logo
Windows PCs under threat from zero-day flaw used in ransomware attacks — update your computer right now

Windows PCs under threat from zero-day flaw used in ransomware attacks — update your computer right now

Yahoo11-04-2025
When you buy through links on our articles, Future and its syndication partners may earn a commission.
Of the 134 Windows security flaws fixed by Microsoft in yesterday's Patch Tuesday updates, only one was a zero-day flaw that could be potentially exploited by hackers in order to gain system privileges.
Today though, Microsoft has said that flaw (tracked as CVE-2025-29824) has indeed been used as a zero-day exploit in targeted ransomware attacks.
Since it has now been patched, it is of critical importance that Windows users download and install this update immediately to protect their systems. Though the attacks were aimed at a small number of international targets including IT and real estate sectors in the United States, financial institutions in Venezuela, a software company in Spain and a retail sector in Saudi Arabia, any unpatched system is vulnerable.
This zero-day flaw is a privilege escalation bug in the Windows Common Log File System that can be exploited in order to achieve SYSTEM privileges. The Hacker News explains that hackers value these types of exploits specifically because they can enable privileged access for widespread deployment and be used to infect vulnerable PCs with ransomware.
The threat actors have leveraged a malware named PipeMagic in order to deliver both the exploits as well as ransomware payloads; this is the second Window's zero-day flaw to be delivered via this malware. The first one( tracked as CVE-2025-24983) was also a privilege escalation bug, but for the Win32 Kernel Subsystem. That vulnerability was flagged by ESET and patched by Microsoft last month.
While it is currently unknown how the attacks are gaining initial access, it does seem as though the threat actors behind them have been using the certutil utility to download the malware from a compromised third-party site that is being used to stage payloads. Microsoft is tracking the activity and post compromise exploitation of this zero-day under the name Storm-2460.
Patch Tuesday falls on the second Tuesday of every month, so set a calendar reminder so that you can remember to update your PC around that time. Outdated software is a great access point for hackers and threat actors, so don't leave yourself open to attacks by neglecting to install serious updates. Likewise, you can also remind yourself to set up automated updates and scans for your security software, since you should of course have one of the best antivirus programs installed on your PC too.
Since Windows Defender is built-in to Windows, you can use it to periodically scan your system for malware or viruses too. And obviously, you want to practice safe browsing habits online. You can see if your antivirus security suite comes with a hardened browser or VPN feature for an added layer of security but whatever you do, never click on links, attachments or downloads from unexpected senders or unknown sources. Only download apps and software from trusted app stores and developers, and know how to recognize common phishing techniques.
Zero-day flaws provide an easy way for hackers and other cybercriminals to gain a foothold for their attacks and this is why knowledge of them sells for such a high price. Unfortunately though, the only thing you can do to stay safe from attacks exploiting them is to install security updates as soon as they become available and to practice good cyber hygiene online.
Scammers are impersonating QuickBooks in last-minute tax phishing scam — and it's stealing financial data
Google just patched two critical Android zero-days exploited by hackers — update your phone right now
T-Mobile is starting to send out data breach settlement payments for up to $25K — see if you qualify
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

Microsoft re-joins handheld gaming fight against Nintendo's Switch
Microsoft re-joins handheld gaming fight against Nintendo's Switch

Yahoo

time21 minutes ago

  • Yahoo

Microsoft re-joins handheld gaming fight against Nintendo's Switch

The record launch in June for the Nintendo Switch 2, a game console that can be played at home or on the go, heralds a new portable race that Microsoft aims to win with a handheld version of its Xbox. Selling itself as the option for discerning, hardcore gamers, Microsoft's Xbox ROG Ally console is available to try for the hundreds of thousands of visitors at the Gamescom trade show in Cologne, Germany. The US tech giant said the devices would go on sale from October 16, but has yet to reveal the price. Born of a partnership with Taiwanese hardware heavyweight Asus, the handheld device includes a central screen with two side grips sporting the same array of joysticks, triggers and buttons as a familiar Xbox controller. "We're really designing and building around an entire ecosystem of devices, to allow people to play where they want, how they want," Jason Ronald, the Microsoft vice president who heads up console development, told reporters. Microsoft's console sales have declined and its Game Pass subscription service has yet to convince large numbers of players, pushing the world's biggest games publisher to seek new sources of growth. - Sights on Valve - At 5.8 million units sold in seven weeks, the Switch 2's mammoth launch figures have other industry players salivating. But "the Switch 2 has that unique thing of games that are nowhere else", locking in fans of beloved Nintendo franchises like Mario or Zelda, Rhys Elliott of the data firm Alinea Analytics told AFP. Microsoft's biggest competitor in the handheld arena is instead another American firm: Valve, which runs the Steam games platform and offers the Steam Deck portable device. Valve says sales of the device have reached several millions since its 2022 launch for the device, which aims at a different market from the Switch. Like the ROG Ally, the Steam Deck was conceived as an on-the-go alternative to a powerful gaming PC. With its portable, Microsoft is targeting "people that already own Xboxes and potentially a PC", said Christopher Dring, founder of the specialist website The Game Business. "The bigger goal of this is engagement," he added. "If you can get your players to play your games more, they will spend more" time and money on them even when away from the console in the living room. Elliott agreed that portables are "complementary" devices to existing consoles. - Sony on the sidelines - For now, Japan's Sony, maker of the PlayStation consoles, is staying out of the portable fight, having withdrawn after 2011's PlayStation Vita failed to match the success of the 2004-era PlayStation Portable, which scored 76 million sales. Sony never revealed sales figures for the Vita. But in late 2023 it dipped a toe back into the scene with a new PlayStation Portal, which incorporates a screen that lets users play games running on their console at home via internet streaming. With no official sales figures, some industry sources estimate around two million sales for the device. "Remote play still impacts a very small portion of the overall audience, but it's growing and is showing strong potential for the future," Mat Piscatella of the gaming data firm Circana has said. Gaming media is already abuzz with rumours about a portable version of a future PlayStation 6 -- though Sony's next-generation console is likely years away. kf/tgb/js Error in retrieving data Sign in to access your portfolio Error in retrieving data Error in retrieving data Error in retrieving data Error in retrieving data

The AI race is on. Google needs its engineers to keep up with the competition.
The AI race is on. Google needs its engineers to keep up with the competition.

Business Insider

timean hour ago

  • Business Insider

The AI race is on. Google needs its engineers to keep up with the competition.

Good morning. I couldn't assemble flat-pack furniture if my life depended on it. Sometimes, it feels like it actually does. That's why I'm thrilled about this startup's mission: Make US manufacturing easier than following an Ikea manual. In today's big story, BI's Hugh Langley exclusively reports on Google ramping up the pressure on workers to use AI for everything — or risk falling behind. Googlers told Hugh how they feel about it. What's on deck: Markets: Infamous market bear Michael Burry appears to have flipped his stance on stocks. Tech: Hundreds of Microsoft employees are comparing compensation in a giant spreadsheet, BI exclusively reports. Business: Target's next CEO already has a plan to revive the retailer. But first, the competition is fierce. If this was forwarded to you, sign up here. The big story Google under pressure For Googlers, the message is clear: use AI to make yourself more productive — or get left behind. Some are excited about it, others are doing it grudgingly, one Google engineer told Hugh. Either way, their boss needs them to do it. Google is under pressure. In an all-hands meeting last month, CEO Sundar Pichai said that as rival companies leverage AI, Google needs to rise to the challenge if it wants to compete, employees who heard the remarks told BI. He's not wrong about the competition. Microsoft told workers in June that " using AI is no longer optional." In a frank blog post, GitHub's CEO said developers have a choice: embrace AI, or " get out of your career." The rivals are becoming lean, mean, and increasingly machine. These directives apply as much to the companies as to their workers. If they fall behind their competitors — as a worker may fall behind a colleague — they risk never catching up. The future of the software engineering profession will be a tale of the haves and have-nots. That's according to Meta's chief technology officer. "The engineers who master the tools to the point that they can't themselves be replaced by the tools command a premium," he said on Monday. Google seems to know this — and it's watching its engineers closely. Pichai said in June that engineers' weekly productivity hours are up 10% thanks to AI. Some companies are tracking employee AI use on a more granular level. Three providers of worker-tracking software told BI they've seen a sharp rise in demand over the past two years. Companies want their workers to use AI, and they aren't taking risks. It can be an unpleasant message to hear. Few people enjoy receiving instructions that come with stark warnings. That said, the Google employees who spoke with BI seem on board. "It seems like a no-brainer that you need to be using it to get ahead," one engineer told Hugh. In Google's internal message board, BI found more skeptical remarks: "You know a technology works and is great when you're forced to praise it to maintain your livelihood." In this race, it seems there is no medal for second place. In the end, there may only be the companies that kept up, and the ones that didn't. 3 things in markets 1. JPMorgan's new HQ blurs the lines between work and life. The bank's new Midtown Manhattan office is filled with a luxury gym, a massive food hall, a 24/7 grab-and-go option, and more. Headhunters, consultants, and management experts told BI those wrap-around perks reinforce Wall Street's work-as-life culture, though. 2. Don't lose faith in major tech stocks. This week's sell-off is likely driven by anticipation of Fed Chair Jerome Powell's speech at Jackson Hole on Friday, wealth manager Jeremy Hartle told BI. UBS said it's still confident in the sector despite the selling. 3. The "Big Short" investor seems to have done a 180. Michael Burry, one of the market's most famous bears, appears to have overhauled his stock portfolio, according to an update from his firm last week. He's swapping bearish puts for bullish calls, and is betting on ailing companies like Lululemon to execute a turnaround, portfolio gurus told BI. 3 things in tech 1. How much Microsoft employees say they make. It's review season at the software giant, and employees are comparing notes on compensation in a large spreadsheet, BI's Ashley Stewart exclusively reports. With 850 entries and counting, here's what employees across cloud, AI, and other teams have said they earn in salary, stock, and bonuses. 2. Inside Meta's massive AI restructuring. Alexandr Wang, the leader of Meta Superintelligence Labs, announced the biggest reorganization of the company's AI operations in a memo sent to employees. Most team leaders will report to Wang, and the company will dissolve yet another major AI unit. 3. It's not just AI talent: Google is paying the big bucks for celebs. Google flexed its marketing might with a star-studded Pixel event, featuring cameos from "Call Her Daddy" podcaster Alex Cooper, NBA star Steph Curry, and more. The tech giant also announced a new partnership with Curry, who will serve as its "Performance Advisor" across its various products. 3 things in business 1. Sin City's sluggish summer. Las Vegas is in the middle of a vibe shift. Since gambling has expanded to other cities and consumers are starting to expect more high-end experiences, Vegas is losing some of its appeal to the more budget-conscious thrill-seekers. But it's not dead yet. 2. Target's new CEO has a plan to get the retailer back on track. In its earnings call, Target announced COO Michael Fiddelke will take over as CEO in February. Fiddelke, who spent the past quarter leading a new acceleration effort, laid out a three-part plan that he said is based on "knowing what makes Target Target." 3. TJX's secret weapon to keep prices low. As other retailers have started passing tariff costs onto consumers, the company behind T.J. Maxx, Marshalls, and Home Goods has been able to soften the blow and keep sales and profits strong. Its CEO credited TJX's price negotiation strategy and how well its buying and allocation teams work in tandem. In other news Exclusive: TikTok Shop is making advertisers give AI more control — whether they like it or not. The US housing market's historic slump could send inflation plummeting in the coming year. Older Americans in their 80s are applying for jobs — and hitting a wall. Crews have been fighting flames aboard USS New Orleans, a US Navy amphibious warship that caught fire in Japan. Why ESPN chief Jimmy Pitaro held back on streaming — until now. America is about to fall off a demographic cliff. What's happening today Jackson Hole economic policy symposium commences. Walmart reports earnings. Fox launches direct-to-consumer streaming service. Hallam Bullock, senior editor, in London. Meghan Morris, bureau chief, in Singapore. Akin Oyedele, deputy editor, in New York. Grace Lett, editor, in New York. Amanda Yen, associate editor, in New York. Lisa Ryan, executive editor, in New York. Kiera Fields, editor, in London. Dan DeFrancesco, deputy editor and anchor, in New York (on parental leave).

An options trade on Nvidia that gives upside exposure and downside protection as earnings approach
An options trade on Nvidia that gives upside exposure and downside protection as earnings approach

CNBC

timean hour ago

  • CNBC

An options trade on Nvidia that gives upside exposure and downside protection as earnings approach

Nvidia is the leader in the semiconductor industry. Ahead of its fiscal second-quarter earnings report on Wednesday, and largely due to its dominance in artificial intelligence, Nvidia is the largest publicly traded company in the world by market capitalization — and by a substantial margin. The difference between the valuation of Nvidia and second-place Microsoft is large enough to buy Exxon Mobil with some change left over. Here's another superlative" Nvidia has a total return of more than 32,000% over the past 10 years. This extraordinary investment performance is driven by the company's GPUs, which offer superior parallel processing, essential for AI model training and inference, building on their origins in gaming. The company's proprietary CUDA software platform further solidifies its market leadership by providing a seamless integration environment for developers, creating a robust ecosystem that is challenging for competitors to replicate. The demand for AI compute remains exceptionally strong, driven by substantial capex growth at the hyperscalers. The Blackwell architecture is expected to further boost this momentum, with analysts projecting quarterly revenue reaching $50 billion by year-end, provided supply constraints ease and orders continue. Beyond data centers, Nvidia is expanding into automotive AI, robotics and cloud gaming, opening up additional revenue streams. Gross margins have consistently been near 70% ( > 56% net is projected next year), and the company has a history of exceeding earnings expectations. If the company achieves the $5.98 in adjusted earnings per share, the Street is forecasting next year that would represent nearly 36% growth year over year. As of Wednesday's close (~$175), that suggests a PEG ratio (price-earnings to growth ratio) of less than 1. Unsurprisingly then, analyst sentiment is overwhelmingly positive. While the growth projections remain extraordinary, along with the apparent enthusiasm for the stock, its performance has been somewhat less so recently. It may surprise you to learn that the Dow Jones Industrial Average has actually outperformed by nearly 4% over the past 10 trading days. Admittedly, some of that outperformance is attributable to the recent rebound in UnitedHealth. Is the underperformance due to exhaustion? Concerns from the latest Federal Reserve meeting minutes that a rate cut is less likely? Merely the lagging industrials indexing finally playing catch-up? Whatever the reason, it's worth considering whether an options trade might offer better risk-adjusted returns between now and the end of the year than the stock itself. A calendar call spread risk reversal would still offer upside, likely provide a modest standstill return in the event the stock stalls and, in the worst case, compel the trader to own the stock at a slight discount (~12.5%) to the prevailing market price in the example trade provided below. DISCLOSURES: None. All opinions expressed by the CNBC Pro contributors are solely their opinions and do not reflect the opinions of CNBC, NBC UNIVERSAL, their parent company or affiliates, and may have been previously disseminated by them on television, radio, internet or another medium. THE ABOVE CONTENT IS SUBJECT TO OUR TERMS AND CONDITIONS AND PRIVACY POLICY . THIS CONTENT IS PROVIDED FOR INFORMATIONAL PURPOSES ONLY AND DOES NOT CONSITUTE FINANCIAL, INVESTMENT, TAX OR LEGAL ADVICE OR A RECOMMENDATION TO BUY ANY SECURITY OR OTHER FINANCIAL ASSET. THE CONTENT IS GENERAL IN NATURE AND DOES NOT REFLECT ANY INDIVIDUAL'S UNIQUE PERSONAL CIRCUMSTANCES. THE ABOVE CONTENT MIGHT NOT BE SUITABLE FOR YOUR PARTICULAR CIRCUMSTANCES. BEFORE MAKING ANY FINANCIAL DECISIONS, YOU SHOULD STRONGLY CONSIDER SEEKING ADVICE FROM YOUR OWN FINANCIAL OR INVESTMENT ADVISOR. Click here for the full disclaimer.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store