Category: Microsoft
-
Microsoft: June Windows Server security updates cause DHCP issues
Microsoft: June Windows Server security updates cause DHCP issues Microsoft acknowledged a new issue caused by the June 2025 security updates, causing the DHCP service to freeze on some Windows Server systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 users want these five features back
Windows 11 users want these five features back When Windows 11 was first released, many long-time users felt features they loved had been taken away overnight. Three and a half years later, the same complaints still rise to the top of the Feedback Hub with tens of thousands of votes. […] Mayank Parmar Go to…
-
Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices
Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices Microsoft is investigating a known issue that triggers Secure Boot errors and prevents Surface Hub v1 devices from starting up. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft confirms auth issues affecting Microsoft 365 users
Microsoft confirms auth issues affecting Microsoft 365 users Microsoft is investigating an ongoing incident that is causing users to experience errors with some Microsoft 365 authentication features. […] Sergiu Gatlan Go to bleepingcomputer
-
June Patch Tuesday digs into 67 bugs
June Patch Tuesday digs into 67 bugs An extremely Windows-heavy month, with a surprise cameo by… Sophos?! Angela Gunn Go to sophos
-
Why Denmark is breaking up with Microsoft
Why Denmark is breaking up with Microsoft Relying too heavily on a US tech giant for your nation’s digital infrastructure is starting to feel a bit… well, risky. Graham Cluley Go to grahamcluley
-
Password-spraying attacks target 80,000 Microsoft Entra ID accounts
Password-spraying attacks target 80,000 Microsoft Entra ID accounts Hackers have been using the TeamFiltration pentesting framework to target more than 80,000 Microsoft Entra ID accounts at hundreds of organizations worldwide. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Edge now offers secure password deployment for businesses
Microsoft Edge now offers secure password deployment for businesses Microsoft announced that a new Edge feature allowing employees to share passwords more securely in enterprise environments has reached general availability. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 10 KB5060533 cumulative update released with 7 changes, fixes
Windows 10 KB5060533 cumulative update released with 7 changes, fixes Microsoft has released the KB5060533 cumulative update for Windows 10 22H2 and Windows 10 21H2, with seven fixes or changes, including bringing seconds back to the time shown in the Calendar flyout. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws Today is Microsoft’s June 2025 Patch Tuesday, which includes security updates for 66 flaws, including one actively exploited vulnerability and another that was publicly disclosed. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft shares script to restore inetpub folder you shouldn’t delete
Microsoft shares script to restore inetpub folder you shouldn’t delete Microsoft has released a PowerShell script to help restore an empty ‘inetpub’ folder created by the April 2025 Windows security updates if deleted. As Microsoft previously warned, this folder helps mitigate a high-severity Windows Process Activation privilege escalation vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Proxy Services Feast on Ukraine’s IP Address Exodus
Proxy Services Feast on Ukraine’s IP Address Exodus Image: Mark Rademaker, via Shutterstock. Ukraine has seen nearly one-fifth of its Internet space come under Russian control or sold to Internet address brokers since February 2022, a new study finds. The analysis indicates large chunks of Ukrainian Internet address space are now in the hands of…
-
Microsoft unveils free EU cybersecurity program for governments
Microsoft unveils free EU cybersecurity program for governments Microsoft announced in Berlin today a new European Security Program that promises to bolster cybersecurity for European governments. […] Bill Toulas Go to bleepingcomputer
-
Microsoft adds quick machine recovery to Windows 11 settings
Microsoft adds quick machine recovery to Windows 11 settings Microsoft is testing a dedicated page in Windows Settings for quick machine recovery, which will provide users with additional configuration options. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft and CrowdStrike partner to link hacking group names
Microsoft and CrowdStrike partner to link hacking group names Microsoft and CrowdStrike announced today that they’ve partnered to connect the aliases used for specific threat groups without actually using a single naming standard. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft now testing Notepad text formatting in Windows 11
Microsoft now testing Notepad text formatting in Windows 11 Microsoft announced today that the Windows 11 Notepad application is getting a text formatting feature supporting Markdown-style input. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Authenticator now warns to export passwords before July cutoff
Microsoft Authenticator now warns to export passwords before July cutoff The Microsoft Authenticator app is now issuing notifications warning that the password autofill feature is being deprecated in July, suggesting users move to Microsoft Edge instead. […] Lawrence Abrams Go to bleepingcomputer
-
U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams
U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams Image: Shutterstock, ArtHead. The U.S. government today imposed economic sanctions on Funnull Technology Inc., a Philippines-based company that provides computer infrastructure for hundreds of thousands of websites involved in virtual currency investment scams known as “pig butchering.” In January 2025, KrebsOnSecurity detailed how…
-
Microsoft: Windows 11 might fail to start after installing KB5058405
Microsoft: Windows 11 might fail to start after installing KB5058405 Microsoft has confirmed that some Windows 11 systems might fail to start after installing the KB5058405 security update released during this month’s Patch Tuesday. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 10 KB5058481 update brings seconds back to calendar flyout
Windows 10 KB5058481 update brings seconds back to calendar flyout Microsoft has released the optional KB5058481 preview cumulative update for Windows 10 22H2 with seven changes, including restoring seconds to the time display in the calendar flyout for those who previously lost it. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5058499 update rolls out new Share and Click to Do features
Windows 11 KB5058499 update rolls out new Share and Click to Do features Microsoft has released the KB5058499 preview cumulative update for Windows 11 24H2 with forty-eight new features or changes, with many gradually rolling out, such as the new Windows Share feature and tje Click to Do Preview. […] Lawrence Abrams Go to bleepingcomputer
-
Russian Laundry Bear cyberspies linked to Dutch Police hack
Russian Laundry Bear cyberspies linked to Dutch Police hack A previously unknown Russian-backed cyberespionage group now tracked as Laundry Bear has been linked to a September 2024 Dutch police security breach. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows Server emergency update fixes Hyper-V VM freezes, restart issues
Windows Server emergency update fixes Hyper-V VM freezes, restart issues Microsoft has released an emergency update to address a known issue causing some Hyper-V virtual machines with Windows Server 2022 to freeze or restart unexpectedly. […] Sergiu Gatlan Go to bleepingcomputer
-
Signal Blocks Windows Recall
Signal Blocks Windows Recall This article gives a good rundown of the security risks of Windows Recall, and the repurposed copyright protection took that Signal used to block the AI feature from scraping Signal data. Bruce Schneier Go to bruce schneier
-
Windows 11 Notepad gets AI-powered text writing capabilities
Windows 11 Notepad gets AI-powered text writing capabilities Microsoft is testing a new AI-powered text generation feature in Notepad that can let Windows Insiders create content based on custom prompts. […] Sergiu Gatlan Go to bleepingcomputer
-
Oops: DanaBot Malware Devs Infected Their Own PCs
Oops: DanaBot Malware Devs Infected Their Own PCs The U.S. government today unsealed criminal charges against 16 individuals accused of operating and selling DanaBot, a prolific strain of information-stealing malware that has been sold on Russian cybercrime forums since 2018. The FBI says a newer version of DanaBot was used for espionage, and that many…
-
Windows 10 emergency updates fix BitLocker recovery issues
Windows 10 emergency updates fix BitLocker recovery issues Microsoft has released out-of-band updates to fix a known issue causing Windows 10 systems to boot into BitLocker recovery after installing the May 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Releases Emergency Fix for BitLocker Recovery Issue
Microsoft Releases Emergency Fix for BitLocker Recovery Issue Microsoft has released an emergency out-of-band update (KB5061768) to address a critical issue causing Windows 10 systems to boot into BitLocker recovery screens following the installation of the May 2025 security updates. The fix, released on May 19, comes after numerous reports from enterprise customers experiencing system…
-
Abusing dMSA with Advanced Active Directory Persistence Techniques
Abusing dMSA with Advanced Active Directory Persistence Techniques Delegated Managed Service Accounts (dMSAs), introduced in Windows Server 2025, represent Microsoft’s latest innovation in secure service account management. While designed to enhance security by preventing traditional credential theft attacks like Kerberoasting, security researchers have uncovered potential abuse vectors that could allow attackers to establish persistent access…
-
New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender
New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender A new tool called ‘Defendnot’ can disable Microsoft Defender on Windows devices by registering a fake antivirus product, even when no real AV is installed. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft confirms May Windows 10 updates trigger BitLocker recovery
Microsoft confirms May Windows 10 updates trigger BitLocker recovery Microsoft has confirmed that some Windows 10 and Windows 10 Enterprise LTSC 2021 systems will boot into BitLocker recovery after installing the May 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 10 KB5058379 update triggers BitLocker recovery on some devices
Windows 10 KB5058379 update triggers BitLocker recovery on some devices The Windows 10 KB5058379 cumulative update is triggering unexpected BitLocker recovery prompts on some devices afters it’s installed and the computer restarted. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft primes 71 fixes for May Patch Tuesday
Microsoft primes 71 fixes for May Patch Tuesday Five issues actively exploited in the wild, but the real excitement may have been handled in advance Angela Gunn Go to sophos
-
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws Today is Microsoft’s May 2025 Patch Tuesday, which includes security updates for 72 flaws, including five actively exploited and two publicly disclosed zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network
Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network Microsoft has issued a security advisory regarding a new vulnerability in Active Directory Certificate Services (AD CS) that could allow attackers to perform denial-of-service attacks over a network. The vulnerability, identified as CVE-2025-29968, affects multiple versions of Windows Server and has been…
-
Microsoft Defender Vulnerability Allows Attackers to Elevate Privileges
Microsoft Defender Vulnerability Allows Attackers to Elevate Privileges A newly disclosed security flaw in Microsoft Defender for Endpoint could allow attackers with local access to elevate their privileges to SYSTEM level, potentially gaining complete control over affected systems. The vulnerability, tracked as CVE-2025-26684, was patched as part of Microsoft’s May 2025 Patch Tuesday security updates…
-
Windows 11 upgrade block lifted after Safe Exam Browser fix
Windows 11 upgrade block lifted after Safe Exam Browser fix Microsoft has removed an upgrade block that prevented some Safe Exam Browser users from installing the Windows 11 2024 Update due to incompatibility issues. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Teams will soon block screen capture during meetings
Microsoft Teams will soon block screen capture during meetings Microsoft is working on adding a new Teams feature that will prevent users from capturing screenshots of sensitive information shared during meetings. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Teams To Block Screen Capture During Meetings
Microsoft Teams To Block Screen Capture During Meetings Microsoft has announced a new “Prevent Screen Capture” feature for Teams that will block unauthorized screenshots during meetings. The feature, scheduled for worldwide rollout in July 2025, represents Microsoft’s continued focus on enterprise security and regulatory compliance in an era where sensitive information is increasingly shared in…
-
Play ransomware exploited Windows logging flaw in zero-day attacks
Play ransomware exploited Windows logging flaw in zero-day attacks The Play ransomware gang has exploited a high-severity Windows Common Log File System flaw in zero-day attacks to gain SYSTEM privileges and deploy malware on compromised systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: April updates cause Windows Server auth issues
Microsoft: April updates cause Windows Server auth issues Microsoft says the April 2025 security updates are causing authentication issues on some Windows Server 2025 domain controllers. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft pushes fix for Windows 11 update 0x80240069 errors
Microsoft pushes fix for Windows 11 update 0x80240069 errors Microsoft has fixed a known issue preventing Windows 11 24H2 feature updates from being delivered via Windows Server Update Services (WSUS) after installing the April 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft ends Authenticator password autofill, moves users to Edge
Microsoft ends Authenticator password autofill, moves users to Edge Microsoft has announced that it will discontinue the password storage and autofill feature in the Authenticator app starting in July and will complete the deprecation in August 2025. […] Bill Toulas Go to bleepingcomputer
-
Microsoft makes all new accounts passwordless by default
Microsoft makes all new accounts passwordless by default Microsoft has announced that all new Microsoft accounts will be “passwordless by default” to secure them against password attacks such as phishing, brute force, and credential stuffing. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Windows Server hotpatching to require subscription
Microsoft: Windows Server hotpatching to require subscription Microsoft has announced it will require paid subscriptions for Windows Server 2025 hotpatching, a service that enables admins to install security updates without restarting. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11’s Recall AI is now rolling out on Copilot+ PCs
Windows 11’s Recall AI is now rolling out on Copilot+ PCs Microsoft has confirmed that Windows Recall is rolling out to everyone with Windows 11 KB5055627 on Copilot+ PCs. […] Mayank Parmar Go to bleepingcomputer
-
Windows 11 KB5055627 update released with 30 new changes, fixes
Windows 11 KB5055627 update released with 30 new changes, fixes Microsoft has released the KB5055627 preview cumulative update for Windows 11 24H2 with many new features gradually rolling out, and some new bug fixes for everyone. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft announces fix for CPU spikes when typing in Outlook
Microsoft announces fix for CPU spikes when typing in Outlook Microsoft says it will soon fix a known issue causing CPU spikes when typing messages in recent versions of its classic Outlook email client. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes machine learning bug flagging Adobe emails as spam
Microsoft fixes machine learning bug flagging Adobe emails as spam Microsoft says it mitigated a known issue in one of its machine learning (ML) models that mistakenly flagged Adobe emails in Exchange Online as spam. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft’s Symlink Patch Created New Windows DoS Vulnerability
Microsoft’s Symlink Patch Created New Windows DoS Vulnerability A recent Microsoft security update, intended to patch a critical privilege escalation vulnerability, has inadvertently introduced a new and significant flaw. The fix now enables non-administrative users to effectively block all future Windows security updates, creating a denial-of-service condition. This unintended consequence of the patch highlights the…
-
Microsoft fixes Remote Desktop freezes caused by Windows updates
Microsoft fixes Remote Desktop freezes caused by Windows updates Microsoft has resolved a known issue causing Remote Desktop sessions to freeze on Windows Server 2025 and Windows 11 24H2 devices. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes Windows Server 2025 blue screen, install issues
Microsoft fixes Windows Server 2025 blue screen, install issues Microsoft has fixed several known issues that caused Blue Screen of Death (BSOD) and installation issues on Windows Server 2025 systems with a high core count. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Entra account lockouts caused by user token logging mishap
Microsoft Entra account lockouts caused by user token logging mishap Microsoft confirms that the weekend Entra account lockouts were caused by the invalidation of short-lived user refresh tokens that were mistakenly logged into internal systems. […] Lawrence Abrams Go to bleepingcomputer
-
Widespread Microsoft Entra lockouts tied to new security feature rollout
Widespread Microsoft Entra lockouts tied to new security feature rollout Windows administrators from numerous organizations report widespread account lockouts triggered by false positives in the rollout of a new Microsoft Entra ID’s “leaked credentials” detection app called MACE. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Defender will isolate undiscovered endpoints to block attacks
Microsoft Defender will isolate undiscovered endpoints to block attacks Microsoft is testing a new Defender for Endpoint capability that will block traffic to and from undiscovered endpoints to thwart attackers’ lateral network movement attempts. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft starts final Windows Recall testing before rollout
Microsoft starts final Windows Recall testing before rollout Microsoft is gradually rolling out the AI-powered Windows Recall feature to Insiders in the Release Preview channel before making it generally available to all Windows users with Copilot+ PCs. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Windows ‘inetpub’ folder created by security fix, don’t delete
Microsoft: Windows ‘inetpub’ folder created by security fix, don’t delete Microsoft has now confirmed that an April 2025 Windows security update is creating a new empty “inetpub” folder and warned users not to delete it. […] Sergiu Gatlan Go to bleepingcomputer
-
AI Vulnerability Finding
AI Vulnerability Finding Microsoft is reporting that its AI systems are able to find new vulnerabilities in source code: Microsoft discovered eleven vulnerabilities in GRUB2, including integer and buffer overflows in filesystem parsers, command flaws, and a side-channel in cryptographic comparison. Additionally, 9 buffer overflows in parsing SquashFS, EXT4, CramFS, JFFS2, and symlinks were discovered…
-
Microsoft releases emergency update to fix Office 2016 crashes
Microsoft releases emergency update to fix Office 2016 crashes Microsoft has released an out-of-band Office update to fix a known issue that caused Word, Excel, and Outlook to crash after installing the KB5002700 security update for Office 2016. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Licensing issue blocks Microsoft 365 Family for some users
Microsoft: Licensing issue blocks Microsoft 365 Family for some users Microsoft is investigating a potential licensing issue blocking access to Microsoft 365 services for some customers with Family subscriptions. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 tests sharing apps screen and files with Copilot AI
Windows 11 tests sharing apps screen and files with Copilot AI Copilot on Windows 11 is testing OS-level integration that would allow you to share your favourite apps’ screen with Copilot. […] Mayank Parmar Go to bleepingcomputer
-
Industrial-strength April Patch Tuesday covers 135 CVEs
Industrial-strength April Patch Tuesday covers 135 CVEs One actively exploited issue patched; five Critical-severity Office vulns exploitable via Preview Pane Angela Gunn Go to sophos
-
Patch Tuesday, April 2025 Edition
Patch Tuesday, April 2025 Edition Microsoft today released updates to plug at least 121 security holes in its Windows operating systems and software, including one vulnerability that is already being exploited in the wild. Eleven of those flaws earned Microsoft’s most-dire “critical” rating, meaning malware or malcontents could exploit them with little to no interaction…
-
Microsoft fixes auth issues on Windows Server, Windows 11 24H2
Microsoft fixes auth issues on Windows Server, Windows 11 24H2 Microsoft has fixed a known issue causing authentication problems when Credential Guard is enabled on systems using the Kerberos PKINIT pre-auth security protocol. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Windows CLFS zero-day exploited by ransomware gang
Microsoft: Windows CLFS zero-day exploited by ransomware gang Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw in the Windows Common Log File System to gain SYSTEM privileges on victims’ systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws
Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws Today is Microsoft’s April 2025 Patch Tuesday, which includes security updates for 134 flaws, including one actively exploited zero-day vulnerability. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 10 KB5055518 update fixes random text when printing
Windows 10 KB5055518 update fixes random text when printing Microsoft has released the KB5055518 cumulative update for Windows 10 22H2 and Windows 10 21H2, with nine changes or fixes. […] Lawrence Abrams Go to bleepingcomputer
-
EncryptHub’s dual life: Cybercriminal vs Windows bug-bounty researcher
EncryptHub’s dual life: Cybercriminal vs Windows bug-bounty researcher EncryptHub, a notorious threat actor linked to breaches at 618 organizations, is believed to have reported two Windows zero-day vulnerabilities to Microsoft, revealing a conflicted figure straddling the line between cybercrime and security research. […] Bill Toulas Go to bleepingcomputer
-
Microsoft delays WSUS driver sync deprecation indefinitely
Microsoft delays WSUS driver sync deprecation indefinitely Microsoft announced today that, based on customer feedback, it will indefinitely delay removing driver synchronization in Windows Server Update Services (WSUS). […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Celebrates 50th Anniversary!
Microsoft Celebrates 50th Anniversary! Microsoft celebrated its 50th anniversary on April 4, 2025, reflecting on its journey since Bill Gates and Paul Allen founded the company in 1975. The milestone event, held at Microsoft’s Redmond, Washington headquarters, blended nostalgia with cutting-edge AI advancements, particularly through its Copilot platform, while highlighting the transformative role of technology…
-
Microsoft starts testing Windows 11 taskbar icon scaling
Microsoft starts testing Windows 11 taskbar icon scaling Microsoft is testing a new taskbar icon scaling feature that automatically scales down Windows taskbar icons to show more apps when it gets too overcrowded. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft adds hotpatching support to Windows 11 Enterprise
Microsoft adds hotpatching support to Windows 11 Enterprise Microsoft has announced that hotpatch updates are now available for business customers using Windows 11 Enterprise 24H2 on x64 (AMD/Intel) systems, starting today. […] Sergiu Gatlan Go to bleepingcomputer
-
New Windows 11 trick lets you bypass Microsoft Account requirement
New Windows 11 trick lets you bypass Microsoft Account requirement A previously unknown trick lets you easily bypass using a Microsoft Account in Windows 11, just as Microsoft tries to make it harder to use local accounts. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft uses AI to find flaws in GRUB2, U-Boot, Barebox bootloaders
Microsoft uses AI to find flaws in GRUB2, U-Boot, Barebox bootloaders Microsoft used its AI-powered Security Copilot to discover 20 previously unknown vulnerabilities in the GRUB2, U-Boot, and Barebox open-source bootloaders. […] Bill Toulas Go to bleepingcomputer
-
Microsoft tests new Windows 11 tool to remotely fix boot crashes
Microsoft tests new Windows 11 tool to remotely fix boot crashes Microsoft has begun testing a new Windows 11 tool called Quick Machine Recovery, which is designed to remotely deploy fixes for buggy drivers and configurations that prevent the operating system from starting. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft’s killing script used to avoid Microsoft Account in Windows 11
Microsoft’s killing script used to avoid Microsoft Account in Windows 11 Microsoft has removed the ‘BypassNRO.cmd’ script from Windows 11 preview builds, which allowed users to bypass the requirement to use a Microsoft Account when installing the operating system. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft fixes button that restores classic Outlook client
Microsoft fixes button that restores classic Outlook client Microsoft resolved an issue that caused the new Outlook email client to crash when users clicked a button designed to switch back to classic Outlook. […] Sergiu Gatlan Go to bleepingcomputer
-
Hijacked Microsoft Stream classic domain “spams” SharePoint sites
Hijacked Microsoft Stream classic domain “spams” SharePoint sites The legacy domain for Microsoft Stream was hijacked to show a fake Amazon site promoting a Thailand casino, causing all SharePoint sites with old embedded videos to display it as spam. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5053656 update released with 38 changes and fixes
Windows 11 KB5053656 update released with 38 changes and fixes Microsoft has released the KB5053656 preview cumulative update for Windows 11 24H2 with 38 changes, including real-time translation on AMD and Intel-powered Copilot+ PCs and fixes for authentication and blue-screen issues. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: New Windows scheduled task will launch Office apps faster
Microsoft: New Windows scheduled task will launch Office apps faster In May, Microsoft plans to roll out a new Windows scheduled task that launches automatically to help Microsoft Office apps load faster. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 update breaks Veeam recovery, causes connection errors
Windows 11 update breaks Veeam recovery, causes connection errors Microsoft and Veeam are investigating a known issue that triggers connection errors on Windows 11 24H2 systems when restoring from Veeam Recovery Media. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Exchange Online bug mistakenly quarantines user emails
Microsoft: Exchange Online bug mistakenly quarantines user emails Microsoft is investigating an Exchange Online bug causing anti-spam systems to mistakenly quarantine some users’ emails. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Exchange Online outage affects Outlook web users
Microsoft Exchange Online outage affects Outlook web users Microsoft is investigating an ongoing outage preventing Outlook on the web users from accessing their Exchange Online mailboxes. […] Sergiu Gatlan Go to bleepingcomputer
-
New Windows zero-day exploited by 11 state hacking groups since 2017
New Windows zero-day exploited by 11 state hacking groups since 2017 At least 11 state-backed hacking groups from North Korea, Iran, Russia, and China have been exploiting a new Windows vulnerability in data theft and cyber espionage zero-day attacks since 2017. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Windows File Explorer Vulnerability Let Attackers Perform Network Spoofing – PoC Released
Microsoft Windows File Explorer Vulnerability Let Attackers Perform Network Spoofing – PoC Released A critical vulnerability in Windows File Explorer, identified as CVE-2025-24071, enables attackers to steal NTLM hashed passwords without any user interaction beyond simply extracting a compressed file. Security researchers have released a proof-of-concept exploit demonstrating this high-severity flaw, which Microsoft patched in…
-
Microsoft: New RAT malware used for crypto theft, reconnaissance
Microsoft: New RAT malware used for crypto theft, reconnaissance Microsoft has discovered a new remote access trojan (RAT) that employs “sophisticated techniques” to avoid detection, maintain persistence, and extract sensitive data. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: March Windows updates mistakenly uninstall Copilot
Microsoft: March Windows updates mistakenly uninstall Copilot Microsoft says the March 2025 Windows cumulative updates automatically and mistakenly remove the AI-powered Copilot digital assistant from some Windows 10 and Windows 11 systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Week-long Exchange Online outage causes email failures, delays
Week-long Exchange Online outage causes email failures, delays Microsoft says it partially mitigated a week-long Exchange Online outage causing delays or failures when sending or receiving email messages. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft apologizes for removing VSCode extensions used by millions
Microsoft apologizes for removing VSCode extensions used by millions Microsoft has reinstated the ‘Material Theme – Free’ and ‘Material Theme Icons – Free’ extensions on the Visual Studio Marketplace after finding that the obfuscated code they contained wasn’t actually malicious. […] Bill Toulas Go to bleepingcomputer
-
Windows Notepad to get AI text summarization in Windows 11
Windows Notepad to get AI text summarization in Windows 11 Microsoft is now testing an AI-powered text summarization feature in Notepad and a Snipping Tool “Draw & Hold” feature that helps draw perfect shapes. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft says button to restore classic Outlook is broken
Microsoft says button to restore classic Outlook is broken Microsoft is investigating a known issue that causes the new Outlook email client to crash when users click the “Go to classic Outlook” button, which should help them switch back to the classic Outlook. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft365 Themed Attack Leveraging OAuth Redirection for Account Takeover
Microsoft365 Themed Attack Leveraging OAuth Redirection for Account Takeover Two sophisticated phishing campaigns were observed targeting Microsoft 365 users by exploiting OAuth redirection vulnerabilities combined with brand impersonation techniques. Threat researchers are warning organizations about these highly targeted attacks designed to bypass traditional security controls and achieve account takeover (ATO). The malicious campaigns leverage familiar…
-
Little fires everywhere for March Patch Tuesday
Little fires everywhere for March Patch Tuesday Just 57 CVEs to contend with (plus advisories), but six are already under exploit in the wild Angela Gunn Go to sophos
-
Windows 10 KB5053606 update fixes broken SSH connections
Windows 10 KB5053606 update fixes broken SSH connections Microsoft has released the KB5053606 cumulative update for Windows 10 22H2 and Windows 10 21H2, which fixes numerous bugs, including one preventing SSH connections. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws Today is Microsoft’s March 2025 Patch Tuesday, which includes security updates for 57 flaws, including six actively exploited zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5053598 & KB5053602 cumulative updates released
Windows 11 KB5053598 & KB5053602 cumulative updates released Microsoft has released Windows 11 KB5053598 and KB5053602 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues. […] Mayank Parmar Go to bleepingcomputer
-
Microsoft March 2025 Patch Tuesday: Fixes for 57 Vulnerabilities & 6 Actively Exploited Zero-Days
Microsoft March 2025 Patch Tuesday: Fixes for 57 Vulnerabilities & 6 Actively Exploited Zero-Days Microsoft’s March 2025 Patch Tuesday addresses 57 vulnerabilities, including six zero-day vulnerabilities that are currently being exploited. The security update includes fixes for Windows, Microsoft Office, Azure, and other components. The March patch tuesday update included fixes for: In addition to…
-
CISA Warns of Microsoft Windows Management Console (MMC) Vulnerability Exploited in Wild
CISA Warns of Microsoft Windows Management Console (MMC) Vulnerability Exploited in Wild The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding an actively exploited vulnerability in Microsoft Windows Management Console (MMC), tracked as CVE-2025-26633. This improper neutralization flaw (CWE-707) enables remote attackers to execute arbitrary code over a network, posing significant…
-
Microsoft shares guidance on upcoming Publisher deprecation
Microsoft shares guidance on upcoming Publisher deprecation Microsoft has published guidance for users of Microsoft Publisher as it will no longer be supported after October 2026 and removed from Microsoft 365. […] Bill Toulas Go to bleepingcomputer
-
Microsoft says malvertising campaign impacted 1 million PCs
Microsoft says malvertising campaign impacted 1 million PCs Microsoft has taken down an undisclosed number of GitHub repositories used in a massive malvertising campaign that impacted almost one million devices worldwide. […] Sergiu Gatlan Go to bleepingcomputer