Tech

Hackers exploit zero-day Common Log File System vulnerability to plant ransomware

Share
Share


  • Microsoft said it observed a threat actor known as Storm-2460 abuse a use after free flaw in Windows Common Log File System Driver
  • The flaw is used to deploy PipeMagic, which is then used to deliver ransomware
  • Users are advised to install the released patch immediately

Cybercriminals are abusing a post-compromise zero-day vulnerability in the Windows Common Log File System (CLFS) to deploy ransomware.

Earlier this week, Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) published a new in-depth report, describing how a flaw tracked as CVE-2025-29824 is being used in cyberattacks.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Amazon is planning one of its biggest cloud investments yet as it goes big down under
Tech

Amazon is planning one of its biggest cloud investments yet as it goes big down under

Amazon to invest AU$20 billion in Australia between now and 2029 New...

Forget Ray-ban – Meta’s next smart glasses just got a surprise launch date and an exciting new partner
Tech

Forget Ray-ban – Meta’s next smart glasses just got a surprise launch date and an exciting new partner

Meta has just announced it’s partnering with Oakley on something new Most...

Here’s why you should be excited about Audio Overviews coming to Google Search
Tech

Here’s why you should be excited about Audio Overviews coming to Google Search

Google is testing the NotebookLM feature Audio Overviews in Search The feature...