Category: Microsoft
-
Microsoft Congratulates MSRC’s Most Valuable Security Researchers
Microsoft Congratulates MSRC’s Most Valuable Security Researchers Microsoft has officially announced its 2025 Most Valuable Security Researchers, recognizing the top 100 security researchers worldwide who have made significant contributions to protecting Microsoft customers through the Microsoft Security Response Center (MSRC) program. The recognition is based on a comprehensive point system that evaluates researchers’ valid vulnerability…
-
Windows KB5064489 emergency update fixes Azure VM launch issues
Windows KB5064489 emergency update fixes Azure VM launch issues Microsoft has released an emergency update to fix a bug that prevents Azure virtual machines from launching when the Trusted Launch setting is disabled and Virtualization-Based Security (VBS) is enabled. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 10 KB5062554 update breaks emoji panel search feature
Windows 10 KB5062554 update breaks emoji panel search feature The search feature for the Windows 10 emoji panel is broken after installing the KB5062554 cumulative update released Tuesday, making it not possible to look up emojis by name or keyword. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 now uses JScript9Legacy engine for improved security
Windows 11 now uses JScript9Legacy engine for improved security Microsoft announced that it has replaced the default scripting engine JScript with the newer and more secure JScript9Legacy on Windows 11 version 24H2 and later. […] Bill Toulas Go to bleepingcomputer
-
July Patch Tuesday offers 127 fixes
July Patch Tuesday offers 127 fixes The seventh month is always a big one for Microsoft, and this year is no exception Angela Gunn Go to sophos
-
Microsoft Authenticator on iOS moves backups fully to iCloud
Microsoft Authenticator on iOS moves backups fully to iCloud Microsoft is rolling out a new backup system in September for its Authenticator app on iOS, removing the requirement to use a Microsoft personal account to back up TOTP secrets and account names. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft confirms Windows Server Update Services (WSUS) sync is broken
Microsoft confirms Windows Server Update Services (WSUS) sync is broken Microsoft has confirmed a widespread issue in Windows Server Update Services (WSUS) that prevents organizations from syncing with Microsoft Update and deploying the latest Windows updates. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Outlook Down: Users Unable to Access Mailboxes
Microsoft Outlook Down: Users Unable to Access Mailboxes In a significant disruption for millions of users worldwide, Microsoft Outlook has been experiencing a major outage since Wednesday, July 9, 2025, starting at 10:20 PM UTC. The issue has left users unable to access their mailboxes through any connection method, causing widespread frustration among individuals and…
-
Windows 10 KB5062554 cumulative update released with 13 changes, fixes
Windows 10 KB5062554 cumulative update released with 13 changes, fixes Microsoft has released the KB5062554 cumulative update for Windows 10 22H2 and Windows 10 21H2, with thirteen new fixes or changes. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5062553 & KB5062552 cumulative updates released
Windows 11 KB5062553 & KB5062552 cumulative updates released Microsoft has released Windows 11 KB5062553 and KB5062552 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues. […] Mayank Parmar Go to bleepingcomputer
-
Microsoft SQL Server 0-Day Vulnerability Exposes Sensitive Data Over Network
Microsoft SQL Server 0-Day Vulnerability Exposes Sensitive Data Over Network A critical information disclosure vulnerability in Microsoft SQL Server, designated as CVE-2025-49719, allows unauthorized attackers to access sensitive data over network connections. This vulnerability stems from improper input validation within SQL Server’s processing mechanisms, enabling attackers to disclose uninitialized memory contents without requiring authentication or…
-
Microsoft Remote Desktop Client Vulnerability Let Attackers Execute Remote Code
Microsoft Remote Desktop Client Vulnerability Let Attackers Execute Remote Code A critical security vulnerability in Microsoft Remote Desktop Client could allow attackers to execute arbitrary code on victim systems. The vulnerability, designated as CVE-2025-48817, affects multiple versions of Windows and poses significant security risks for organizations that rely on Remote Desktop Protocol (RDP) connections. Key…
-
Hands on with Windows 11 Notepad’s new markdown support
Hands on with Windows 11 Notepad’s new markdown support Notepad now lets you use markdown text formatting on Windows 11, which means you can write in Notepad just like you could in WordPad. […] Mayank Parmar Go to bleepingcomputer
-
Microsoft Investigating Forms Service Issue Not Accessible for Users
Microsoft Investigating Forms Service Issue Not Accessible for Users Microsoft is currently investigating a significant service disruption affecting Microsoft Forms, leaving numerous users unable to access the popular online survey and quiz platform. The issue, identified as incident FM1109073, began on July 4, 2025, at 12:42 PM GMT+5:30 and has been classified as a service…
-
Microsoft asks users to ignore Windows Firewall config errors
Microsoft asks users to ignore Windows Firewall config errors Microsoft asked customers this week to disregard incorrect Windows Firewall errors that appear after rebooting their systems following the installation of the June 2025 preview update. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Defender for Office 365 now blocks email bombing attacks
Microsoft Defender for Office 365 now blocks email bombing attacks Microsoft says its Defender for Office 365 cloud-based email security suite will now automatically detect and block email bombing attacks. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 KB5060829 update released with 38 new changes, fixes
Windows 11 KB5060829 update released with 38 new changes, fixes Microsoft has released the KB5060829 preview cumulative update for Windows 11 24H2, which includes 38 changes, including improvements to the taskbar and a new PC-to-PC migration experience. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft confirms Family Safety blocks Google Chrome from launching
Microsoft confirms Family Safety blocks Google Chrome from launching Microsoft has confirmed that its Family Safety parental control service is blocking users from launching Google Chrome and other web browsers on Windows systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 10 KB5061087 update released with 13 changes and fixes
Windows 10 KB5061087 update released with 13 changes and fixes Microsoft has released the June 2025 non-security preview update for Windows 10, version 22H2, with fixes for bugs preventing the Start Menu from launching and breaking scanning features on USB multi-function printers. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows Snipping Tool now lets you create animated GIF recordings
Windows Snipping Tool now lets you create animated GIF recordings Microsoft announced that the Windows screenshot and screencast Snipping Tool utility is getting support for exporting animated GIF recordings. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft investigates OneDrive bug that breaks file search
Microsoft investigates OneDrive bug that breaks file search Microsoft is investigating a known OneDrive issue that is causing searches to appear blank for some users or return no results even when searching for files they know they’ve already uploaded. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Announces New Security Defaults for Windows 365 Cloud PCs
Microsoft Announces New Security Defaults for Windows 365 Cloud PCs Summary 1. Redirection controls disable clipboard, drive, USB, and printer access by default to prevent data exfiltration and malware injection. 2. Virtualization-based security enables VBS, Credential Guard, and HVCI on Windows 11 Cloud PCs to fortify against credential theft and kernel exploits. 3. Selective implementation…
-
Microsoft 365 to block file access via legacy auth protocols by default
Microsoft 365 to block file access via legacy auth protocols by default Microsoft has announced that it will soon update security defaults for all Microsoft 365 tenants to block access to SharePoint, OneDrive, and Office files via legacy authentication protocols. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: June Windows Server security updates cause DHCP issues
Microsoft: June Windows Server security updates cause DHCP issues Microsoft acknowledged a new issue caused by the June 2025 security updates, causing the DHCP service to freeze on some Windows Server systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 users want these five features back
Windows 11 users want these five features back When Windows 11 was first released, many long-time users felt features they loved had been taken away overnight. Three and a half years later, the same complaints still rise to the top of the Feedback Hub with tens of thousands of votes. […] Mayank Parmar Go to…
-
Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices
Microsoft: KB5060533 update triggers boot errors on Surface Hub v1 devices Microsoft is investigating a known issue that triggers Secure Boot errors and prevents Surface Hub v1 devices from starting up. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft confirms auth issues affecting Microsoft 365 users
Microsoft confirms auth issues affecting Microsoft 365 users Microsoft is investigating an ongoing incident that is causing users to experience errors with some Microsoft 365 authentication features. […] Sergiu Gatlan Go to bleepingcomputer
-
June Patch Tuesday digs into 67 bugs
June Patch Tuesday digs into 67 bugs An extremely Windows-heavy month, with a surprise cameo by… Sophos?! Angela Gunn Go to sophos
-
Why Denmark is breaking up with Microsoft
Why Denmark is breaking up with Microsoft Relying too heavily on a US tech giant for your nation’s digital infrastructure is starting to feel a bit… well, risky. Graham Cluley Go to grahamcluley
-
Password-spraying attacks target 80,000 Microsoft Entra ID accounts
Password-spraying attacks target 80,000 Microsoft Entra ID accounts Hackers have been using the TeamFiltration pentesting framework to target more than 80,000 Microsoft Entra ID accounts at hundreds of organizations worldwide. […] Bill Toulas Go to bleepingcomputer
-
Microsoft Edge now offers secure password deployment for businesses
Microsoft Edge now offers secure password deployment for businesses Microsoft announced that a new Edge feature allowing employees to share passwords more securely in enterprise environments has reached general availability. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 10 KB5060533 cumulative update released with 7 changes, fixes
Windows 10 KB5060533 cumulative update released with 7 changes, fixes Microsoft has released the KB5060533 cumulative update for Windows 10 22H2 and Windows 10 21H2, with seven fixes or changes, including bringing seconds back to the time shown in the Calendar flyout. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws Today is Microsoft’s June 2025 Patch Tuesday, which includes security updates for 66 flaws, including one actively exploited vulnerability and another that was publicly disclosed. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft shares script to restore inetpub folder you shouldn’t delete
Microsoft shares script to restore inetpub folder you shouldn’t delete Microsoft has released a PowerShell script to help restore an empty ‘inetpub’ folder created by the April 2025 Windows security updates if deleted. As Microsoft previously warned, this folder helps mitigate a high-severity Windows Process Activation privilege escalation vulnerability. […] Sergiu Gatlan Go to bleepingcomputer
-
Proxy Services Feast on Ukraine’s IP Address Exodus
Proxy Services Feast on Ukraine’s IP Address Exodus Image: Mark Rademaker, via Shutterstock. Ukraine has seen nearly one-fifth of its Internet space come under Russian control or sold to Internet address brokers since February 2022, a new study finds. The analysis indicates large chunks of Ukrainian Internet address space are now in the hands of…
-
Microsoft unveils free EU cybersecurity program for governments
Microsoft unveils free EU cybersecurity program for governments Microsoft announced in Berlin today a new European Security Program that promises to bolster cybersecurity for European governments. […] Bill Toulas Go to bleepingcomputer
-
Microsoft adds quick machine recovery to Windows 11 settings
Microsoft adds quick machine recovery to Windows 11 settings Microsoft is testing a dedicated page in Windows Settings for quick machine recovery, which will provide users with additional configuration options. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft and CrowdStrike partner to link hacking group names
Microsoft and CrowdStrike partner to link hacking group names Microsoft and CrowdStrike announced today that they’ve partnered to connect the aliases used for specific threat groups without actually using a single naming standard. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft now testing Notepad text formatting in Windows 11
Microsoft now testing Notepad text formatting in Windows 11 Microsoft announced today that the Windows 11 Notepad application is getting a text formatting feature supporting Markdown-style input. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Authenticator now warns to export passwords before July cutoff
Microsoft Authenticator now warns to export passwords before July cutoff The Microsoft Authenticator app is now issuing notifications warning that the password autofill feature is being deprecated in July, suggesting users move to Microsoft Edge instead. […] Lawrence Abrams Go to bleepingcomputer
-
U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams
U.S. Sanctions Cloud Provider ‘Funnull’ as Top Source of ‘Pig Butchering’ Scams Image: Shutterstock, ArtHead. The U.S. government today imposed economic sanctions on Funnull Technology Inc., a Philippines-based company that provides computer infrastructure for hundreds of thousands of websites involved in virtual currency investment scams known as “pig butchering.” In January 2025, KrebsOnSecurity detailed how…
-
Microsoft: Windows 11 might fail to start after installing KB5058405
Microsoft: Windows 11 might fail to start after installing KB5058405 Microsoft has confirmed that some Windows 11 systems might fail to start after installing the KB5058405 security update released during this month’s Patch Tuesday. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 10 KB5058481 update brings seconds back to calendar flyout
Windows 10 KB5058481 update brings seconds back to calendar flyout Microsoft has released the optional KB5058481 preview cumulative update for Windows 10 22H2 with seven changes, including restoring seconds to the time display in the calendar flyout for those who previously lost it. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 11 KB5058499 update rolls out new Share and Click to Do features
Windows 11 KB5058499 update rolls out new Share and Click to Do features Microsoft has released the KB5058499 preview cumulative update for Windows 11 24H2 with forty-eight new features or changes, with many gradually rolling out, such as the new Windows Share feature and tje Click to Do Preview. […] Lawrence Abrams Go to bleepingcomputer
-
Russian Laundry Bear cyberspies linked to Dutch Police hack
Russian Laundry Bear cyberspies linked to Dutch Police hack A previously unknown Russian-backed cyberespionage group now tracked as Laundry Bear has been linked to a September 2024 Dutch police security breach. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows Server emergency update fixes Hyper-V VM freezes, restart issues
Windows Server emergency update fixes Hyper-V VM freezes, restart issues Microsoft has released an emergency update to address a known issue causing some Hyper-V virtual machines with Windows Server 2022 to freeze or restart unexpectedly. […] Sergiu Gatlan Go to bleepingcomputer
-
Signal Blocks Windows Recall
Signal Blocks Windows Recall This article gives a good rundown of the security risks of Windows Recall, and the repurposed copyright protection took that Signal used to block the AI feature from scraping Signal data. Bruce Schneier Go to bruce schneier
-
Windows 11 Notepad gets AI-powered text writing capabilities
Windows 11 Notepad gets AI-powered text writing capabilities Microsoft is testing a new AI-powered text generation feature in Notepad that can let Windows Insiders create content based on custom prompts. […] Sergiu Gatlan Go to bleepingcomputer
-
Oops: DanaBot Malware Devs Infected Their Own PCs
Oops: DanaBot Malware Devs Infected Their Own PCs The U.S. government today unsealed criminal charges against 16 individuals accused of operating and selling DanaBot, a prolific strain of information-stealing malware that has been sold on Russian cybercrime forums since 2018. The FBI says a newer version of DanaBot was used for espionage, and that many…
-
Windows 10 emergency updates fix BitLocker recovery issues
Windows 10 emergency updates fix BitLocker recovery issues Microsoft has released out-of-band updates to fix a known issue causing Windows 10 systems to boot into BitLocker recovery after installing the May 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Releases Emergency Fix for BitLocker Recovery Issue
Microsoft Releases Emergency Fix for BitLocker Recovery Issue Microsoft has released an emergency out-of-band update (KB5061768) to address a critical issue causing Windows 10 systems to boot into BitLocker recovery screens following the installation of the May 2025 security updates. The fix, released on May 19, comes after numerous reports from enterprise customers experiencing system…
-
Abusing dMSA with Advanced Active Directory Persistence Techniques
Abusing dMSA with Advanced Active Directory Persistence Techniques Delegated Managed Service Accounts (dMSAs), introduced in Windows Server 2025, represent Microsoft’s latest innovation in secure service account management. While designed to enhance security by preventing traditional credential theft attacks like Kerberoasting, security researchers have uncovered potential abuse vectors that could allow attackers to establish persistent access…
-
New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender
New ‘Defendnot’ tool tricks Windows into disabling Microsoft Defender A new tool called ‘Defendnot’ can disable Microsoft Defender on Windows devices by registering a fake antivirus product, even when no real AV is installed. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft confirms May Windows 10 updates trigger BitLocker recovery
Microsoft confirms May Windows 10 updates trigger BitLocker recovery Microsoft has confirmed that some Windows 10 and Windows 10 Enterprise LTSC 2021 systems will boot into BitLocker recovery after installing the May 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 10 KB5058379 update triggers BitLocker recovery on some devices
Windows 10 KB5058379 update triggers BitLocker recovery on some devices The Windows 10 KB5058379 cumulative update is triggering unexpected BitLocker recovery prompts on some devices afters it’s installed and the computer restarted. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft primes 71 fixes for May Patch Tuesday
Microsoft primes 71 fixes for May Patch Tuesday Five issues actively exploited in the wild, but the real excitement may have been handled in advance Angela Gunn Go to sophos
-
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws Today is Microsoft’s May 2025 Patch Tuesday, which includes security updates for 72 flaws, including five actively exploited and two publicly disclosed zero-day vulnerabilities. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network
Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network Microsoft has issued a security advisory regarding a new vulnerability in Active Directory Certificate Services (AD CS) that could allow attackers to perform denial-of-service attacks over a network. The vulnerability, identified as CVE-2025-29968, affects multiple versions of Windows Server and has been…
-
Microsoft Defender Vulnerability Allows Attackers to Elevate Privileges
Microsoft Defender Vulnerability Allows Attackers to Elevate Privileges A newly disclosed security flaw in Microsoft Defender for Endpoint could allow attackers with local access to elevate their privileges to SYSTEM level, potentially gaining complete control over affected systems. The vulnerability, tracked as CVE-2025-26684, was patched as part of Microsoft’s May 2025 Patch Tuesday security updates…
-
Windows 11 upgrade block lifted after Safe Exam Browser fix
Windows 11 upgrade block lifted after Safe Exam Browser fix Microsoft has removed an upgrade block that prevented some Safe Exam Browser users from installing the Windows 11 2024 Update due to incompatibility issues. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Teams will soon block screen capture during meetings
Microsoft Teams will soon block screen capture during meetings Microsoft is working on adding a new Teams feature that will prevent users from capturing screenshots of sensitive information shared during meetings. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Teams To Block Screen Capture During Meetings
Microsoft Teams To Block Screen Capture During Meetings Microsoft has announced a new “Prevent Screen Capture” feature for Teams that will block unauthorized screenshots during meetings. The feature, scheduled for worldwide rollout in July 2025, represents Microsoft’s continued focus on enterprise security and regulatory compliance in an era where sensitive information is increasingly shared in…
-
Play ransomware exploited Windows logging flaw in zero-day attacks
Play ransomware exploited Windows logging flaw in zero-day attacks The Play ransomware gang has exploited a high-severity Windows Common Log File System flaw in zero-day attacks to gain SYSTEM privileges and deploy malware on compromised systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: April updates cause Windows Server auth issues
Microsoft: April updates cause Windows Server auth issues Microsoft says the April 2025 security updates are causing authentication issues on some Windows Server 2025 domain controllers. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft pushes fix for Windows 11 update 0x80240069 errors
Microsoft pushes fix for Windows 11 update 0x80240069 errors Microsoft has fixed a known issue preventing Windows 11 24H2 feature updates from being delivered via Windows Server Update Services (WSUS) after installing the April 2025 security updates. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft ends Authenticator password autofill, moves users to Edge
Microsoft ends Authenticator password autofill, moves users to Edge Microsoft has announced that it will discontinue the password storage and autofill feature in the Authenticator app starting in July and will complete the deprecation in August 2025. […] Bill Toulas Go to bleepingcomputer
-
Microsoft makes all new accounts passwordless by default
Microsoft makes all new accounts passwordless by default Microsoft has announced that all new Microsoft accounts will be “passwordless by default” to secure them against password attacks such as phishing, brute force, and credential stuffing. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Windows Server hotpatching to require subscription
Microsoft: Windows Server hotpatching to require subscription Microsoft has announced it will require paid subscriptions for Windows Server 2025 hotpatching, a service that enables admins to install security updates without restarting. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11’s Recall AI is now rolling out on Copilot+ PCs
Windows 11’s Recall AI is now rolling out on Copilot+ PCs Microsoft has confirmed that Windows Recall is rolling out to everyone with Windows 11 KB5055627 on Copilot+ PCs. […] Mayank Parmar Go to bleepingcomputer
-
Windows 11 KB5055627 update released with 30 new changes, fixes
Windows 11 KB5055627 update released with 30 new changes, fixes Microsoft has released the KB5055627 preview cumulative update for Windows 11 24H2 with many new features gradually rolling out, and some new bug fixes for everyone. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft announces fix for CPU spikes when typing in Outlook
Microsoft announces fix for CPU spikes when typing in Outlook Microsoft says it will soon fix a known issue causing CPU spikes when typing messages in recent versions of its classic Outlook email client. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes machine learning bug flagging Adobe emails as spam
Microsoft fixes machine learning bug flagging Adobe emails as spam Microsoft says it mitigated a known issue in one of its machine learning (ML) models that mistakenly flagged Adobe emails in Exchange Online as spam. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft’s Symlink Patch Created New Windows DoS Vulnerability
Microsoft’s Symlink Patch Created New Windows DoS Vulnerability A recent Microsoft security update, intended to patch a critical privilege escalation vulnerability, has inadvertently introduced a new and significant flaw. The fix now enables non-administrative users to effectively block all future Windows security updates, creating a denial-of-service condition. This unintended consequence of the patch highlights the…
-
Microsoft fixes Remote Desktop freezes caused by Windows updates
Microsoft fixes Remote Desktop freezes caused by Windows updates Microsoft has resolved a known issue causing Remote Desktop sessions to freeze on Windows Server 2025 and Windows 11 24H2 devices. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft fixes Windows Server 2025 blue screen, install issues
Microsoft fixes Windows Server 2025 blue screen, install issues Microsoft has fixed several known issues that caused Blue Screen of Death (BSOD) and installation issues on Windows Server 2025 systems with a high core count. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Entra account lockouts caused by user token logging mishap
Microsoft Entra account lockouts caused by user token logging mishap Microsoft confirms that the weekend Entra account lockouts were caused by the invalidation of short-lived user refresh tokens that were mistakenly logged into internal systems. […] Lawrence Abrams Go to bleepingcomputer
-
Widespread Microsoft Entra lockouts tied to new security feature rollout
Widespread Microsoft Entra lockouts tied to new security feature rollout Windows administrators from numerous organizations report widespread account lockouts triggered by false positives in the rollout of a new Microsoft Entra ID’s “leaked credentials” detection app called MACE. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft Defender will isolate undiscovered endpoints to block attacks
Microsoft Defender will isolate undiscovered endpoints to block attacks Microsoft is testing a new Defender for Endpoint capability that will block traffic to and from undiscovered endpoints to thwart attackers’ lateral network movement attempts. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft starts final Windows Recall testing before rollout
Microsoft starts final Windows Recall testing before rollout Microsoft is gradually rolling out the AI-powered Windows Recall feature to Insiders in the Release Preview channel before making it generally available to all Windows users with Copilot+ PCs. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Windows ‘inetpub’ folder created by security fix, don’t delete
Microsoft: Windows ‘inetpub’ folder created by security fix, don’t delete Microsoft has now confirmed that an April 2025 Windows security update is creating a new empty “inetpub” folder and warned users not to delete it. […] Sergiu Gatlan Go to bleepingcomputer
-
AI Vulnerability Finding
AI Vulnerability Finding Microsoft is reporting that its AI systems are able to find new vulnerabilities in source code: Microsoft discovered eleven vulnerabilities in GRUB2, including integer and buffer overflows in filesystem parsers, command flaws, and a side-channel in cryptographic comparison. Additionally, 9 buffer overflows in parsing SquashFS, EXT4, CramFS, JFFS2, and symlinks were discovered…
-
Microsoft releases emergency update to fix Office 2016 crashes
Microsoft releases emergency update to fix Office 2016 crashes Microsoft has released an out-of-band Office update to fix a known issue that caused Word, Excel, and Outlook to crash after installing the KB5002700 security update for Office 2016. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Licensing issue blocks Microsoft 365 Family for some users
Microsoft: Licensing issue blocks Microsoft 365 Family for some users Microsoft is investigating a potential licensing issue blocking access to Microsoft 365 services for some customers with Family subscriptions. […] Sergiu Gatlan Go to bleepingcomputer
-
Windows 11 tests sharing apps screen and files with Copilot AI
Windows 11 tests sharing apps screen and files with Copilot AI Copilot on Windows 11 is testing OS-level integration that would allow you to share your favourite apps’ screen with Copilot. […] Mayank Parmar Go to bleepingcomputer
-
Industrial-strength April Patch Tuesday covers 135 CVEs
Industrial-strength April Patch Tuesday covers 135 CVEs One actively exploited issue patched; five Critical-severity Office vulns exploitable via Preview Pane Angela Gunn Go to sophos
-
Patch Tuesday, April 2025 Edition
Patch Tuesday, April 2025 Edition Microsoft today released updates to plug at least 121 security holes in its Windows operating systems and software, including one vulnerability that is already being exploited in the wild. Eleven of those flaws earned Microsoft’s most-dire “critical” rating, meaning malware or malcontents could exploit them with little to no interaction…
-
Microsoft fixes auth issues on Windows Server, Windows 11 24H2
Microsoft fixes auth issues on Windows Server, Windows 11 24H2 Microsoft has fixed a known issue causing authentication problems when Credential Guard is enabled on systems using the Kerberos PKINIT pre-auth security protocol. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft: Windows CLFS zero-day exploited by ransomware gang
Microsoft: Windows CLFS zero-day exploited by ransomware gang Microsoft says the RansomEXX ransomware gang has been exploiting a high-severity zero-day flaw in the Windows Common Log File System to gain SYSTEM privileges on victims’ systems. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws
Microsoft April 2025 Patch Tuesday fixes exploited zero-day, 134 flaws Today is Microsoft’s April 2025 Patch Tuesday, which includes security updates for 134 flaws, including one actively exploited zero-day vulnerability. […] Lawrence Abrams Go to bleepingcomputer
-
Windows 10 KB5055518 update fixes random text when printing
Windows 10 KB5055518 update fixes random text when printing Microsoft has released the KB5055518 cumulative update for Windows 10 22H2 and Windows 10 21H2, with nine changes or fixes. […] Lawrence Abrams Go to bleepingcomputer
-
EncryptHub’s dual life: Cybercriminal vs Windows bug-bounty researcher
EncryptHub’s dual life: Cybercriminal vs Windows bug-bounty researcher EncryptHub, a notorious threat actor linked to breaches at 618 organizations, is believed to have reported two Windows zero-day vulnerabilities to Microsoft, revealing a conflicted figure straddling the line between cybercrime and security research. […] Bill Toulas Go to bleepingcomputer
-
Microsoft delays WSUS driver sync deprecation indefinitely
Microsoft delays WSUS driver sync deprecation indefinitely Microsoft announced today that, based on customer feedback, it will indefinitely delay removing driver synchronization in Windows Server Update Services (WSUS). […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft Celebrates 50th Anniversary!
Microsoft Celebrates 50th Anniversary! Microsoft celebrated its 50th anniversary on April 4, 2025, reflecting on its journey since Bill Gates and Paul Allen founded the company in 1975. The milestone event, held at Microsoft’s Redmond, Washington headquarters, blended nostalgia with cutting-edge AI advancements, particularly through its Copilot platform, while highlighting the transformative role of technology…
-
Microsoft starts testing Windows 11 taskbar icon scaling
Microsoft starts testing Windows 11 taskbar icon scaling Microsoft is testing a new taskbar icon scaling feature that automatically scales down Windows taskbar icons to show more apps when it gets too overcrowded. […] Sergiu Gatlan Go to bleepingcomputer
-
Microsoft adds hotpatching support to Windows 11 Enterprise
Microsoft adds hotpatching support to Windows 11 Enterprise Microsoft has announced that hotpatch updates are now available for business customers using Windows 11 Enterprise 24H2 on x64 (AMD/Intel) systems, starting today. […] Sergiu Gatlan Go to bleepingcomputer
-
New Windows 11 trick lets you bypass Microsoft Account requirement
New Windows 11 trick lets you bypass Microsoft Account requirement A previously unknown trick lets you easily bypass using a Microsoft Account in Windows 11, just as Microsoft tries to make it harder to use local accounts. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft uses AI to find flaws in GRUB2, U-Boot, Barebox bootloaders
Microsoft uses AI to find flaws in GRUB2, U-Boot, Barebox bootloaders Microsoft used its AI-powered Security Copilot to discover 20 previously unknown vulnerabilities in the GRUB2, U-Boot, and Barebox open-source bootloaders. […] Bill Toulas Go to bleepingcomputer
-
Microsoft tests new Windows 11 tool to remotely fix boot crashes
Microsoft tests new Windows 11 tool to remotely fix boot crashes Microsoft has begun testing a new Windows 11 tool called Quick Machine Recovery, which is designed to remotely deploy fixes for buggy drivers and configurations that prevent the operating system from starting. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft’s killing script used to avoid Microsoft Account in Windows 11
Microsoft’s killing script used to avoid Microsoft Account in Windows 11 Microsoft has removed the ‘BypassNRO.cmd’ script from Windows 11 preview builds, which allowed users to bypass the requirement to use a Microsoft Account when installing the operating system. […] Lawrence Abrams Go to bleepingcomputer
-
Microsoft fixes button that restores classic Outlook client
Microsoft fixes button that restores classic Outlook client Microsoft resolved an issue that caused the new Outlook email client to crash when users clicked a button designed to switch back to classic Outlook. […] Sergiu Gatlan Go to bleepingcomputer