Kaspersky reports that highly targeted attacks are using Microsoft Windows and Chrome zero-days
Kaspersky confirms that as a part of Patch Tuesday, Microsoft has finally patched both attacks.


Patch Tuesday is a general term used when Microsoft, Adobe, Oracle, and others regularly release software patches (updates) for their software products.[/caption]Yesterday, 21 June, as a part of Patch Tuesday, Microsoft finally patched both attacks.To recall, Patch Tuesday is a general term used when Microsoft, Adobe, Oracle, and others regularly release software patches (updates) for their software products.While Kaspersky researchers couldn't retrieve remote execution code for the exploit, they suggested that attackers may have used CVE-2021-21224 vulnerability, related to a Type Mismatch bug in the V8.They also discovered and analysed the second exploit in the Microsoft Windows OS kernel which had two vulnerabilities. The first, named CVE-2021-31955, is an Information Disclosure vulnerability that leads to leaking sensitive kernel information. The second is an Elevation of Privilege vulnerability that allows attackers to exploit the kernel and gain elevated access to the computer. It is named CVE-2021-31956.Experts at Kaspersky recommend various ways to protect your organisation from attacks exploiting the aforementioned vulnerabilities. You must update your Chrome browser and Microsoft Windows regularly. Use a reliable endpoint security solution such as Kaspersky Endpoint Security for Business that is powered by exploit prevention, behavior detection, and a remediation engine that can roll back malicious actions. Also, install anti-APT and EDR solutions, enabling capabilities for threat discovery and detection, investigation, and timely remediation of incidents. Upskill your SOC team with professional training and provide them access to the latest threat intelligence.“Now that these vulnerabilities have been made publicly known, it’s possible that we’ll see an increase of their usage in attacks by this and other threat actors. That means it’s very important for users to download the latest patch from Microsoft as soon as possible,” comments Boris Larin, Senior Security Researcher with the Global Research and Analysis Team (GreAT).

Why AI notetakers are raising serious privacy and security concerns
China's low-cost AI models are changing the global AI race. Here's why Silicon Valley is worried
China's Kimi K3 challenges US AI leaders with frontier-level performance at lower cost
How did Instagram run ads promoting child abuse in India?
Why has India halted WhatsApp’s username feature before launch?
