Category: Microsoft
-
Microsoft: DNS outage impacts Azure and Microsoft 365 services
Microsoft: DNS outage impacts Azure and Microsoft 365 services Microsoft is suffering an ongoing DNS outage affecting customers worldwide, preventing them from logging into company networks and accessing Microsoft Azure and Microsoft 365 services. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5067036 update rolls out Administrator Protection feature
Windows 11 KB5067036 update rolls out Administrator Protection feature Microsoft has released the KB5067036 preview cumulative update for Windows 11 24H2 and 25H2, which begins the rollout of the Administrator Protection cybersecurity feature and an updated Start Menu. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Sued for Allegedly Misleading Millions to Subscribe for Microsoft 365 Subscriptions
Microsoft Sued for Allegedly Misleading Millions to Subscribe for Microsoft 365 Subscriptions Australia’s competition regulator has filed legal proceedings against Microsoft for allegedly misleading approximately 2.7 million Australian consumers regarding subscription options and pricing for Microsoft 365 plans. The Australian Competition and Consumer Commission claims that Microsoft deliberately concealed the availability of cheaper alternative plans…
-
Windows will soon prompt for memory scans after BSOD crashes
Windows will soon prompt for memory scans after BSOD crashes Microsoft has started testing a new feature that prompts Windows 11 users to run a memory scan when logging in after a blue screen of death (BSOD). […] Sergiu Gatlan Go to bleepingcomputer
-
Critical WSUS flaw in Windows Server now exploited in attacks
Critical WSUS flaw in Windows Server now exploited in attacks Attackers are now exploiting a critical-severity Windows Server Update Service (WSUS) vulnerability, which already has publicly available proof-of-concept exploit code. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows Server emergency patches fix WSUS bug with PoC exploit
Windows Server emergency patches fix WSUS bug with PoC exploit Microsoft has released out-of-band (OOB) security updates to patch a critical-severity Windows Server Update Service (WSUS) vulnerability with publicly available proof-of-concept exploit code. […] Sergiu Gatlan Go to bleepingcomputer
-
HP pulls update that broke Microsoft Entra ID auth on some AI PCs
HP pulls update that broke Microsoft Entra ID auth on some AI PCs HP has pulled an HP OneAgent software update for Windows 11 that mistakenly deleted Microsoft certificates required for some organizations to log in to Microsoft Entra ID, effectively disconnecting them from their company’s cloud environments. […] Lawrence Abrams Go to bleepingcomputer
-
Meet the new Clippy: Microsoft unveils Copilot’s “Mico” avatar
Meet the new Clippy: Microsoft unveils Copilot’s “Mico” avatar Today, Microsoft introduced Mico, a new and more personal avatar for the AI-powered Copilot digital assistant, which the company describes as human-centered. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5070773 emergency update fixes Windows Recovery issues
Windows 11 KB5070773 emergency update fixes Windows Recovery issues Microsoft has released an emergency update to fix the Windows Recovery Environment (WinRE), which became unusable on systems with USB mice and keyboards after installing the October 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: October updates break USB input in Windows Recovery
Microsoft: October updates break USB input in Windows Recovery Microsoft has confirmed that this month’s security updates disable USB mice and keyboards in the Windows Recovery Environment (WinRE), making it unusable. […] Sergiu Gatlan Go to bleepingcomputer
-
CISA: High-severity Windows SMB flaw now exploited in attacks
CISA: High-severity Windows SMB flaw now exploited in attacks CISA says threat actors are now actively exploiting a high-severity Windows SMB privilege escalation vulnerability that can let them gain SYSTEM privileges on unpatched systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft lifts more safeguard holds blocking Windows 11 updates
Microsoft lifts more safeguard holds blocking Windows 11 updates Microsoft has removed two more compatibility holds preventing customers from installing Windows 11 24H2 via Windows Update. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes highest-severity ASP.NET Core flaw ever
Microsoft fixes highest-severity ASP.NET Core flaw ever Earlier this week, Microsoft patched a vulnerability that was flagged with the “highest ever” severity rating received by an ASP.NET Core security flaw. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 updates break localhost (127.0.0.1) HTTP/2 connections
Windows 11 updates break localhost (127.0.0.1) HTTP/2 connections Microsoft’s October Windows 11 updates have broken the “localhost” functionality, making applications that connect back to 127.0.0.1 over HTTP/2 no longer function properly. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft disrupts ransomware attacks targeting Teams users
Microsoft disrupts ransomware attacks targeting Teams users Microsoft has disrupted a wave of Rhysida ransomware attacks in early October by revoking over 200 certificates used to sign malicious Teams installers. […] Sergiu Gatlan Go to bleepingcomputer
-
October Patch Tuesday beats January ’25 record
October Patch Tuesday beats January ’25 record Microsoft throws a farewell party for Win10, Office 2016, and Office 2019… a very big party Angela Gunn Go to sophos
-
Final Windows 10 Patch Tuesday update rolls out as support ends
Final Windows 10 Patch Tuesday update rolls out as support ends In what marks the end of an era, Microsoft has released the Windows 10 KB5066791 cumulative update, the final free update for the operating system as it reaches the end of its support lifecycle. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft: Exchange 2016 and 2019 have reached end of support
Microsoft: Exchange 2016 and 2019 have reached end of support Microsoft has reminded that Exchange Server 2016 and 2019 reached the end of support and advised IT administrators to upgrade servers to Exchange Server SE or migrate to Exchange Online. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws Today is Microsoft’s October 2025 Patch Tuesday, which includes security updates for 172 flaws, including six zero-day vulnerabilities. Get patching! […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft IIS Vulnerability Allows Unauthorized Attacker To execute Malicious Code
Microsoft IIS Vulnerability Allows Unauthorized Attacker To execute Malicious Code Microsoft has disclosed a critical remote code execution flaw in its Internet Information Services (IIS) platform, posing risks to organizations relying on Windows servers for web hosting. Tracked as CVE-2025-59282, the vulnerability affects the Inbox COM Objects handling global memory, stemming from a race condition…
-
Microsoft restricts IE mode access in Edge after zero-day attacks
Microsoft restricts IE mode access in Edge after zero-day attacks Microsoft is restricting access to Internet Explorer mode in Edge browser after learning that hackers are leveraging zero-day exploits in the Chakra JavaScript engine for access to target devices. […] Bill Toulas Go to bleepingcomputer
-
Microsoft investigates outage affecting Microsoft 365 apps
Microsoft investigates outage affecting Microsoft 365 apps Microsoft is investigating an ongoing incident that is preventing some customers from accessing Microsoft 365 applications. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 23H2 Home and Pro reach end of support in 30 days
Windows 11 23H2 Home and Pro reach end of support in 30 days Microsoft has reminded customers again today that systems running Home and Pro editions of Windows 11 23H2 will stop receiving security updates next month. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Hackers target universities in “payroll pirate” attacks
Microsoft: Hackers target universities in “payroll pirate” attacks A cybercrime gang tracked as Storm-2657 has been targeting university employees in the United States to hijack salary payments in “pirate payroll” attacks since March 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Defender mistakenly flags SQL Server as end-of-life
Microsoft Defender mistakenly flags SQL Server as end-of-life Microsoft is working to resolve a known issue that causes its Defender for Endpoint enterprise endpoint security platform to incorrectly tag SQL Server software as end-of-life. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft 365 outage blocks access to Teams, Exchange Online
Microsoft 365 outage blocks access to Teams, Exchange Online Microsoft is working to resolve an ongoing outage preventing users from accessing Microsoft 365 services, including Microsoft Teams, Exchange Online, and the admin center. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft enables Exchange Online auto-archiving by default
Microsoft enables Exchange Online auto-archiving by default Microsoft is enabling threshold-based auto-archiving by default in Exchange Online to prevent email flow issues caused by mailboxes filling up faster than expected. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft 365 Outage Blocks Access to Teams, Exchange Online, and Admin Center – Updated
Microsoft 365 Outage Blocks Access to Teams, Exchange Online, and Admin Center – Updated A significant Microsoft 365 outage blocked user access to several critical services, including Microsoft Teams, Exchange Online, and the Microsoft 365 admin center. The incident began late on Wednesday, October 8, 2025, leaving organizations worldwide unable to utilize essential communication and…
-
Microsoft: Critical GoAnywhere bug exploited in ransomware attacks
Microsoft: Critical GoAnywhere bug exploited in ransomware attacks A cybercrime group, tracked as Storm-1175, has been actively exploiting a maximum severity GoAnywhere MFT vulnerability in Medusa ransomware attacks for nearly a month. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Running multiple Office apps causes Copilot issues
Microsoft: Running multiple Office apps causes Copilot issues Microsoft is investigating a bug that causes Copilot issues when multiple Office apps are running simultaneously on the same system. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Outlook stops displaying inline SVG images used in attacks
Microsoft Outlook stops displaying inline SVG images used in attacks Microsoft says Outlook for Web and the new Outlook for Windows will no longer display risky inline SVG images that are being used in attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Defender bug triggers erroneous BIOS update alerts
Microsoft Defender bug triggers erroneous BIOS update alerts Microsoft is working to resolve a bug that causes Defender for Endpoint to incorrectly tag some devices’ BIOS (Basic Input/Output System) firmware as outdated, prompting users to update it. […] Sergiu Gatlan Go to bleepingcomputer
-
New bug in classic Outlook can only be fixed via Microsoft support
New bug in classic Outlook can only be fixed via Microsoft support Microsoft is investigating a known issue that causes the classic Outlook email client to crash upon launch, which can only be resolved via Exchange Online support. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 2025 Update (25H2) is now available, Here’s what’s new
Windows 11 2025 Update (25H2) is now available, Here’s what’s new Today, Microsoft announced the release of Windows 11 25H2, also known as Windows 11 2025 Update. […] Mayank Parmar Go to bleepingcomputer
-
Microsoft’s new AI feature will organize your photos automatically
Microsoft’s new AI feature will organize your photos automatically Microsoft has begun testing a new AI-powered feature in Microsoft Photos, designed to categorize photos automatically on Windows 11 systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft shares temp fix for Outlook encrypted email errors
Microsoft shares temp fix for Outlook encrypted email errors Microsoft is investigating a known issue that triggers Outlook errors when opening encrypted emails sent from other organizations. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Edge to block malicious sideloaded extensions
Microsoft Edge to block malicious sideloaded extensions Microsoft is planning to introduce a new Edge security feature that will protect users against malicious extensions sideloaded into the web browser. […] Sergiu Gatlan Go to bleepingcomputer
-
Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms
Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms U.S. prosecutors last week levied criminal hacking charges against 19-year-old U.K. national Thalha Jubair for allegedly being a core member of Scattered Spider, a prolific cybercrime group blamed for extorting at least $115 million in ransom payments from victims. The charges came as Jubair and an…
-
Microsoft lifts Windows 11 update block after face detection fix
Microsoft lifts Windows 11 update block after face detection fix Microsoft has removed a compatibility hold that prevented devices with integrated cameras from installing Windows 11 24H2 due to a face detection bug causing app freezes. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft starts rolling out Gaming Copilot on Windows 11 PCs
Microsoft starts rolling out Gaming Copilot on Windows 11 PCs Microsoft has begun rolling out the beta version of its AI-powered Gaming Copilot to Windows 11 systems for users aged 18 or older, excluding those in mainland China. […] Sergiu Gatlan Go to bleepingcomputer
-
Notepad gets free AI features on Copilot+ PCs with Windows 11
Notepad gets free AI features on Copilot+ PCs with Windows 11 Microsoft is adding free AI-powered text writing capabilities to Notepad for customers with Copilot+ PCs running Windows 11. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft rolls out Copilot Chat to Microsoft 365 Office apps
Microsoft rolls out Copilot Chat to Microsoft 365 Office apps Microsoft is rolling out Copilot Chat to Word, Excel, PowerPoint, Outlook, and OneNote for paying Microsoft 365 business customers. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: WMIC will be removed after Windows 11 25H2 upgrade
Microsoft: WMIC will be removed after Windows 11 25H2 upgrade Microsoft has announced that the Windows Management Instrumentation Command-line (WMIC) tool will be removed after upgrading to Windows 11 25H2 and later. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Still Uses RC4
Microsoft Still Uses RC4 Senator Ron Wyden has asked the Federal Trade Commission to investigate Microsoft over its continued use of the RC4 encryption algorithm. The letter talks about a hacker technique called Kerberoasting, that exploits the Kerberos authentication system. Bruce Schneier Go to bruce schneier
-
Microsoft: Exchange 2016 and 2019 reach end of support in 30 days
Microsoft: Exchange 2016 and 2019 reach end of support in 30 days Microsoft has reminded administrators again that Exchange 2016 and Exchange 2019 will reach the end of extended support next month and has provided guidance for decommissioning outdated servers. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft reminds of Windows 10 support ending in 30 days
Microsoft reminds of Windows 10 support ending in 30 days On Friday, Microsoft reminded customers once again that Windows 10 will reach its end of support in 30 days, on October 14. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 23H2 Home and Pro reach end of support in 60 days
Windows 11 23H2 Home and Pro reach end of support in 60 days Microsoft has reminded customers today that devices running Home and Pro editions of Windows 11 23H2 will stop receiving updates in November. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes Exchange Online outage affecting users worldwide
Microsoft fixes Exchange Online outage affecting users worldwide Microsoft says that it has mitigated an Exchange Online outage affecting customers worldwide, which blocked their access to emails and calendars. […] Sergiu Gatlan Go to bleepingcomputer
-
U.S. Senator accuses Microsoft of “gross cybersecurity negligence”
U.S. Senator accuses Microsoft of “gross cybersecurity negligence” U.S. Senator Ron Wyden has sent a letter to the Federal Trade Commission (FTC) requesting the agency to investigate Microsoft for failing to provide adequate security in its products, which led to ransomware attacks against healthcare organizations. […] Bill Toulas Go to bleepingcomputer
-
Microsoft To Depreciate VBScript In Windows Warns Developers To Adapt Their Projects
Microsoft To Depreciate VBScript In Windows Warns Developers To Adapt Their Projects Microsoft has officially announced a multi-phase plan to deprecate VBScript in Windows, a move that signals a significant shift for developers, particularly those working with Visual Basic for Applications (VBA). The change, first detailed in May 2024, will gradually phase out the legacy…
-
Microsoft waives fees for Windows devs publishing to Microsoft Store
Microsoft waives fees for Windows devs publishing to Microsoft Store Microsoft announced that, starting today, individual Windows developers will no longer have to pay for publishing their applications on the Microsoft Store. […] Sergiu Gatlan Go to bleepingcomputer
-
September Patch Tuesday handles 81 CVEs
September Patch Tuesday handles 81 CVEs The last round of fixes before Win 10’s final shout touches 15 product families, including Xbox Angela Gunn Go to sophos
-
Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days
Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days Today is Microsoft’s September 2025 Patch Tuesday, which includes security updates for 81 flaws, including two publicly disclosed zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5065426 & KB5065431 cumulative updates released
Windows 11 KB5065426 & KB5065431 cumulative updates released Microsoft has released Windows 11 KB5065426 and KB5065431 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues. […] Mayank Parmar Go to bleepingcomputer
-
Critical Microsoft Office Vulnerabilities Let Attackers Execute Malicious Code
Critical Microsoft Office Vulnerabilities Let Attackers Execute Malicious Code Microsoft has released patches for two significant vulnerabilities in Microsoft Office that could allow attackers to execute malicious code on affected systems. The flaws, tracked as CVE-2025-54910 and CVE-2025-54906, were disclosed on September 9, 2025, and affect various versions of the popular productivity suite. While Microsoft…
-
Microsoft Patch Tuesday, September 2025 Edition
Microsoft Patch Tuesday, September 2025 Edition Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known “zero-day” or actively exploited vulnerabilities in this month’s bundle from Redmond, which nevertheless includes patches for 13 flaws that earned Microsoft’s most-dire “critical” label. Meanwhile, both…
-
Microsoft now enforces MFA on Azure Portal sign-ins for all tenants
Microsoft now enforces MFA on Azure Portal sign-ins for all tenants Microsoft says it has been enforcing multifactor authentication (MFA) for Azure Portal sign-ins across all tenants since March 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft gives US students a free year of Microsoft 365 Personal
Microsoft gives US students a free year of Microsoft 365 Personal Microsoft announced that starting this Thursday, all college students in the United States can get a free year of Microsoft 365 Personal. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5064081 update clears up CPU usage metrics in Task Manager
Windows 11 KB5064081 update clears up CPU usage metrics in Task Manager Microsoft has released the KB5064081 preview cumulative update for Windows 11 24H2, which includes thirty-six new features or changes, with many gradually rolling out. These updates include new Recall features and a new way of displaying CPU usage in Task Manager. […] Lawrence…
-
Microsoft fixes bug behind Windows certificate enrollment errors
Microsoft fixes bug behind Windows certificate enrollment errors Microsoft has resolved a known issue causing false CertificateServicesClient (CertEnroll) error messages after installing the July 2025 preview and subsequent Windows 11 24H2 updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft to enforce MFA for Azure resource management in October
Microsoft to enforce MFA for Azure resource management in October Starting in October, Microsoft will enforce multi-factor authentication (MFA) for all Azure resource management actions to protect Azure clients from unauthorized access attempts. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft says recent Windows update didn’t kill your SSD
Microsoft says recent Windows update didn’t kill your SSD Microsoft has found no link between the August 2025 KB5063878 security update and customer reports of failure and data corruption issues affecting solid-state drives (SSDs) and hard disk drives (HDDs). […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Word will save your files to the cloud by default
Microsoft Word will save your files to the cloud by default Microsoft says that Word for Windows will soon enable autosave and automatically save all new documents to the cloud by default. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Attack Tactics
Microsoft Unveils Storm-0501’s Advanced Cloud Ransomware Attack Tactics Microsoft Threat Intelligence has released a detailed report exposing a significant evolution in ransomware attacks, pioneered by the financially motivated threat actor Storm-0501. The group has shifted from traditional on-premises ransomware to a more destructive, cloud-native strategy that involves data exfiltration and destruction, fundamentally changing the nature…
-
Smashing Security podcast #432: Oops! I auto-filled my password into a cookie banner
Smashing Security podcast #432: Oops! I auto-filled my password into a cookie banner We unpack how some password managers can be tricked into coughing up your secrets, with a clickjacking sleight-of-hand, what website owners can do to prevent it, and how to lock down your personal password vault. Then we time-hope to the post-quantum scramble:…
-
Microsoft: August Windows updates cause severe streaming issues
Microsoft: August Windows updates cause severe streaming issues Microsoft has confirmed that the August 2025 security updates are causing severe lag and stuttering issues with NDI streaming software on some Windows 10 and Windows 11 systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft asks customers for feedback on reported SSD failures
Microsoft asks customers for feedback on reported SSD failures Microsoft is seeking further information from customers who reported failure and data corruption issues affecting their solid-state drives (SSDs) and hard disk drives (HDDs) after installing the August 2025 security update. […] Sergiu Gatlan Go to bleepingcomputer
-
Smashing Security podcast #431: How to mine millions without paying the bill
Smashing Security podcast #431: How to mine millions without paying the bill In episode 431 of the “Smashing Security” podcast, a self-proclaimed crypto-influencer calling himself CP3O thought he had found a shortcut to riches — by racking up millions in unpaid cloud bills. Meanwhile, we look at the growing threat of EDR-killer tools that can…
-
Microsoft fixes Windows upgrades failing with 0x8007007F error
Microsoft fixes Windows upgrades failing with 0x8007007F error Microsoft has resolved a known issue that caused Windows upgrades to fail with 0x8007007F errors on some Windows 11 and Windows Server systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft releases emergency updates to fix Windows recovery
Microsoft releases emergency updates to fix Windows recovery Microsoft has released emergency Windows out-of-band updates to resolve a known issue breaking reset and recovery operations after installing the August 2025 Windows security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft shares workaround for Teams “couldn’t connect” error
Microsoft shares workaround for Teams “couldn’t connect” error Microsoft is resolving a known issue that causes “couldn’t connect” errors when launching the Microsoft Teams desktop and web applications. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Teams to protect against malicious URLs, dangerous file types
Microsoft Teams to protect against malicious URLs, dangerous file types Microsoft recently revealed that it’s currently enhancing protection against dangerous file types and malicious URLs in Teams chats and channels. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft reminds of Windows 10 support ending in two months
Microsoft reminds of Windows 10 support ending in two months Microsoft has reminded customers that Windows 10 will be retired in two months after all editions of Windows 10, version 22H2 reach their end of servicing on October 14. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes Windows Server bug causing cluster, VM issues
Microsoft fixes Windows Server bug causing cluster, VM issues Microsoft has resolved a known issue that triggers Cluster service and VM restart issues after installing July’s Windows Server 2019 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes Windows 11 24H2 updates failing with 0x80240069 error
Microsoft fixes Windows 11 24H2 updates failing with 0x80240069 error Microsoft has resolved a known issue preventing the August 2025 Windows 11 24H2 cumulative update from being delivered via Windows Server Update Services (WSUS). […] Sergiu Gatlan Go to bleepingcomputer
-
August Patch Tuesday includes blasts from the (recent) past
August Patch Tuesday includes blasts from the (recent) past Microsoft haul this month covers 109 CVEs… more or less Angela Gunn Go to sophos
-
Microsoft tests cloud-based Windows 365 disaster recovery PCs
Microsoft tests cloud-based Windows 365 disaster recovery PCs Microsoft has announced the limited public preview of Windows 365 Reserve, a service that provides temporary desktop access to pre-configured cloud PCs for employees whose computers have become unavailable due to cyberattacks, hardware issues, or software problems. […] Sergiu Gatlan Go to bleepingcomputer
-
Over 29,000 Exchange servers unpatched against high-severity flaw
Over 29,000 Exchange servers unpatched against high-severity flaw Over 29,000 Exchange servers exposed online remain unpatched against a high-severity vulnerability that can let attackers move laterally in Microsoft cloud environments, potentially leading to complete domain compromise. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft 365 apps to soon block file access via FPRPC by default
Microsoft 365 apps to soon block file access via FPRPC by default Microsoft has announced that the Microsoft 365 apps for Windows will start blocking access to files via the insecure FPRPC legacy authentication protocol by default starting late August. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft will kill the Lens PDF scanner app for iOS, Android
Microsoft will kill the Lens PDF scanner app for iOS, Android Microsoft announced that it will phase out the Microsoft Lens PDF scanner app for Android and iOS devices starting September 15, 2025. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft warns of high-severity flaw in hybrid Exchange deployments
Microsoft warns of high-severity flaw in hybrid Exchange deployments Microsoft has warned customers to mitigate a high-severity vulnerability in Exchange Server hybrid deployments that could allow attackers to escalate privileges in Exchange Online cloud environments undetected. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft pays record $17 million in bounties over the last 12 months
Microsoft pays record $17 million in bounties over the last 12 months Microsoft paid a record $17 million this year to 344 security researchers across 59 countries through its bug bounty program. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft increases Zero Day Quest prize pool to $5 million
Microsoft increases Zero Day Quest prize pool to $5 million Microsoft will offer up to $5 million in bounty awards at this year’s Zero Day Quest hacking contest, which the company describes as the “largest hacking event in history.” […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Outdated Office apps lose access to voice features in January
Microsoft: Outdated Office apps lose access to voice features in January Microsoft announced that the transcription, dictation, and read aloud features will stop working in older versions of Office 365 applications in late January 2026. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft to disable Excel workbook links to blocked file types
Microsoft to disable Excel workbook links to blocked file types Microsoft has announced that it will start disabling external workbook links to blocked file types by default between October 2025 and July 2026. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft now pays up to $40,000 for some .NET vulnerabilities
Microsoft now pays up to $40,000 for some .NET vulnerabilities Microsoft has expanded its .NET bug bounty program and increased rewards to $40,000 for some .NET and ASP.NET Core vulnerabilities. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Edge now an ‘AI-powered browser’ with Copilot Mode
Microsoft Edge now an ‘AI-powered browser’ with Copilot Mode Microsoft has introduced Copilot Mode, an experimental feature designed to transform Microsoft Edge into a web browser powered by artificial intelligence (AI). […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data
Microsoft: macOS Sploitlight flaw leaks Apple Intelligence data Attackers could use a recently patched macOS vulnerability to bypass Transparency, Consent, and Control (TCC) security checks and steal sensitive user information, including Apple Intelligence cached data. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft SharePoint Zero-Day
Microsoft SharePoint Zero-Day Chinese hackers are exploiting a high-severity vulnerability in Microsoft SharePoint to steal data worldwide: The vulnerability, tracked as CVE-2025-53770, carries a severity rating of 9.8 out of a possible 10. It gives unauthenticated remote access to SharePoint Servers exposed to the Internet. Starting Friday, researchers began warning of active exploitation of the…
-
Microsoft investigates outage affecting Microsoft 365 admin center
Microsoft investigates outage affecting Microsoft 365 admin center Microsoft is investigating an ongoing outage blocking Microsoft 365 administrators with business or enterprise subscriptions from accessing the admin center. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: SharePoint servers also targeted in ransomware attacks
Microsoft: SharePoint servers also targeted in ransomware attacks A Chinese hacking group is deploying Warlock ransomware on Microsoft SharePoint servers vulnerable to widespread attacks targeting the recently patched ToolShell zero-day exploit chain. […] Sergiu Gatlan Go to bleepingcomputer
-
Brave blocks Windows Recall from screenshotting your browsing activity
Brave blocks Windows Recall from screenshotting your browsing activity Brave Software says its privacy-focused browser will block Microsoft’s Windows Recall from capturing screenshots of Brave windows by default to protect users’ privacy. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5062660 update brings new ‘Windows Resilience’ features
Windows 11 KB5062660 update brings new ‘Windows Resilience’ features Microsoft has released the KB5062660 preview cumulative update for Windows 11 24H2 with twenty-nine new features or changes, with many gradually rolling out, such as the new Black Screen of Death and Quick Machine Recovery tool. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 gets new Black Screen of Death, auto recovery tool
Windows 11 gets new Black Screen of Death, auto recovery tool Microsoft is rolling out significant changes to Windows 11 24H2 as part of the Windows Resilience Initiative, designed to reduce downtime and help devices recover from serious failures, as well as an overhaul of the all-too-familiar BSOD crash screens. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day
Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day Thousands of organizations worldwide face active cyberattacks targeting Microsoft SharePoint servers through two critical vulnerabilities, prompting urgent government warnings and emergency patches. Microsoft confirmed over the weekend that threat actors are actively exploiting two zero-day vulnerabilities in on-premises SharePoint servers, designated CVE-2025-53770 and CVE-2025-53771. The…
-
Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks
Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 that have compromised services worldwide in “ToolShell” attacks. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available
Microsoft SharePoint zero-day exploited in RCE attacks, no patch available Critical zero-day vulnerabilities in Microsoft SharePoint, tracked as CVE-2025-53770 and CVE-2025-53771, have been actively exploited since at least July 18th, with no patch available and at least 85 servers already compromised worldwide. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability
Microsoft Released Emergency Security Update to Patch Critical SharePoint 0-Day Vulnerability Microsoft has issued an urgent security advisory addressing critical zero-day vulnerabilities in on-premises SharePoint Server that attackers are actively exploiting. The vulnerabilities, assigned as CVE-2025-53770 and CVE-2025-53771, pose immediate risks to organizations running SharePoint infrastructure and require immediate remediation. Key Takeaways1. Active zero-day attacks…
-
Microsoft mistakenly tags Windows Firewall error log bug as fixed
Microsoft mistakenly tags Windows Firewall error log bug as fixed Microsoft has mistakenly tagged an ongoing Windows Firewall error message bug as fixed in recent updates, stating that they are still working on a resolution. […] Lawrence Abrams Go to bleepingcomputer