See every side of every news story
Published loading...Updated

Windows PCs under threat from zero-day flaw used in ransomware attacks — update your computer right now

  • Microsoft addressed CVE-2025-29824, a zero-day vulnerability in Windows CLFS, during its April 2025 Patch Tuesday.
  • Ransomware actors, specifically the Storm-2460 group , exploited the flaw to elevate privileges on compromised systems.
  • This use-after-free vulnerability allowed low-privilege attackers to gain SYSTEM privileges without user interaction, enabling malware deployment.
  • Microsoft urges applying security updates; however, Windows 10 x64/32-bit patches were delayed, and Windows 11 version 24H2 is unaffected.
  • The vulnerability's exploitation led to the installation of PipeMagic backdoor and ransomware deployment, prompting CISA to add it to KEV.
Insights by Ground AI
Does this summary seem wrong?

26 Articles

All
Left
Center
3
Right
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center
Factuality

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in on Tuesday, April 8, 2025.
Sources are mostly out of (0)

You have read out of your 5 free daily articles.

Join us as a member to unlock exclusive access to diverse content.