Microsoft has released its June 2025 Patch Tuesday security updates, addressing 66 vulnerabilities, including one actively exploited zero-day (CVE-2025-33053) and one publicly disclosed flaw (CVE-2025-33073). Among the 66 vulnerabilities, ten are classified as “Critical,” with eight related to remote code execution (RCE) and two involving privilege escalation. Breakdown of Vulnerabilities: 13 Elevation of Privilege Vulnerabilities 3 Security Feature Bypass Vulnerabilities 25 Remote Code Execution Vulnerabilities 17 Information Disclosure Vulnerabilities 6 Denial of Service Vulnerability 2 Spoofing Vulnerabilities Actively Exploited Zero-Day Vulnerabilities: 1. CVE-2025-33053- Web Distributed Authoring and Versioning (WEBDAV) Remote Code Execution Vulnerability The flaw, discovered by Check Point Research, allows remote attackers to execute arbitrary code on affected systems if a user interacts with a specially crafted WebDAV URL. 2. CVE-2025-33073 - Windows SMB Client Elevation of Privilege Vulnerability This flaw stems from improper access control within Windows SMB, enabling an authorized attacker to escalate privileges over a network.
Researchers at Mysterium VPN have identified 12,088,677 IP addresses serving publicly accessible .env-style files, exposing credentials and tokens at massive scale. The United Stat...
The job search process has become a new attack surface for software engineers, as Microsoft Defender Experts uncovered a coordinated campaign leveraging malicious repositories disg...
Online home improvement marketplace ManoMano has reportedly suffered a significant data breach impacting approximately 38 million users. Threat actors claim to have accessed and ex...