logo

Microsoft fixes two Windows zero-days exploited in malware attacks

ID: af229440-9d00-51cf-9729-626918f5376b

STIX ID: report--af229440-9d00-51cf-9729-626918f5376b

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-04-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft's April 2024 Patch Tuesday fixed two actively exploited zero-days: CVE-2024-26234, a malicious proxy driver/backdoor signed with a legitimate Microsoft Hardware Publisher Certificate, and CVE-2024-29988, a SmartScreen/Mark-of-the-Web bypass used to evade detections and deliver malware (including DarkMe RAT) in targeted campaigns attributed to financially motivated actors such as Water Hydra.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.