Microsoft Fixes Six Exploited Bugs in February Patch Tuesday Updates
The exploited vulnerabilities in question exist across various products, from Microsoft Word to Windows Shell.
All topics
The exploited vulnerabilities in question exist across various products, from Microsoft Word to Windows Shell.
Exploitation of CVE-2025-8088 in the wild began before disclosure, with attacks confirmed as early as July 18, 2025.
The vulnerability (CVE-2026-21509) requires user interaction for an attack to succeed, with the most likely vector being an attacker sending a malicious Office file to a victim, who then opens it.
This week, we talk about how Microsoft disrupted a long-running, large-scale cybercrime-as-a-service platform called RedVDS that has been active since 2019 and was used in high-volume phishing and BEC scams (1:00), then we discuss the research from Cisco Talos on another (!) Chinese APT called UAT-8837 that is targeting critical infrastructure organizations in North America […]
The takedown marks a significant blow to the cybercrime-as-a-service ecosystem, which fuels large-scale, automated fraud.
The important-severity flaw (CVE-2025-62215) has been exploited, said Microsoft.