Microsoft has released its June 2025 Patch Tuesday security updates, addressing 66 vulnerabilities, including one actively exploited zero-day (CVE-2025-33053) and one publicly disclosed flaw (CVE-2025-33073). Among the 66 vulnerabilities, ten are classified as “Critical,” with eight related to remote code execution (RCE) and two involving privilege escalation. Breakdown of Vulnerabilities: 13 Elevation of Privilege Vulnerabilities 3 Security Feature Bypass Vulnerabilities 25 Remote Code Execution Vulnerabilities 17 Information Disclosure Vulnerabilities 6 Denial of Service Vulnerability 2 Spoofing Vulnerabilities Actively Exploited Zero-Day Vulnerabilities: 1. CVE-2025-33053- Web Distributed Authoring and Versioning (WEBDAV) Remote Code Execution Vulnerability The flaw, discovered by Check Point Research, allows remote attackers to execute arbitrary code on affected systems if a user interacts with a specially crafted WebDAV URL. 2. CVE-2025-33073 - Windows SMB Client Elevation of Privilege Vulnerability This flaw stems from improper access control within Windows SMB, enabling an authorized attacker to escalate privileges over a network.
Cybersecurity researchers at Securonix, as reported by The Hacker News, have uncovered a stealthy Python-based backdoor framework dubbed DEEP#DOOR. The malware is designed to estab...
The Phoenix Phishing-as-a-Service (PhaaS) platform has emerged as a significant driver of large-scale smishing campaigns targeting users across banking, telecom, and logistics sect...
Security researchers have identified a high-severity Linux local privilege escalation vulnerability tracked as CVE-2026-31431, carrying a CVSS score of 7.8. Named “Copy Fail” b...