patch Tuesdsay, and warned orgs that the vulnerability, tracked as CVE-2024-26169, could allow an attacker to… Continue Reading