logo
Windows PCs under threat from zero-day flaw used in ransomware attacks — update your computer right now

Windows PCs under threat from zero-day flaw used in ransomware attacks — update your computer right now

Yahoo11-04-2025

When you buy through links on our articles, Future and its syndication partners may earn a commission.
Of the 134 Windows security flaws fixed by Microsoft in yesterday's Patch Tuesday updates, only one was a zero-day flaw that could be potentially exploited by hackers in order to gain system privileges.
Today though, Microsoft has said that flaw (tracked as CVE-2025-29824) has indeed been used as a zero-day exploit in targeted ransomware attacks.
Since it has now been patched, it is of critical importance that Windows users download and install this update immediately to protect their systems. Though the attacks were aimed at a small number of international targets including IT and real estate sectors in the United States, financial institutions in Venezuela, a software company in Spain and a retail sector in Saudi Arabia, any unpatched system is vulnerable.
This zero-day flaw is a privilege escalation bug in the Windows Common Log File System that can be exploited in order to achieve SYSTEM privileges. The Hacker News explains that hackers value these types of exploits specifically because they can enable privileged access for widespread deployment and be used to infect vulnerable PCs with ransomware.
The threat actors have leveraged a malware named PipeMagic in order to deliver both the exploits as well as ransomware payloads; this is the second Window's zero-day flaw to be delivered via this malware. The first one( tracked as CVE-2025-24983) was also a privilege escalation bug, but for the Win32 Kernel Subsystem. That vulnerability was flagged by ESET and patched by Microsoft last month.
While it is currently unknown how the attacks are gaining initial access, it does seem as though the threat actors behind them have been using the certutil utility to download the malware from a compromised third-party site that is being used to stage payloads. Microsoft is tracking the activity and post compromise exploitation of this zero-day under the name Storm-2460.
Patch Tuesday falls on the second Tuesday of every month, so set a calendar reminder so that you can remember to update your PC around that time. Outdated software is a great access point for hackers and threat actors, so don't leave yourself open to attacks by neglecting to install serious updates. Likewise, you can also remind yourself to set up automated updates and scans for your security software, since you should of course have one of the best antivirus programs installed on your PC too.
Since Windows Defender is built-in to Windows, you can use it to periodically scan your system for malware or viruses too. And obviously, you want to practice safe browsing habits online. You can see if your antivirus security suite comes with a hardened browser or VPN feature for an added layer of security but whatever you do, never click on links, attachments or downloads from unexpected senders or unknown sources. Only download apps and software from trusted app stores and developers, and know how to recognize common phishing techniques.
Zero-day flaws provide an easy way for hackers and other cybercriminals to gain a foothold for their attacks and this is why knowledge of them sells for such a high price. Unfortunately though, the only thing you can do to stay safe from attacks exploiting them is to install security updates as soon as they become available and to practice good cyber hygiene online.
Scammers are impersonating QuickBooks in last-minute tax phishing scam — and it's stealing financial data
Google just patched two critical Android zero-days exploited by hackers — update your phone right now
T-Mobile is starting to send out data breach settlement payments for up to $25K — see if you qualify

Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

AMD Sees AI Inference Growing 80% Annually
AMD Sees AI Inference Growing 80% Annually

Yahoo

time28 minutes ago

  • Yahoo

AMD Sees AI Inference Growing 80% Annually

AMD (NASDAQ:AMD) CEO Lisa Su says AI inferencing demand is set to grow more than 80% annually over the next few years, overtaking training as the primary driver of data-center compute. Warning! GuruFocus has detected 5 Warning Sign with META. Speaking at the Advancing AI 2025 conference in San Jose, Su highlighted an explosion of models tailored to coding, healthcare and finance, and forecast that hundreds of thousands, and eventually millions of purpose-built models will drive massive GPU usage. She reminded the audience that last year AMD projected the data-center AI accelerator total addressable market would expand over 60% annually to $500 billion by 2028and now sees that number trending even higher as inference takes off. Su used the stage to unveil the MI350 GPU series, including the flagship MI355, which delivers a 35 performance leap over its predecessor and 40% more tokens per dollar versus Nvidia's (NASDAQ:NVDA) B200 when running LLMs like DeepSeek-R1 and Llama 3.3. Customers such as Meta (NASDAQ:META), xAI and Microsoft are already preparing upgrades from MI300 to MI350, highlighting growing commercial traction. Su also touted AMD's record 40% share of the AI-accelerator market, powering the world's two fastest supercomputers and serving seven of the top ten model providers with its Instinct chips. Eric Boyd, Microsoft's AI-platform VP, reinforced the momentum, praising AMD's high-capacity memory per chip as a significant advantage for LLM workloads. Why It Matters: With inferencing now the largest driver of AI compute, AMD's optimistic growth outlook and new hardware could translate into accelerated revenue and margin expansion as enterprises race to deploy ever more specialized AI models. This article first appeared on GuruFocus. Sign in to access your portfolio

SMB survival requires cybersecurity transformation with AI
SMB survival requires cybersecurity transformation with AI

Fast Company

time42 minutes ago

  • Fast Company

SMB survival requires cybersecurity transformation with AI

Cybersecurity is now one of the top three risks threatening small and medium-sized businesses (SMBs) in 2025, alongside inflation and economic concerns. Yet many SMBs remain unaware of the full scope of their vulnerability to modern cyberattacks. With AI-powered automation, cybercriminals can attack thousands of SMBs at once, exploiting weak defenses and businesses without dedicated security teams or advanced AI technology. However, a concerning 60% of SMBs remain dangerously underprepared by believing large corporations are more likely targets or being convinced their business has no cyber vulnerabilities at all. The cost of inaction due to misplaced confidence is devastating: nearly 55% say it would take less than $50,000 in financial losses from a cyberattack to force them out of business. One in five SMBs have declared bankruptcy or shut their doors permanently after a cyber incident. Survival requires a shift in strategy. SMBs must take control by using the same advanced AI tools attackers rely on to fight back. A NEW STRATEGY: 4 SIMPLE STEPS TO START With the right strategies, SMBs can protect their data, minimize vulnerabilities, and transform cybersecurity from a cost into an asset. Here's how: 1. Know Your Data Cybercriminals don't attack randomly. They target what's easiest and most profitable: customer payment data, financial records, employee credentials, and business-critical systems. SMBs need to know what data they have, where it's stored, and who has access. Begin with data mapping. Inventory where your data lives—cloud platforms, servers, employee devices, and third-party tools. Identify what's stored, how sensitive it is, and who needs access. From there: Apply role-based access controls Encrypt sensitive information Use multi-factor authentication (MFA) Back up critical data regularly Train teams on basic security hygiene These quick wins dramatically lower risk without blowing budget. 2. Take Care Of The Basics Most cyberattacks aren't successful because of advanced hacking techniques. They succeed because of basic security gaps. Eighty percent of SMBs recognize their vulnerabilities, yet many continue to make basic mistakes. For instance: 23% use memorable passwords, like pet or family member names. 22% don't have cybersecurity measures for internet-connected devices like mobile phones. 18% don't require regular software updates, leaving known vulnerabilities unpatched. 16% never back up their data. 14% don't require MFA for staff. These simple, low-cost steps immediately reduce an SMB's attack surface. MFA can prevent 99% of account takeover attacks. Regular software updates close security gaps cybercriminals actively scan for. And limiting administrator privileges—so only essential personnel can install new software or access sensitive systems—reduces the chance of malware spreading through the network. 3. Train Your Team Technology only goes so far. Seventeen percent of SMBs admit they don't train their employees on cybersecurity best practices, even though human error remains the root cause of most breaches. Falling for phishing emails, mishandling sensitive data, or using unauthorized apps unwittingly opens the door to attackers. Build a culture of security by: Offering short, regular training sessions tailored to each role. Teaching employees how to identify and report phishing and social engineering attempts. Reinforcing password hygiene and safe device usage. Employees can be your weakest link or your first line of defense. The difference is training. 4. Prepare For The Inevitable Even the strongest security defenses can't stop every attack, but knowing how to respond can limit the damage. A cyber incident response plan doesn't need to be complex—just clear and actionable: Document a step-by-step process for handling an attack: how to identify one, who to notify, how to contain damage, and how to restore operations. Assign roles in advance so employees aren't scrambling to act. Test response plans regularly through tabletop exercises or simulated scenarios. More than half of SMBs (53%) experienced Wi-Fi or network disruptions in the past year. Others faced phishing attacks (48%) or website downtime (45%). These are common and costly, but with preparation, they don't have to be fatal. HOW MSSPs UPLEVEL YOUR STRATEGY Even with the best security mindset and preventative measures, most SMBs don't have the time, expertise, or resources to keep up. Seventy-four percent self-manage their cybersecurity or rely on a family member or friend. That's where managed security service providers (MSSPs) come in. For SMBs that are stretched thin and can't afford full-time security professionals, MSSPs provide proactive monitoring, threat detection, and rapid response, thereby acting as an extension of SMBs' internal teams by working 24/7 to identify and mitigate risks before they turn into costly breaches. But despite the clear need, only 15% of SMBs outsource to an MSSP. Offloading these responsibilities frees up valuable time and allows SMBs to focus on growth, rather than security. AI: THE SMB EQUALIZER TO MAXIMIZE DEFENSE Just as cybercriminals use AI to automate attacks and scale operations, SMBs can use AI to fight back. AI-powered security tools help SMBs detect threats faster, respond more effectively, and offload manual security tasks. AI recognizes anomalies in real time. Unlike traditional security measures that rely on pre-programmed rules, AI continuously learns and adapts by flagging suspicious activity before attacks can escalate. For example, AI can detect an employee logging in from an unusual location or a sudden increase in file downloads—both signs of an impending breach. In fact, 55% of SMBs say AI will be most useful in identifying cybersecurity threats before they impact business operations. AI also automates routine security processes. From identifying phishing texts and emails (49%) to automating software updates (26%), AI-driven security reduces the workload on small IT teams and ensures critical security measures aren't overlooked. Instead of manually sifting through endless security alerts, AI prioritizes real threats by helping SMBs respond quickly and efficiently. SMBs that take a proactive approach by leveraging AI-powered security and expert support from MSSPs don't just reduce risk, they gain a strategic edge. In a landscape where 20% of SMBs won't survive a single attack, investing in cybersecurity isn't a luxury. It's a necessity.

Prediction: This Company Will Be the Most Valuable AI Stock in 2026
Prediction: This Company Will Be the Most Valuable AI Stock in 2026

Yahoo

timean hour ago

  • Yahoo

Prediction: This Company Will Be the Most Valuable AI Stock in 2026

Microsoft successfully integrated advanced AI technologies across its entire ecosystem. The company is a dominant player in the enterprise software space, which is relatively resilient to economic conditions. Microsoft has a diversified revenue business, which helps it face market volatility and competitive pressures. 10 stocks we like better than Microsoft › The U.S. equity market bounced back impressively from the turbulence caused by April's tariff shocks. With strong earnings performance and easing geopolitical tensions, investors are again looking out for the next technology winner. Nvidia (NASDAQ: NVDA) had a phenomenal run in the past few years, riding high on GPU demand. However, there is one stock that is also building a bigger moat. Meet Microsoft (NASDAQ: MSFT), a global technology giant that has embedded artificial intelligence (AI) into every layer of its ecosystem. Although Nvidia and Microsoft are currently challenging each other to become the world's most valuable company, the latter's approach can enable it to surpass Nvidia significantly by next year. Here's why. Nvidia primarily focuses on developing the hardware and software infrastructure needed to drive the ongoing AI revolution. In contrast, Microsoft has built a strong presence across both the AI infrastructure and AI application markets. Microsoft is leveraging AI technologies to increase performance and lower costs across the entire technology stack, including data center design, hardware, system software, and model optimization. Subsequently, the company managed to monetize its AI technologies through several avenues -- from direct use, such as Copilot virtual assistants across applications like Microsoft 365, Dynamics 365, and GitHub, to indirect use through third-party applications built using its Azure AI services. Microsoft is also scaling up its AI infrastructure rapidly and released the Phi family of small language models (38 million downloads) and BitNet b1.58, which runs on CPUs. This reduced the company's dependency on GPUs, which can help lower costs and broaden AI accessibility. Microsoft tools and platforms such as GitHub, Visual Studio Code, and Power Platform are increasingly used by developers to build AI applications. This is creating a strong network effect, as the value of these offerings rapidly increases with new insights provided by the existing developer base, attracting even more developers. Microsoft has also processed over 100 trillion tokens (such as ID tokens, access tokens, or refresh tokens, which are used for user authentication) in the third quarter, a fivefold increase on a year-over-year basis. This massive scale has given the company a strong data advantage in operational and optimization insights, which hardware players cannot replicate. Third-quarter fiscal 2025 results highlight the success of management's AI strategy. Azure and other cloud services revenue rose 33% year over year, with AI services contributing 16 percentage points to that growth. The company also reported a threefold increase in Microsoft 365 Copilot use and a fourfold increase in GitHub Copilot use on a year-over-year basis. Enterprise customers extensively used Microsoft's business productivity products over the past decade. Since these products are deeply embedded in the company's infrastructure, clients find it challenging to switch to competitors. This enterprise software is seeing even better customer retention rates and recurring revenue with AI integration. Furthermore, the company's long-term enterprise relationships also provide cross-selling and distribution opportunities, an advantage that pure-play AI companies are unable to replicate. Currently, more than 230,000 organizations, including 90% of companies that make up the Fortune 500, use the company's virtual assistant, Copilot. Unlike Nvidia's GPU sales, which are one-time transactions, Microsoft's AI services generate recurring revenue streams. And companies opt to delay GPU purchases in a tighter economy but are less likely to eliminate mission-critical software that runs their daily operations. Microsoft generates revenue from a diverse range of sources, including cloud computing infrastructure, a suite of productivity applications, gaming, and advertising. This has significantly reduced the company's business concentration risk stemming from overreliance on a single or a few markets. All these strategies have led to exceptional revenue visibility. The company ended the third quarter with commercial remaining performance obligations (RPOs) of $315 billion, representing a 34% year-over-year increase. And Microsoft's 98% annuity revenue model offers more predictable cash flows compared to Nvidia's bulk GPU sales, which are highly dependent on semiconductor cycles and ongoing AI infrastructure build-outs. Nvidia's investment case becomes even riskier when we consider the increasing competition from companies such as Advanced Micro Devices, Intel, and hyperscalers developing in-house chips. As the costs of AI inference workloads rise, more clients will prefer to shift workloads from costlier GPUs to less expensive CPUs or seek software services that can postpone the obsolescence of existing GPUs. Plus, increased export restrictions on Nvidia's GPU sales to China and other international markets also pose a significant headwind. This can hurt the chipmaker's top line in the coming years. Microsoft currently trades at 26.2 times forward earnings, which is lower than its five-year average of 33.2. Despite this, the valuation is at a premium, especially for a company that is not only in AI but is also a major software company. Hence, some investors may be uncomfortable paying premium AI valuations for traditional software businesses. But AI is gradually transforming every aspect of Microsoft's business. The company's financial results continue to be impressive despite significant investments in AI infrastructure. In the third quarter, Microsoft's operating margins rose 1 percentage point year over year to 46% , while cash flow from operations surged 16% year over year to $37 billion. The company also maintains a cash and investments balance of $79.6 billion, which ensures strong financial flexibility. Lastly, management remains committed to returning value to shareholders, as evidenced by the $9.7 billion paid in dividends and share repurchases, a 15% increase year over year. Against this backdrop, it does seem pretty plausible for the company to definitively emerge as the most valuable AI stock in 2026. This may be a smart time to buy at least a small stake in Microsoft. Before you buy stock in Microsoft, consider this: The Motley Fool Stock Advisor analyst team just identified what they believe are the for investors to buy now… and Microsoft wasn't one of them. The 10 stocks that made the cut could produce monster returns in the coming years. Consider when Netflix made this list on December 17, 2004... if you invested $1,000 at the time of our recommendation, you'd have $657,871!* Or when Nvidia made this list on April 15, 2005... if you invested $1,000 at the time of our recommendation, you'd have $875,479!* Now, it's worth noting Stock Advisor's total average return is 998% — a market-crushing outperformance compared to 174% for the S&P 500. Don't miss out on the latest top 10 list, available when you join . See the 10 stocks » *Stock Advisor returns as of June 9, 2025 Manali Pradhan has no position in any of the stocks mentioned. The Motley Fool has positions in and recommends Advanced Micro Devices, Intel, Microsoft, and Nvidia. The Motley Fool recommends the following options: long January 2026 $395 calls on Microsoft, short August 2025 $24 calls on Intel, and short January 2026 $405 calls on Microsoft. The Motley Fool has a disclosure policy. Prediction: This Company Will Be the Most Valuable AI Stock in 2026 was originally published by The Motley Fool

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into the world of global news and events? Download our app today from your preferred app store and start exploring.
app-storeplay-store