logo

Crims found and exploited these two Microsoft bugs before Redmond fixed 'em

ID: 80cb3b1a-550c-545d-bdcc-8d76cc6f4885

STIX ID: report--80cb3b1a-550c-545d-bdcc-8d76cc6f4885

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-02-14

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Microsoft's February Patch Tuesday fixed 73 vulnerabilities, including two that are being actively exploited: CVE-2024-21412 (an Internet shortcut bypass exploited by the financially motivated Water Hydra group to deliver the DarkMe remote-access trojan to traders) and CVE-2024-21351 (a SmartScreen bypass). The bulletin also lists several critical Microsoft flaws (Exchange, Office, Business Central, Hyper-V, etc.) and summarizes February security updates from Adobe, SAP, Intel, AMD, Cisco, and Google/Android, urging prompt patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.