A recent discovery has exposed a significant flaw in Windows, known as the “Windows Zero-day Downgrade Attack,” that allows threat actors to downgrade fully updated systems to versions with known vulnerabilities. This attack method is particularly alarming because it exploits the trust users place in Windows Update, a cornerstone of maintaining system security. The Mechanics […]
A critical vulnerability, now known as the “0.0.0.0 Day vulnerability,” has resurfaced after 18 years, impacting Google Chrome, Mozilla Firefox, and Apple Safari. This flaw, originally reported in 2008, allows malicious websites to bypass critical security mechanisms and interact with services on a local network, posing significant risks to Linux and macOS devices. Notably, this […]
A recently patched security flaw in Microsoft Defender SmartScreen has been exploited to deliver malicious information stealers, including ACR Stealer, Lumma Stealer, and Meduza Stealer. This vulnerability, known as CVE-2024-21412 and rated with a CVSS score of 8.1, enables attackers to bypass SmartScreen protection and distribute harmful payloads. Microsoft resolved this high-severity vulnerability in its […]