惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

腾讯CDC
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - Franky
博客园_首页
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
IT之家
IT之家
The Cloudflare Blog
V
Visual Studio Blog
罗磊的独立博客
T
Tailwind CSS Blog
S
SegmentFault 最新的问题
Hugging Face - Blog
Hugging Face - Blog
V
V2EX
阮一峰的网络日志
阮一峰的网络日志
D
Docker
Last Week in AI
Last Week in AI
B
Blog RSS Feed
C
Check Point Blog
J
Java Code Geeks
The GitHub Blog
The GitHub Blog
有赞技术团队
有赞技术团队
博客园 - 聂微东
MongoDB | Blog
MongoDB | Blog
雷峰网
雷峰网

The Register - Security: Patches

Homeland security cybercops say patch TrueConf (Russia Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update Year-long Russian attacks infect users as soon as they look at an email Cisco SD-WAN make-me-root bug under attack Ivanti tells Sentry customers to patch now as critical bugs hit 10.0 and 9.9 AI is making Patch Tuesday (kinda) fun again Anthropic to release Mythos-class models to the public Clear your calendar, Drupal user: You have a critically urgent patch to install Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Critical cPanel, WHM flaw probs exploited as 0-day, pros say Microsoft patch fell short. New Windows flaw exploited More Cisco SD-WAN bugs battered in attacks Critical Fortinet sandbox bugs allow auth bypass and RCE Ancient Excel bug comes out of retirement for active attacks Microsoft's massive Patch Tuesday: It's raining bugs Attackers exploited the FortiClient EMS bug as a 0-day Citrix NetScaler bug may be multiple flaws in one Ransomware crims abused Cisco 0-day weeks before disclosure Google rushes Chrome update to fix zero-days under attack CISA warns max-severity n8n bug is being exploited in the wild Cisco warns of two more SD-WAN bugs under active attack LexisNexis Legal & Professional confirms data breach Five Eyes warn: Patch your Cisco SD-WAN or risk root takeover Patch these 4 critical, make-me-root SolarWinds bugs ASAP Attacker gets into France's DB listing all bank accounts CISA gives feds 3 days to patch actively exploited Dell bug CISA gives feds 3 days to patch actively exploited Dell bug Google fixes exploited Chrome CSS zero-day Critical Microsoft bug from 2024 under exploitation
Ransomware scum, other crims exploit 4 old Microsoft bugs
Jessica Lyons Jessica Lyons · 2026-04-14 · via The Register - Security: Patches

Patches

Zombie Microsoft bugs rise from the dead, pave way for crims and ransomware scum

One was patched almost 14 years ago

Crooks are exploiting four Microsoft vulnerabilities - one patched 14 years ago and another tied to ransomware activity - according to America's lead cyber-defense agency, which on Monday gave federal agencies two weeks to patch them.

The four vulnerabilities added to CISA's Known Exploited Vulnerabilities (KEV) catalog on Monday are:

CVE-2025-60710, a link-following vulnerability in Windows that allows privilege escalation. After initially disclosing this bug in November 2025, Redmond fully fixed it a month later.

CVE-2023-36424, a Windows Common Log File System Driver flaw that allows privilege escalation. Microsoft patched this one in November 2023.

CVE-2023-21529, a deserialization of untrusted data issue in Microsoft Exchange Server that allows an authenticated attacker to achieve remote code execution (RCE). Redmond disclosed and patched the bug in February 2023. Just last week, Microsoft's threat hunters warned that a financially motivated crime crew tracked as Storm-1175 is exploiting this Exchange bug, plus 15 others, to gain initial access to organizations before ultimately stealing their data and deploying Medusa ransomware in extortion attacks.

CVE-2012-1854, an insecure library loading vulnerability in Microsoft Visual Basic for Applications that allows RCE. Microsoft pushed a security fix for this one in July 2012, and then a second software update in November 2012 that fully patched the flaw. At the time, Redmond said it was "aware of limited, targeted attacks attempting to exploit the vulnerability." This means a flaw first exploited almost 14 years ago is still turning up in active attacks today.

We've reached out to Microsoft for more details about the scope of exploitation, and who is attacking these four CVEs, and will update this story if we receive any response to our inquiries.

CISA lists ransomware use for all four as "unknown," although according to Redmond, at least one of them (CVE-2023-21529) has been abused for this type of attack.

"These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA warned in adding the bugs to its catalog, and set an April 27 deadline for all federal agencies to apply patches.

Also on Monday, CISA added two Adobe bugs, a use-after-free vuln in Acrobat tracked as CVE-2020-9715, and a prototype pollution flaw tracked as CVE-2026-34621 that affected both Adobe Acrobat and Reader, to the KEV. The latter had been exploited as a zero-day for months, and Adobe finally released a patch over the weekend. ®