Microsoft Urgent Windows Security Alert to Millions - 10 Critical Zero-Days Found

Microsoft Urgent Windows Security Alert to Millions - 10 Critical Zero-Days Found

Microsoft has released its latest Patch Tuesday update addressing a total of 90 security flaws, including 10 zero-day flaws

As reported by The Hacker News, nine of these 90 flaws are critical, with the remaining 80 rated as critical At the same time, Microsoft has also patched 36 vulnerabilities in its Edge browser since last month

If you own the best Windows laptops or desktops running Windows, you should install these new patches immediately to avoid falling victim to attacks that exploit them Here's everything you need to know about the August Patch Tuesday update and some tips to keep your PC safe from hackers

Overall, 10 zero-day flaws were fixed in this month's Patch Tuesday update, six of which are currently being used by hackers in attacks:

The first flaw above is the most serious with a CVSS score of 88, while the last flaw allows hackers to trick unsuspecting It is perhaps the most notable because it allows a hacker to bypass Microsoft's SmartScreen protection in Windows by tricking the user into opening a malicious file The vulnerability has also come to the attention of the US Cybersecurity Infrastructure Security Administration (CISA), which has requested that the federal agency patch the vulnerability by early September

In a blog post, cybersecurity firm Tenable highlighted a Microsoft Office spoofing vulnerability (tracked as CVE-2024-38200) that was also fixed in the latest Patch Tuesday update By sending a specially crafted file as an attachment to a phishing email, hackers can exploit this flaw to launch an attack

Unfortunately, Microsoft has not yet released a fix for two privilege escalation vulnerabilities (tracked as CVE-2024-38202 and CVE-2024-21302) that can be used to downgrade a Windows system to an earlier version of the OS and launch further attacks ) for which no fixes have yet been released However, when contacted by The Hacker News, Microsoft said it would consider patching these flaws in a future update

The easiest way to keep your PC protected is to install the latest updates as soon as they become available This is because hackers often target users with outdated software

From here, to stay safe from malware and other viruses, you should also consider using the best antivirus software; Windows Defender has improved significantly over the past few years and is much better at detecting and stopping malware However, paid antivirus software often comes with useful extras like VPNs and password managers for additional protection

You also want to avoid clicking on links or downloading attachments, as emails from unknown senders may contain malware Similarly, when looking for new software online, it is advisable to scroll down to the actual search results, as hackers use ads to spread malware

Hackers and companies like Microsoft play a constant game of cat and mouse with each other when it comes to patching vulnerabilities used in cyber attacks But if you update your computer regularly, think twice before clicking on suspicious links, and don't download files from disreputable websites, you should be able to avoid falling victim to cyber attacks and other online scams

Patch Tuesday updates are released on the second Tuesday of each month, so you should plan to update your Windows PC around that time and make sure you have the latest software running on your computer

Categories