A zero day vulnerability called LegacyHive is now actively exploited against Windows systems, giving attackers administrator access even on fully patched machines by abusing the User Profile Service. Microsoft has not released a patch yet, so SMBs must implement immediate compensating controls while waiting for the fix.
Federal authorities issued urgent warnings today as CISA added two actively exploited Fortinet FortiSandbox vulnerabilities to its Known Exploited Vulnerabilities catalog. These critical flaws allow attackers to execute unauthorized commands on affected systems. Federal agencies must patch by July 19th, and private organizations should act immediately.
A newly disclosed Windows zero-day vulnerability called LegacyHive poses significant risk to businesses. The flaw allows attackers to gain administrator access on fully patched Windows systems by abusing the User Profile Service, without exploiting any traditional software bugs. Microsoft has not yet released a patch.
Mac users face new threats from ClickLock stealer malware, which uses social engineering tactics and fake verification pages to steal credentials. The malware repeatedly crashes applications to force users to enter their passwords.
In legal news, 23andMe reached an $18 million settlement with 42 state attorneys general following its 2023 data breach that exposed 6 million users' genetic information. The settlement mandates enhanced security measures including risk analysis, an Advisory Board, and continued user data deletion rights.
Sources: Infosecurity Magazine, BleepingComputer, GBHackers, Security Affairs
What does the LegacyHive zero day vulnerability mean for your business?
The LegacyHive zero day bypasses traditional patching because it exploits the User Profile Service without triggering software vulnerabilities. This matters to manufacturing and professional services firms because it affects Windows systems you thought were protected. CISA typically releases workarounds for unpatched zero days within 48-72 hours. Your immediate action: check CISA.gov for LegacyHive mitigation steps, restrict User Profile Service access to admin accounts only, and monitor Windows event logs for suspicious credential activity. Fortinet vulnerabilities demand equal urgency, apply patches for FortiSandbox before July 19th (federal deadline) or disable the appliance if you cannot patch in time.
Key takeaways
- Windows zero day LegacyHive has no patch yet; watch CISA.gov daily for official workarounds and apply them immediately.
- Fortinet FortiSandbox flaws are actively exploited now. Patch by July 19th or disable the system until patched.
- Both threats bypass standard defenses. Test your incident response plan to confirm your team can isolate affected systems quickly.
Frequently asked questions
Do I need to worry about the zero day vulnerability if I use Mac?
Not for LegacyHive, which targets Windows. However, Mac users face ClickLock stealer malware that uses fake verification pages to capture credentials. Warn your team not to re-enter passwords after app crashes and verify requests through official channels before providing credentials.
What should I do about the Fortinet warning?
Check your network for FortiSandbox appliances. If you have them, apply patches immediately. If you cannot patch before July 19th, consider disabling the appliance until patches are tested and deployed. Contact your Fortinet vendor or MSP for patch availability.
How does the 23andMe settlement affect my business?
If your firm uses third-party SaaS tools (HR systems, cloud storage, email vendors), this breach shows why vendor security matters. Audit your contracts to confirm vendors perform risk assessments and delete customer data on request. Add security clauses to renewal agreements.
Where do I find official guidance on these threats?
Visit CISA.gov for the Known Exploited Vulnerabilities catalog, security alerts, and free mitigation guidance. Federal agencies must follow CISA timelines, but private SMBs should treat CISA advisories as urgent benchmarks and act within 24-48 hours of a warning.