Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
What Travel Marketers Need To Know Now

What Travel Marketers Need To Know Now

4 June 2026
Why SpaceX is breaking the IPO playbook with a  billion fixed-price offering

Why SpaceX is breaking the IPO playbook with a $75 billion fixed-price offering

4 June 2026
This Jellyfish Has 24 Eyes — A Biologist Explains What It Actually Sees With Them

This Jellyfish Has 24 Eyes — A Biologist Explains What It Actually Sees With Them

4 June 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » Windows Passwords At Risk As New 0-Day Confirmed—Act Now
Innovation

Windows Passwords At Risk As New 0-Day Confirmed—Act Now

Press RoomBy Press Room26 March 20254 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
Windows Passwords At Risk As New 0-Day Confirmed—Act Now

Oh boy, it’s raining zero days for Windows users right now. Just two weeks on from Microsoft confirming no less than six zero-day attacks impacting users in the Windows operating system, like London buses, another has belatedly arrived. The difference, however, is this latest threat to all users of Windows Workstation and Server versions from Windows 7 and Server 2008 R2 to the latest Windows 11 v24H2 and Server 2025, has no official patch from Microsoft to fix it. This is a problem when you consider the endgame of an attacker exploiting this vulnerability is to steal password cases and bypass authentication protections. The good news is that there is a way to fix it, at least while you wait for Microsoft to act. Here’s what you need to know.

This Windows Password Hash Vulnerability Is So New It Doesn’t Have A Number Yet

A private message from Mitja Kolsek on the X social media platform dropped in my inbox late on March 25. I tend to take anything I receive from Kolsek seriously, as he’s the CEO of ACROS Security. This company develops and distributes unofficial security patches for zero-day vulnerabilities where no official fix is available. “We reported this to Microsoft and will not disclose details until they have issued an official patch,” was enough to trigger my journalistic intrigue and should be enough to trigger your desire to apply a temporary fix as well. Why so? Because, Kolsek explained, his researchers uncovered a vulnerability that “allows an attacker to obtain user’s NTLM credentials by having the user view a malicious file in Windows Explorer.”

If this sounds familiar, there’s a good reason for that: I reported on a very similar Windows zero-day Dec. 6, 2024. Similar, but not the same. The “impact and attack scenarios of this issue are identical,” Kolsek said, but the latest vulnerability is different and not yet publicly discussed. As already mentioned, Kolsek isn’t going to be releasing the full technical details any time soon, at least not until Microsoft has issued a patch.

What we do know is that these NT Lan Manager vulnerabilities can enable an attacker to steal Windows credentials by simply tricking the user into viewing a malicious file. NTLM is a suite of Microsoft security protocols providing authentication, integrity and confidentiality to users. This is why the zero-day is of such importance, although it’s not thought of as critical. “These types of vulnerabilities are not critical,” Kolsek said, “and their exploitability depends on several factors.” But, and it’s a big but, they have been used in real-world attacks, and that’s all you need to know. Well, that and the minor detail that NTLM exploits, including relay attacks to bypass authentication and pass-the-hash attacks to steal credentials, are widely used to gain access to networks, with all that can bring to the hacking party.

As Microsoft Investigates, Windows Users Can Use This Temporary Fix

Given all of the above and the fact that a Microsoft spokesperson said, “We are aware of this report and will take action as needed to help keep customers protected,” which likely means waiting until the next Patch Tuesday at least, I’d recommend taking action now.

This is where Kolsek and his micro patch solution enter stage left. 0patch seeks to address the vulnerability gap, that time between a zero-day being discovered and an official patch being released, by providing free mini-fixes in the meantime. This works using a patching agent that analyzes processes and applies any new patch in memory without disturbing the process itself. “Since this is a 0day vulnerability with no official vendor fix available,” Kolsek said, “we are providing our micropatches for free until such fix becomes available.” If you use Windows, you know what to do.

Microsoft NTLM Password Hash Windfows 11 Windows 10 Windows Network Windows Passwrod Windows Vulnerability windows zero-day Zero Day
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

What Travel Marketers Need To Know Now

What Travel Marketers Need To Know Now

4 June 2026
This Jellyfish Has 24 Eyes — A Biologist Explains What It Actually Sees With Them

This Jellyfish Has 24 Eyes — A Biologist Explains What It Actually Sees With Them

4 June 2026
Why Continuous Security Validation Matters More Than Ever

Why Continuous Security Validation Matters More Than Ever

4 June 2026
Why Finance Transformation Is Failing—And It’s Not The Technology

Why Finance Transformation Is Failing—And It’s Not The Technology

4 June 2026
Audio Technica Launches Flagship Cartridge AT-MCD1 At High End Vienna

Audio Technica Launches Flagship Cartridge AT-MCD1 At High End Vienna

4 June 2026
Apple Blasts Android And Chrome In New Ad Campaign On iPhone Privacy

Apple Blasts Android And Chrome In New Ad Campaign On iPhone Privacy

4 June 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

Sam Altman’s World Wants To Scan Your Eyes To Prove You’re Human

22 October 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Why Continuous Security Validation Matters More Than Ever

Why Continuous Security Validation Matters More Than Ever

4 June 20262 Views
In SpaceX’s IPO: a Tesla merger clue and a .75 billion insider windfall for friends and family

In SpaceX’s IPO: a Tesla merger clue and a $3.75 billion insider windfall for friends and family

4 June 20260 Views
Why Finance Transformation Is Failing—And It’s Not The Technology

Why Finance Transformation Is Failing—And It’s Not The Technology

4 June 20260 Views
These COOs became CEOs. Here’s what they wish everyone knew about succession planning

These COOs became CEOs. Here’s what they wish everyone knew about succession planning

4 June 20262 Views

Recent Posts

  • What Travel Marketers Need To Know Now
  • Why SpaceX is breaking the IPO playbook with a $75 billion fixed-price offering
  • This Jellyfish Has 24 Eyes — A Biologist Explains What It Actually Sees With Them
  • BT’s CEO is bringing football logic to Britain’s digital future
  • Why Continuous Security Validation Matters More Than Ever

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
What Travel Marketers Need To Know Now

What Travel Marketers Need To Know Now

4 June 2026
Why SpaceX is breaking the IPO playbook with a  billion fixed-price offering

Why SpaceX is breaking the IPO playbook with a $75 billion fixed-price offering

4 June 2026
This Jellyfish Has 24 Eyes — A Biologist Explains What It Actually Sees With Them

This Jellyfish Has 24 Eyes — A Biologist Explains What It Actually Sees With Them

4 June 2026
Most Popular
BT’s CEO is bringing football logic to Britain’s digital future

BT’s CEO is bringing football logic to Britain’s digital future

4 June 20261 Views
Why Continuous Security Validation Matters More Than Ever

Why Continuous Security Validation Matters More Than Ever

4 June 20262 Views
In SpaceX’s IPO: a Tesla merger clue and a .75 billion insider windfall for friends and family

In SpaceX’s IPO: a Tesla merger clue and a $3.75 billion insider windfall for friends and family

4 June 20260 Views

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.