Microsoft has released its July 2025 Patch Tuesday security updates, addressing 137 vulnerabilities, including one actively exploited zero-day (CVE-2025-49719). Among the 137 vulnerabilities, fourteen are classified as “Critical,” with ten related to remote code execution (RCE), one is an information disclosure, and two are involving AMD side channel attack flaws. Breakdown of Vulnerabilities: 53 Elevation of Privilege Vulnerabilities 8 Security Feature Bypass Vulnerabilities 41 Remote Code Execution Vulnerabilities 18 Information Disclosure Vulnerabilities 6 Denial of Service Vulnerability 4 Spoofing Vulnerabilities Four Mariner and three Microsoft Edge issues fixed earlier this month are not included in these counts. Actively Exploited Zero-Day Vulnerabilities: CVE-2025-49719 – Microsoft SQL Server Vulnerability Leading to Information Disclosure The flaw, disclosed by Microsoft, allows a remote, unauthenticated attacker to access sensitive data from uninitialized memory on affected Microsoft SQL Server systems if improper input is processed over a network.
The ongoing TeamPCP software supply chain campaign has compromised the official Microsoft DurableTask Python client hosted on PyPI. Researchers identified malicious versions of the...
Security researchers discovered a software supply chain attack involving a malicious Go package named github.com/shopsprint/decimal, a typosquatted clone of the legitimate github.c...
Security researchers have uncovered a new information-stealing malware called Gremlin Stealer that employs advanced evasion and infrastructure-hiding techniques to compromise Windo...