Summary
Ryan, Henry, and Seth walk through Microsoft's March 2025 Patch Tuesday, where the standout fixes are two zero-days already exploited in the wild. Seth covers CVE-2025-26633, a Microsoft Management Console flaw that runs code when a user opens a malicious .msc file delivered through phishing, and Henry covers CVE-2025-24993, a Windows NTFS heap-based buffer overflow that triggers when someone mounts a crafted VHD. The episode also flags roughly eight Chromium-based Edge vulnerabilities, including use-after-free bugs that let attackers escape the browser sandbox. Ryan, Henry, and Seth note that security culture and user training matter as much as the patches themselves.
)
)
)
)
)
)
)