Category: Microsoft

  • Microsoft shares manual fix for WSUS sync delays and timeouts

    Microsoft shares manual fix for WSUS sync delays and timeouts Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. […] Sergiu Gatlan Go to bleepingcomputer

  • Windows LegacyHive zero-day flaw gets free, unofficial patches

    Windows LegacyHive zero-day flaw gets free, unofficial patches Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. […] Sergiu Gatlan Go to bleepingcomputer

  • New Windows LegacyHive zero-day gives hackers admin privileges

    New Windows LegacyHive zero-day gives hackers admin privileges A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. […] Sergiu Gatlan Go to bleepingcomputer

  • Windows Server 2022 reach end of mainstream support in 90 days

    Windows Server 2022 reach end of mainstream support in 90 days Microsoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years. […] Sergiu Gatlan Go to bleepingcomputer

  • CISA warns admins to patch actively exploited SharePoint flaws

    CISA warns admins to patch actively exploited SharePoint flaws The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft: Some Dell PCs shut down after recent Windows updates

    Microsoft: Some Dell PCs shut down after recent Windows updates Microsoft is blocking this month’s Windows 11 security updates on some Dell devices because they are causing shutdowns and performance issues. […] Sergiu Gatlan Go to bleepingcomputer

  • Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts

    Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts Forg365 is a phishing-as-a-service platform that targets Microsoft accounts, combining AI-powered phishing, session theft, and post-compromise mailbox access in a single operator panel The platform is reportedly distributed through Telegram, where criminals can access a 30-day trial, pay about per month, or choose an annual…

  • Microsoft expects more Windows security updates from AI-discovered flaws

    Microsoft expects more Windows security updates from AI-discovered flaws Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase. […] Lawrence Abrams Go to bleepingcomputer

  • Microsoft patches RoguePlanet Defender zero-day vulnerability

    Microsoft patches RoguePlanet Defender zero-day vulnerability Microsoft has released a security patch to address a Defender zero-day vulnerability known as “RoguePlanet,” disclosed after the June 2026 Patch Tuesday. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft Releases Patches for RoguePlanet Defender Zero-Day Vulnerability

    Microsoft Releases Patches for RoguePlanet Defender Zero-Day Vulnerability Microsoft has released security updates to address a newly disclosed zero-day vulnerability in Microsoft Defender, publicly referred to as “RoguePlanet.” The flaw, tracked as CVE-2026-50656, affects the Microsoft Malware Protection Engine and could allow attackers to gain elevated privileges on vulnerable systems. The vulnerability is classified as…

  • Microsoft to enable Windows settings backup by default for orgs

    Microsoft to enable Windows settings backup by default for orgs Microsoft says the Windows settings backup and restore tool will be enabled by default on Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems after upgrading to Windows 11 26H2. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft testing new Cloud Rebuild Windows 11 recovery feature

    Microsoft testing new Cloud Rebuild Windows 11 recovery feature Microsoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft fixes bug that removed Copilot buttons in Outlook

    Microsoft fixes bug that removed Copilot buttons in Outlook Microsoft has fixed a known issue causing the Copilot Chat or Copilot buttons in Classic Outlook to disappear for Windows users with the Copilot Chat (Basic) license. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit

    Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit Security researchers from HawkTrace have disclosed technical details of a high-severity server-side request forgery (SSRF) vulnerability in Microsoft Exchange, tracked as CVE-2026-45504. The flaw, which carries a CVSS score of 8.8, allows authenticated, low-privileged users to read arbitrary files from vulnerable Exchange servers, raising…

  • Microsoft quietly extends free Windows 10 ESU support to October 2027

    Microsoft quietly extends free Windows 10 ESU support to October 2027 Microsoft has quietly extended its free Windows 10 Extended Security Updates (ESU) program for consumers by an additional year, allowing enrolled devices to continue receiving security updates until October 12, 2027. […] Lawrence Abrams Go to bleepingcomputer

  • Windows 11 KB5095093 update rolls out new Point-in-Time restore feature

    Windows 11 KB5095093 update rolls out new Point-in-Time restore feature ​​Microsoft has released the KB5095093 preview cumulative update for Windows 11 24H2 and 25H2, which fixes numerous bugs and begins rolling out new features, including the new Point-in-Time restore feature. […] Lawrence Abrams Go to bleepingcomputer

  • Microsoft says Windows 11 26H2 is coming soon, details upgrade process

    Microsoft says Windows 11 26H2 is coming soon, details upgrade process Microsoft has confirmed that Windows 11 version 26H2 will be the next feature update and that devices running Windows 11 24H2 and 25H2 will be able to upgrade using a small enablement package. […] Lawrence Abrams Go to bleepingcomputer

  • Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed

    Smashing Security podcast #472: AI gets hacked, and BitLocker gets bypassed What if your AI coding assistant could be tricked into stealing your own company’s secrets – by reading a single booby-trapped bug report? No phishing email. No malware. No password ever stolen. Just an AI doing exactly what it was told. Meanwhile, someone themselves…

  • Microsoft working on Defender patch for RoguePlanet zero-day

    Microsoft working on Defender patch for RoguePlanet zero-day Microsoft confirmed that it’s working on a security patch for a Defender zero-day vulnerability named “RoguePlanet,” disclosed one week ago. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft fixes BitLocker recovery bug on Windows Server 2025

    Microsoft fixes BitLocker recovery bug on Windows Server 2025 Microsoft has resolved a known issue causing some Windows Server 2025 devices to boot into BitLocker recovery after installing the April 2026 security update. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days

    Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days On Tuesday, Microsoft patched two zero-day vulnerabilities that let attackers gain SYSTEM privileges on fully patched Windows systems, and a third one that grants access to BitLocker-protected drives. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft Defender ‘RoguePlanet’ zero-day grants SYSTEM privileges

    Microsoft Defender ‘RoguePlanet’ zero-day grants SYSTEM privileges A security researcher has released a new Microsoft Defender zero-day exploit named “RoguePlanet” just hours after Microsoft fixed two previously disclosed flaws during June 2026 Patch Tuesday. […] Lawrence Abrams Go to bleepingcomputer

  • Hands on with Intelligent Terminal, an AI-powered Windows Terminal

    Hands on with Intelligent Terminal, an AI-powered Windows Terminal Microsoft has created an open-source fork of Windows Terminal called “Intelligent Terminal,” and it allows you to use AI directly inside Terminal without interfering with the regular session. […] Mayank Parmar Go to bleepingcomputer

  • VS Code zero-day lets hackers steal GitHub tokens in one click

    VS Code zero-day lets hackers steal GitHub tokens in one click A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows attackers to steal GitHub authentication tokens by tricking users into clicking a link. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft’s Coreutils project brings Linux commands to Windows

    Microsoft’s Coreutils project brings Linux commands to Windows Microsoft announced today at its Build 2026 developer conference the release of Coreutils for Windows, bringing many commonly used Linux command-line utilities to Windows as native applications. […] Lawrence Abrams Go to bleepingcomputer

  • Microsoft Threatening Security Researcher

    Microsoft Threatening Security Researcher An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal action against the researcher. Lots of recriminations are being traded back and forth. Bruce Schneier Go to bruce schneier

  • Microsoft Tightens Entra ID Password Resets With New Authentication Change

    Microsoft Tightens Entra ID Password Resets With New Authentication Change Microsoft has announced a significant security update to its Entra ID Self-Service Password Reset (SSPR) feature, introducing stricter authentication requirements designed to reduce identity-based attacks. The update mandates the use of explicitly registered authentication methods, removing reliance on directory-stored contact information that has not been…

  • Microsoft Clarifies It Won’t Sue Security Researchers Amid Nightmare-Eclipse Controversy

    Microsoft Clarifies It Won’t Sue Security Researchers Amid Nightmare-Eclipse Controversy Microsoft has clarified its stance, reducing perceived legal threats and reaffirming its commitment to coordinated vulnerability disclosure, following significant backlash from the security research community. In a carefully worded statement released in late May 2026, Microsoft’s Security Response Center (MSRC) moved to defuse a growing crisis over…

  • Microsoft Warns Public Release of Zero-Day Details Before Vendor Coordination

    Microsoft Warns Public Release of Zero-Day Details Before Vendor Coordination Microsoft has issued a strong warning after multiple zero-day vulnerabilities were publicly disclosed without prior coordination, raising concerns about increased risk to users and enterprise environments. The company stated that recent disclosures exposed critical security flaws before patches were available, giving threat actors a potential…

  • Windows 11 KB5089573 update released with performance improvements

    Windows 11 KB5089573 update released with performance improvements Microsoft has released the KB5089573 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 30 changes, including performance and reliability improvements. […] Sergiu Gatlan Go to bleepingcomputer

  • FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required

    FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts – no password required So, you’ve enabled multi-factor authentication. You’ve taught your staff never to type their passwords into dodgy-looking login pages. Surely your Microsoft 365 accounts are safe now? Well, think again. Read more in my article on the Hot for Security…

  • Microsoft: Domain Controller lookup may fail on Windows Server 2016

    Microsoft: Domain Controller lookup may fail on Windows Server 2016 Microsoft has confirmed a new known issue affecting Windows Server 2016 systems that causes domain controller lookups to fail after installing the KB5087537 May 2026 security update. […] Sergiu Gatlan Go to bleepingcomputer

  • FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA

    FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA The FBI has issued a new cybersecurity warning about a rapidly emerging phishing-as-a-service (PhaaS) platform named Kali365, which is actively targeting Microsoft 365 users to steal access tokens and bypass multi-factor authentication (MFA). Kali365 is being distributed primarily through Telegram channels,…

  • Microsoft warns of new Defender zero-days exploited in attacks

    Microsoft warns of new Defender zero-days exploited in attacks On Wednesday, Microsoft started rolling out security patches for two Defender vulnerabilities that have been exploited in zero-day attacks. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft shares mitigation for YellowKey Windows zero-day

    Microsoft shares mitigation for YellowKey Windows zero-day Microsoft has shared mitigations for YellowKey, a recently disclosed Windows BitLocker zero-day vulnerability that grants access to protected drives. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft confirms Windows 11 security update install issues

    Microsoft confirms Windows 11 security update install issues Microsoft has confirmed that the May 2026 Windows 11 security update (KB5089549) fails to install on some systems and triggers 0x800f0922 errors. […] Sergiu Gatlan Go to bleepingcomputer

  • New Windows ‘MiniPlasma’ zero-day exploit gives SYSTEM access, PoC released

    New Windows ‘MiniPlasma’ zero-day exploit gives SYSTEM access, PoC released A cybersecurity researcher has released a proof-of-concept exploit for a Windows privilege escalation zero-day dubbed “MiniPlasma” that lets attackers gain SYSTEM privileges on fully patched Windows systems.  […] Lawrence Abrams Go to bleepingcomputer

  • CISA Warns of Microsoft Exchange Server Vulnerability Exploited in Attacks

    CISA Warns of Microsoft Exchange Server Vulnerability Exploited in Attacks CISA has issued a fresh warning about a newly disclosed Microsoft Exchange Server vulnerability that is already being exploited in real-world attacks, raising concerns for organizations relying on on-premises email infrastructure. The flaw CVE-2026-42897 is a cross-site scripting (XSS) vulnerability affecting Microsoft Exchange Server, specifically within…

  • Microsoft Exchange, Windows 11, and Cursor Zero-Days Exploited on Pwn2Own Day 2

    Microsoft Exchange, Windows 11, and Cursor Zero-Days Exploited on Pwn2Own Day 2 Pwn2Own Berlin 2026 is rapidly escalating into one of the most intense offensive security contests in recent years, with Day Two delivering a fresh wave of critical zero-day exploits targeting enterprise software, AI tools, and operating systems. Security researchers demonstrated real-world attack scenarios…

  • Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own

    Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own ​During the second day of Pwn2Own Berlin 2026, competitors collected $385,750 in cash awards after exploiting 15 unique zero-day vulnerabilities in multiple products, including Windows 11, Microsoft Exchange, and Red Hat Enterprise Linux for Workstations. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft backpedals: Edge to stop loading passwords into memory

    Microsoft backpedals: Edge to stop loading passwords into memory Microsoft is updating the Edge web browser to ensure it no longer loads saved passwords into process memory in clear text at startup after previously stating it was “by design.” […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft warns of Exchange zero-day flaw exploited in attacks

    Microsoft warns of Exchange zero-day flaw exploited in attacks On Thursday, Microsoft shared mitigations for a high-severity Exchange Server vulnerability exploited in attacks that allow threat actors to execute arbitrary code via cross-site scripting (XSS) while targeting Outlook on the web users. […] Sergiu Gatlan Go to bleepingcomputer

  • Critical Microsoft Exchange Server Vulnerability Actively Exploited in Attacks

    Critical Microsoft Exchange Server Vulnerability Actively Exploited in Attacks Microsoft issued an urgent security alert regarding a newly discovered vulnerability in Exchange Server that is currently being exploited in the wild. Tracked as CVE-2026-42897, this critical spoofing flaw carries a high CVSS 3.1 severity score of 8.1 and directly impacts on-premises email infrastructure. Threat actors…

  • Microsoft releases Windows 10 KB5087544 extended security update

    Microsoft releases Windows 10 KB5087544 extended security update Microsoft has released the Windows 10 KB5087544 extended security update to fix the May 2026 Patch Tuesday vulnerabilities and resolve an issue with the new Remote Desktop warnings. […] Lawrence Abrams Go to bleepingcomputer

  • Patch Tuesday, May 2026 Edition

    Patch Tuesday, May 2026 Edition Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this month with some of the more widely-used software makers — including Apple, Google, Microsoft, Mozilla…

  • Microsoft Teams for Android Allow Users to Join Third-Party Meetings via SIP

    Microsoft Teams for Android Allow Users to Join Third-Party Meetings via SIP Microsoft is expanding interoperability in its mobile communication ecosystem by allowing Microsoft Teams users on Android devices to join third-party meetings via the Session Initiation Protocol (SIP). Recently detailed on the Microsoft 365 roadmap, this upcoming feature addresses a major enterprise demand for…

  • Azure AD Conditional Access Bypassed Via Phantom Device Registration and PRT Abuse

    Azure AD Conditional Access Bypassed Via Phantom Device Registration and PRT Abuse Cloud identity security relies heavily on Microsoft Entra ID (formerly Azure AD) Conditional Access. It acts as the primary digital gatekeeper, checking user locations, calculating risk scores, and verifying device health before granting access. However, an authorized red team engagement by Howler Cell…

  • Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha

    Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha Microsoft Defender is detecting legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha, resulting in widespread false-positive alerts, and in some cases, removing certificates from Windows. […] Lawrence Abrams Go to bleepingcomputer

  • Microsoft tests modern Windows Run, says it’s faster than legacy dialog

    Microsoft tests modern Windows Run, says it’s faster than legacy dialog Microsoft has confirmed that Windows 11 is getting a new modern Run dialog with dark mode support and faster performance in a new preview build. […] Mayank Parmar Go to bleepingcomputer

  • Windows 11 KB5083631 update released with 34 changes and fixes

    Windows 11 KB5083631 update released with 34 changes and fixes Microsoft has released the KB5083631 optional cumulative update for Windows 11, which includes 34 changes, such as a new Xbox mode for Windows PCs, enhanced security and performance for batch files, and performance improvements for launching startup apps. […] Sergiu Gatlan Go to bleepingcomputer

  • Alleged Silk Typhoon hacker extradited to the United States to face charges

    Alleged Silk Typhoon hacker extradited to the United States to face charges A man accused of working as a hacker for China’s Ministry of State Security has been extradited to the USA from Italy, and faces – if found guilty – the prospect of decades behind bars. Read more in my article on the Hot…

  • Microsoft: New Remote Desktop warnings may display incorrectly

    Microsoft: New Remote Desktop warnings may display incorrectly Microsoft has confirmed a new issue causing newly introduced Windows security warnings to display incorrectly when opening Remote Desktop (.rdp) files. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft asks iPhone users to reauthenticate after Outlook outage

    Microsoft asks iPhone users to reauthenticate after Outlook outage After addressing a widespread outage that affected Outlook.com users worldwide on Monday, Microsoft has asked iPhone users to re-enter their credentials to regain access to their Outlook and Hotmail accounts via the default Mail app. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft rolls out revamped Windows Insider Program

    Microsoft rolls out revamped Windows Insider Program Microsoft says it’s rolling out a revamped Windows Insider Program experience as part of the broader plans to address performance and reliability concerns affecting Windows 11. […] Mayank Parmar Go to bleepingcomputer

  • Windows Update gets new controls to reduce forced restarts

    Windows Update gets new controls to reduce forced restarts Microsoft is rolling out Windows Update improvements that give users more control over how updates are installed while reducing disruption from frequent or poorly timed restarts. […] Lawrence Abrams Go to bleepingcomputer

  • Microsoft to roll out Entra passkeys on Windows in late April

    Microsoft to roll out Entra passkeys on Windows in late April Microsoft will roll out passkey support for phishing-resistant passwordless authentication to Microsoft Entra‑protected resources from Windows devices starting late April. […] Sergiu Gatlan Go to bleepingcomputer

  • Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals

    Hackers Can Abuse Entra Agent ID Administrator Role to Hijack Service Principals A critical scope overreach vulnerability was recently identified in the Microsoft Entra Agent Identity Platform. The newly introduced Agent ID Administrator role allowed accounts to hijack arbitrary service principals and escalate privileges across the entire tenant. Microsoft has fully patched this behavior across…

  • Microsoft releases emergency patches for critical ASP.NET flaw

    Microsoft releases emergency patches for critical ASP.NET flaw Microsoft has released out-of-band (OOB) security updates to patch a critical ASP.NET Core privilege escalation vulnerability. […] Sergiu Gatlan Go to bleepingcomputer

  • Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks

    Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks Over 1,300 Microsoft SharePoint servers exposed online remain unpatched against a spoofing vulnerability that was exploited as a zero-day and is still being abused in ongoing attacks. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft pulls service update causing Teams launch failures

    Microsoft pulls service update causing Teams launch failures Microsoft has reverted a recent service update that was preventing some customers from launching the Microsoft Teams desktop client. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft releases emergency updates to fix Windows Server issues

    Microsoft releases emergency updates to fix Windows Server issues Microsoft has released out-of-band (OOB) updates to fix issues affecting Windows Server systems after installing the April 2026 security updates. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft Teams right-click paste broken by Edge update bug

    Microsoft Teams right-click paste broken by Edge update bug Microsoft is warning that a recent Microsoft Edge browser update introduced a bug that breaks right-click paste in chats in the Microsoft Teams desktop client. […] Lawrence Abrams Go to bleepingcomputer

  • Sometimes changing the password on your email mailbox isn’t enough

    Sometimes changing the password on your email mailbox isn’t enough Have you ever taken a look at your Microsoft 365 mailbox rules? If not, it might be worth a few minutes of your time. Because newly released research reveals that hackers may already have beaten you to it. Read more in my article on the…

  • Microsoft: Some Windows servers enter reboot loops after April patches

    Microsoft: Some Windows servers enter reboot loops after April patches Microsoft warns that some Windows domain controllers are entering restart loops after installing the April 2026 security updates. […] Sergiu Gatlan Go to bleepingcomputer

  • Recently leaked Windows zero-days now exploited in attacks

    Recently leaked Windows zero-days now exploited in attacks Threat actors are exploiting three recently disclosed Windows security vulnerabilities in attacks aimed at gaining SYSTEM or elevated administrator permissions. […] Sergiu Gatlan Go to bleepingcomputer

  • Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network

    Windows Snipping Tool Vulnerability Allows Attacker to Perform Spoofing Over a Network Microsoft has addressed a moderate-severity security flaw in the Windows Snipping Tool that could allow malicious actors to steal user credentials. Tracked as CVE-2026-33829, this spoofing vulnerability was officially patched during the April 14, 2026, security updates. Discovered and reported by security researchers…

  • Microsoft: April Windows Server 2025 update may fail to install

    Microsoft: April Windows Server 2025 update may fail to install Microsoft is investigating an issue causing this month’s KB5082063 security update to fail to install on some Windows Server 2025 systems. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft adds Windows protections for malicious Remote Desktop files

    Microsoft adds Windows protections for malicious Remote Desktop files Microsoft has introduced new Windows protections to defend against phishing attacks that abuse Remote Desktop connection (.rdp) files, adding warnings and disabling risky shared resources by default. […] Lawrence Abrams Go to bleepingcomputer

  • Microsoft releases Windows 10 KB5082200 extended security update

    Microsoft releases Windows 10 KB5082200 extended security update Microsoft has released the Windows 10 KB5082200 extended security update to fix the April 2026 Patch Tuesday vulnerabilities, including 2 zero-days. […] Lawrence Abrams Go to bleepingcomputer

  • Microsoft Defender 0-Day Vulnerability Enables Privilege Escalation Attack

    Microsoft Defender 0-Day Vulnerability Enables Privilege Escalation Attack Microsoft has released patch Tuesday security updates to address a newly discovered zero-day vulnerability in the Microsoft Defender Antimalware Platform.   Disclosed on April 14, 2026, the flaw is tracked as CVE-2026-33825 and carries an “Important” severity rating. If successfully exploited, this elevation-of-privilege vulnerability allows an attacker…

  • Microsoft Confirms Recent Windows 11 Updates Break Push Button Reset

    Microsoft Confirms Recent Windows 11 Updates Break Push Button Reset Microsoft has officially acknowledged that recent security updates for Windows 11 are causing the “Reset this PC” (Push-button reset) recovery feature to fail. The issue was confirmed in the release notes for the March 2026 hotpatch updates, affecting systems running the latest operating system version.…

  • Microsoft: Canadian employees targeted in payroll pirate attacks

    Microsoft: Canadian employees targeted in payroll pirate attacks A financially motivated threat actor tracked as Storm-2755 is stealing Canadian employees’ salary payments after hijacking their accounts in payroll pirate attacks. […] Sergiu Gatlan Go to bleepingcomputer

  • On Microsoft’s Lousy Cloud Security

    On Microsoft’s Lousy Cloud Security ProPublica has a scoop: In late 2024, the federal government’s cybersecurity evaluators rendered a troubling verdict on one of Microsoft’s biggest cloud computing offerings. The tech giant’s “lack of proper detailed security documentation” left reviewers with a “lack of confidence in assessing the system’s overall security posture,” according to an…

  • Microsoft suspends dev accounts for high-profile open source projects

    Microsoft suspends dev accounts for high-profile open source projects Microsoft has suspended developer accounts used to maintain multiple high-profile open-source projects without proper notification and no way to quickly reinstate them, effectively blocking them from publishing new software builds and security patches for Windows users. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft Suspends Developer Accounts of High-Profile Open-Source Projects

    Microsoft Suspends Developer Accounts of High-Profile Open-Source Projects Microsoft has suspended the Windows Hardware Program developer accounts of two critical open-source security projects, VeraCrypt and WireGuard, blocking their ability to sign drivers and push updates to millions of Windows users, with no prior warning or explanation provided to the developers. Mounir Idrassi, the lead developer…

  • Microsoft rolls out fix for broken Windows Start Menu search

    Microsoft rolls out fix for broken Windows Start Menu search Microsoft has pushed a server-side fix for a known issue that broke the Windows Start Menu search feature on some Windows 11 23H2 devices. […] Sergiu Gatlan Go to bleepingcomputer

  • Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit

    Disgruntled researcher leaks “BlueHammer” Windows zero-day exploit Exploit code has been released for an unpatched Windows privilege escalation flaw reported privately to Microsoft, allowing attackers to gain SYSTEM or elevated administrator permissions. […] Bill Toulas Go to bleepingcomputer

  • Microsoft fixes Classic Outlook bug causing email delivery issues

    Microsoft fixes Classic Outlook bug causing email delivery issues Microsoft has resolved a known issue that was preventing some Classic Outlook users from sending emails via Outlook.com. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft removes Support and Recovery Assistant from Windows

    Microsoft removes Support and Recovery Assistant from Windows Microsoft has deprecated and removed the Support and Recovery Assistant (SaRA) command-line utility from all in-support versions of Windows updates starting March 10. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft Releases New Defender Update for Windows 11, 10, and Server Installation Images

    Microsoft Releases New Defender Update for Windows 11, 10, and Server Installation Images Microsoft has officially rolled out its latest security intelligence update for Microsoft Defender Antivirus, delivering crucial protections for Windows 11, Windows 10, and Windows Server installation images. This vital release ensures that Microsoft’s built-in antimalware solutions are fully equipped to identify and neutralize…

  • Microsoft still working to fix Exchange Online mailbox access issues

    Microsoft still working to fix Exchange Online mailbox access issues Microsoft is investigating and working to resolve Exchange Online mailbox access issues that have intermittently affected Outlook mobile and macOS users for weeks. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft now force upgrades unmanaged Windows 11 24H2 PCs

    Microsoft now force upgrades unmanaged Windows 11 24H2 PCs Starting this week, Microsoft has begun force-upgrading unmanaged devices running Windows 11 24H2 Home and Pro editions to Windows 11 25H2. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft links Classic Outlook issue to email delivery problems

    Microsoft links Classic Outlook issue to email delivery problems Microsoft is investigating a known issue that prevents some Classic Outlook users from sending emails via Outlook.com. […] Sergiu Gatlan Go to bleepingcomputer

  • New Windows 11 emergency update fixes preview update install issues

    New Windows 11 emergency update fixes preview update install issues Microsoft released an emergency update to fix the March 2026 KB5079391 non-security preview update, which was pulled over the weekend due to installation issues. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft pulls KB5079391 Windows update over install issues

    Microsoft pulls KB5079391 Windows update over install issues Microsoft has pulled a buggy Windows 11 non-security preview update to investigate a known issue that triggers 0x80073712 errors during installation. […] Sergiu Gatlan Go to bleepingcomputer

  • Windows 11 KB5079391 update rolls out Smart App Control improvements

    Windows 11 KB5079391 update rolls out Smart App Control improvements ​Microsoft has released the KB5079391 preview cumulative update for Windows 11 24H2 and 25H2, which includes 29 changes, such as Smart App Control and Display improvements. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft Xbox One Hacked

    Microsoft Xbox One Hacked It’s an impressive feat, over a decade after the box was released: Since reset glitching wasn’t possible, Gaasedelen thought some voltage glitching could do the trick. So, instead of tinkering with the system rest pin(s) the hacker targeted the momentary collapse of the CPU voltage rail. This was quite a feat,…

  • New KB5085516 emergency update fixes Microsoft account sign-in

    New KB5085516 emergency update fixes Microsoft account sign-in Microsoft has released an emergency update to address a major issue that breaks sign-ins with Microsoft accounts across multiple Microsoft apps, including Teams and OneDrive. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft: March Windows updates break Teams, OneDrive sign-ins

    Microsoft: March Windows updates break Teams, OneDrive sign-ins Microsoft says the March Windows 11 update breaks sign-ins with Microsoft accounts across multiple Microsoft apps, including Teams and OneDrive. […] Sergiu Gatlan Go to bleepingcomputer

  • Microsoft to Stop Force Installation of 365 Copilot App on Windows Devices

    Microsoft to Stop Force Installation of 365 Copilot App on Windows Devices Microsoft has temporarily halted the automatic installation of the Microsoft 365 Copilot app on Windows devices. According to a recent update in the Microsoft 365 Message Center on March 16, 2026, the company paused the mandatory rollout, originally scheduled to be completed late…

  • Microsoft Exchange Online outage blocks access to mailboxes

    Microsoft Exchange Online outage blocks access to mailboxes Microsoft is working to address an ongoing Exchange Online outage that is preventing customers from accessing their mailboxes and calendars. […] Sergiu Gatlan Go to bleepingcomputer

  • Attackers Hijacking Legitimate Websites to Attack Microsoft Teams users

    Attackers Hijacking Legitimate Websites to Attack Microsoft Teams users A multi-vector phishing campaign using compromised WordPress sites to steal login credentials from Microsoft Teams and Xfinity users. By hijacking these trusted sites, attackers can bypass security filters and trick victims into disclosing sensitive information. The threat actors are not relying on a single method to…

  • Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability

    Microsoft to Block Windows 11 and Server 2025 Automated Installation After Critical RCE Vulnerability Microsoft has announced a two-phase plan to disable the hands-free deployment feature in Windows Deployment Services (WDS) following the discovery of a critical remote code execution (RCE) vulnerability tracked as CVE-2026-0386. The flaw, rooted in improper access control, allows an unauthenticated…

  • Microsoft releases Windows 11 OOB hotpatch to fix RRAS RCE flaw

    Microsoft releases Windows 11 OOB hotpatch to fix RRAS RCE flaw Microsoft has released an out-of-band (OOB) update to fix a security vulnerabilities affecting Windows 11 Enterprise devices that receive hotpatch updates instead of the regular Patch Tuesday cumulative updates. […] Lawrence Abrams Go to bleepingcomputer

  • Microsoft: Windows 11 users can’t access C: drive on some Samsung PCs

    Microsoft: Windows 11 users can’t access C: drive on some Samsung PCs Microsoft is investigating a new issue affecting some Samsung laptops running Windows 11 after installing the February 2026 security updates, in which users lose access to their C: drive and are unable to launch applications. […] Lawrence Abrams Go to bleepingcomputer

  • Microsoft investigates classic Outlook sync and connection issues

    Microsoft investigates classic Outlook sync and connection issues ​Microsoft is investigating several issues causing email synchronization and connection problems when using the classic Outlook desktop client. […] Sergiu Gatlan Go to bleepingcomputer

  • Critical Microsoft Office Vulnerability Enables Remote Code Execution Attacks

    Critical Microsoft Office Vulnerability Enables Remote Code Execution Attacks On March 10, 2026, Microsoft released security updates to address a critical vulnerability in its widely used Office suite. Tracked as CVE-2026-26110, this security flaw allows an unauthorized attacker to execute malicious code on a victim’s device. With a high severity rating and a CVSS base…

  • Microsoft releases Windows 10 KB5078885 extended security update

    Microsoft releases Windows 10 KB5078885 extended security update Microsoft has released the Windows 10 KB5078885 extended security update to fix the March 2026 Patch Tuesday vulnerabilities, including 2 zero-days and an issue that prevent some devices from shutting down. […] Lawrence Abrams Go to bleepingcomputer

  • Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws

    Microsoft March 2026 Patch Tuesday fixes 2 zero-days, 79 flaws Today is Microsoft’s March 2026 Patch Tuesday with security updates for 79 flaws, including 2 publicly disclosed zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer

  • Microsoft .NET 0-Day Vulnerability Enables Denial-of-Service Attacks

    Microsoft .NET 0-Day Vulnerability Enables Denial-of-Service Attacks An emergency security update has been released to address a newly disclosed .NET Framework vulnerability, tracked as CVE-2026-26127. This security flaw allows unauthenticated, remote attackers to trigger a Denial-of-Service (DoS) condition on the network. With a CVSS score of 7.5, Microsoft has classified the vulnerability as “Important.” It…