Find notable cyber news and cases, enriched with sources, timelines, and signals.

Windows Agere Modem driver active zero-day (CVE-2025-24990)

Vulnerability
First reported
Last updated
Happening score
H score 45
2 unique sources, 2 articles

Summary

Hide ▲

CVE-2025-24990 is an actively exploited zero-day in the Agere Modem driver bundled with Windows for years, and Microsoft responded by removing the vulnerable driver. The flaw affects Windows systems with the bundled third-party modem driver and was addressed in October 2025 as part of Patch Tuesday.

Related Happenings

Microsoft adds Cloud-Initiated Driver Recovery for Windows Update driver rollbacks

Security Tool/Service
H score10 First: 15.05.2026 15:29 Last: 15.05.2026 15:29 Sources 1

About this happening: Microsoft is adding Cloud-Initiated Driver Recovery to Windows Update, giving it a remote rollback control for problematic Windows drivers. The capability reduces how...

Cloud Software Group NetScaler urgent remediation advisory

Advisory/Mitigation
H score44 First: 25.03.2026 17:52 Last: 25.03.2026 17:52 Sources 1

About this happening: Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...

EDR killer abusing EnPortv.sys to disable 59 security tools

Malware Activity
H score19 First: 04.02.2026 16:17 Last: 04.02.2026 16:17 Sources 1

About this happening: A custom EDR killer abused EnPortv.sys to disable endpoint security tools on infected Windows hosts, creating a window for follow-on intrusion activity. The 64-bit executa...

Windows 10 Agere modem drivers actively exploited elevation-of-privileges privilege-escalation flaw

Vulnerability
H score26 First: 13.01.2026 20:56 Last: 13.01.2026 20:56 Sources 1

About this happening: An actively exploited elevation-of-privileges flaw in built-in Agere modem drivers exposed Windows 10 systems to privilege escalation risk until KB5073724 was inst...

Microsoft Windows 11 WSL VPN connectivity disruption

Service Disruption
H score0 First: 15.12.2025 16:34 Last: 15.12.2025 16:34 Sources 1

About this happening: Recent Windows 11 security updates are disrupting VPN connectivity for Windows Subsystem for Linux (WSL) users in enterprise environments, blocking access to corpora...

Timeline

  1. 15.10.2025 01:57 3 articles · 9mo ago

    Microsoft discloses and removes CVE-2025-24990 Agere Modem zero-day

    Initial Disclosure

    Microsoft released 172 security updates in October Patch Tuesday and identified CVE-2025-24990 as an actively exploited zero-day in the bundled Agere Modem driver affecting Windows systems. Microsoft also removed the vulnerable driver from Windows after active attacks were observed.

    Show sources