Microsoft has released its latest Patch Tuesday Updates and you’ll want to install them as soon as possible, as they contain fixes for 61 security flaws, including two zero days Hackers are exploding in the wild.
As Hacker NewsAccording to reports of these 61 security flaws, one received a critical severity rating, 59 were rated as important, and one has a moderate rating. If you want to take a closer look at each of these flaws, Microsoft has more details, including their Common Vulnerabilities and Exposures (CVE) numbers, their severity ratings, and whether they are currently being exploited or could be in the future. May 2024 Security Updates guide.
If you are using one of the best Windows laptops or a Windows desktop, it is highly recommended that you install these new security updates now to avoid falling victim to any attacks that take advantage of them.
Here’s what you need to know about the two zero-days that were fixed with this round of Patch Tuesday updates along with tips on how to keep your Windows PC safe from hackers.
Zero armed days

While hackers are less likely to exploit most of these flaws in their attacks, Microsoft, along with several cybersecurity companies, have noted that two of them have already been weaponized.
The first is a Windows MSHTML platform security feature bypass vulnerability (tracked as CVE-2024-30040) with a CVSS score of 8.8 (out of 10), while the other is an elevation of privilege vulnerability in the Windows Desktop Window Manager core library (followed as CVE-2024-30051) with a CVSS score of 7.8.
In a notice, Microsoft explained that hackers could use the first zero-day to execute code on a vulnerable Windows PC by convincing a victim to open a malicious document. This malicious document is likely included in a phishing email or sent as a message. Surprisingly, the victim would not even need to click on it or open it for the malware to activate and infect her system.
The second zero-day that Microsoft fixed in this round of Patch Tuesday updates could allow an attacker to gain system privileges. There is a high probability that hackers are widely using this flaw in their attacks, as discovered by researchers from Kaspersky, DBAPPSecurity WeBIN Lab, and Google Threat Analysis Group at the same time.
Kaspersky security researchers explained in a blog post who have seen this zero-day used in conjunction with QakBot and other malware. As such, they believe “multiple threat actors have access to it.” Kaspersky also said that he will release more details related to how this zero-day has been exploited in malware campaigns once enough Windows users have time to update their PCs.
How to keep your Windows PC safe from hackers

As with the best phones, the easiest way to keep your PC safe from cyber attacks, malware, and other threats is to make sure you’re running the latest software.
To do this, click on the Start Menuselect Settings and then go to Update and security. From here, select windows update and then click the Search for updates option. If updates are available, you should download and install them as soon as possible and this is especially true after the release of Microsoft’s Patch Tuesday updates.
If you’re having trouble keeping your Windows PC up to date, here’s everything you need to know how to update Windows 11 and how to update windows 10. Speaking of Windows 10, Microsoft’s previous operating system will end support on October 14 of next year, so now is a good time to upgrade to Windows 11 if you haven’t already. However, if your PC doesn’t meet the requirements, it may be worth checking out our lists of best computers and the best laptops to replace your current machine.
In addition to installing the latest Windows updates, you should also consider investing in the best antivirus software. While Microsoft defender is a built-in antivirus that comes preinstalled on all Windows PCs, but it can’t match the features and regular updates you get with paid antivirus software. It should be enough to protect most people, but if you want added peace of mind, a paid antivirus is the way to go.
Since Patch Tuesday occurs on the second Tuesday of every month, we’ll likely soon hear about more security flaws that have been discovered and fixed in Windows.
- Massive Dell Data Breach Affects 49 Million Users: What You Need to Know
- Google has fixed another Chrome zero-day bug: update your browser
- This Android malware steals passwords by impersonating popular apps