Tag: Zero-Day Flaw

New Windows RasMan zero-day flaw gets free, unofficial patches
News

New Windows RasMan zero-day flaw gets free, unofficial patches

A new Windows zero-day vulnerability that enables attackers to bring down the Remote Access Connection Manager (RasMan) service has free unofficial remedies. Point-to-Point Protocol over Ethernet (PPoE), VPN, and other remote network connections are managed by RasMan, an essential Windows system service that launches automatically and operates in the background with SYSTEM-level privileges. While investigating CVE-2025-59230, a Windows RasMan privilege escalation vulnerability exploited in attacks that was patched in October, ACROS Security, which oversees the 0patch micropatching platform, found a new denial-of-service (DoS) vulnerability. The DoS zero-day is still unpatched in all versions of Windows, including Windows 7 through Windows 11 and Windows Server 2008 R2 through Ser...
Zero-Day Flaw in Zimbra Email Software Exploited by Four Hacker Groups
News

Zero-Day Flaw in Zimbra Email Software Exploited by Four Hacker Groups

Four distinct groups conducted real-world attacks using a zero-day vulnerability in the Zimbra Collaboration email software to steal authentication tokens, user credentials, and email content. According to a report shared with The Hacker News by Google Threat Analysis Group (TAG), "the majority of this activity occurred after the initial fix became public on GitHub." This vulnerability affects versions prior to 8.8.15 Patch 41 and is tracked as CVE-2023-37580 (CVSS score: 6.1). It is a reflected cross-site scripting (XSS) vulnerability. On July 25, 2023, Zimbra released patches that addressed it. By deceiving the victims into clicking on a malicious URL, a successful exploit of this vulnerability could enable the execution of malicious scripts on their web browsers read more Zero...