Summary
February 2025's patches share a pattern: the bar to exploit them keeps dropping, often to a ready-made GitHub proof of concept. Henry opens with CVE-2025-21293, an Active Directory elevation of privilege that now has a live proof of concept abusing the little-known Network Configuration Operators security group. He then covers CVE-2025-21418, an actively exploited WinSock (AFD.sys) zero-day that reaches back to Server 2008. Ryan and Brian cover a 7-Zip Mark of the Web bypass and an Apple AirPlay flaw. The 7-Zip, AirPlay, and Disk Cleanup bugs all target trusted, low-suspicion surfaces. The hosts note that behavioral, non-Windows EDR may catch the 7-Zip bypass that Defender misses.
)
)
)
)
)
)
)