Tag

Microsoft Windows

All articles tagged with #microsoft windows

Microsoft Patch Tuesday Sets a 974-Vulnerability Record With Two Actively Exploited Windows Zero-Days
security1 month ago

Microsoft Patch Tuesday Sets a 974-Vulnerability Record With Two Actively Exploited Windows Zero-Days

Microsoft’s September Patch Tuesday patches a record 974 vulnerabilities across Windows, Office, SQL, and Developer Tools, including two zero-days actively exploited in the wild (CVE-2026-85880 and CVE-2026-81963). The fixes bring the total resolved vulnerabilities to 999 (including 25 non-Microsoft CVEs), with over 110 rated critical and the bulk involving privilege escalation, remote code execution, and information disclosure. CISA added both CVEs to the Known Exploited Vulnerabilities catalog, ordering federal agencies to apply updates by September 22, 2026. Despite the high volume, attackers’ exploitation rates remain limited, so organizations should prioritize remediation based on exposure and relevance.

technology1 month ago

Microsoft Stages Massive Patch Tuesday as AI Aids Historic Vulnerability Sweep

Microsoft released its largest patch batch ever, fixing at least 974 vulnerabilities across Windows and related software, with AI-assisted vulnerability discovery contributing to the surge and pushing this year’s total past 2,600. The update includes two actively exploited zero-days (CVE-2026-81963 and CVE-2026-85880) and 113 critical flaws, notably CVE-2026-69730 (Windows DNS) and CVE-2026-69829 (Windows Shell). Security experts caution that patch volume complicates prioritization and testing for organizations, underscoring the need for careful risk-based remediation and potentially after-hours deployment. The article also notes broader AI-driven patch increases across the industry and urges admins to follow per-patch guidance from sources like SANS and AskWoody.

Microsoft's September patch blitz shatters vulnerability records amid AI-driven bug hunting
technology1 month ago

Microsoft's September patch blitz shatters vulnerability records amid AI-driven bug hunting

Microsoft's September patch release fixes a record ~972 vulnerabilities (997 with Edge/Chromium), including 112 critical flaws and two zero-days in Windows Update and Windows Local Procedure; AI-assisted vulnerability discovery is driving these record numbers as the industry braces for AI-enabled exploits, though active exploitation remains limited so far.

Mozilla-Backed Report Alleges Windows Nudges Toward Edge
technology2 months ago

Mozilla-Backed Report Alleges Windows Nudges Toward Edge

A Mozilla-commissioned study, Over The Edge 2.0, accuses Microsoft of using design tricks in Windows—such as banner prompts, a pre-pinned Edge, and preselected Copilot data-sharing toggles—to nudge users toward Edge. The report finds regional differences (EEA vs US/UK/India) and notes changes in the EU, but Edge’s overall market share remains modest while rival browsers grow. Regulators and competitors call for fair competition; Microsoft did not immediately respond to requests for comment.

technology4 months ago

June 2026 Patch Tuesday Sets Record With 200 Fixes and New Zero-Days

Microsoft's June 2026 Patch Tuesday delivered a record ~200 fixes across Windows and related software, with about 36 rated critical and several publicly exploited flaws. Highlights include IIS zero-day CVE-2026-49160, Nightmare Eclipse-linked Windows flaws (e.g., CVE-2026-45586) and a BitLocker privilege escalation (CVE-2026-50507), plus a Visual Studio Code zero-day exposing GitHub tokens. The patch surge comes amid a broader spike in browser vulnerabilities and other vendor updates (Adobe, Chrome); Nightmare Eclipse has pledged more zero-days for July 14, and Microsoft urges users to back up data before updating.

Windows tightens RDP file use to block phishing-prone connections
security5 months ago

Windows tightens RDP file use to block phishing-prone connections

Microsoft’s April 2026 updates for Windows 10 and Windows 11 add protections to curb phishing by malicious Remote Desktop (.rdp) files: first-open triggers educate users, and subsequent attempts show a security dialog listing the file’s publisher status, remote address, and local resource redirects with all options off by default. If unsigned, a caution label appears; if signed, the publisher is shown but verification is still encouraged. These protections apply only to opening RDP files, not to connections via the Windows Remote Desktop client, and can be temporarily disabled via a registry setting by admins. Microsoft urges keeping the safeguards enabled, noting that attackers have used rogue RDP files in campaigns (e.g., APT29) to steal data, credentials, or even clipboard contents and smart-card authentication.

France Bets on Linux as it Ditches Windows for Digital Sovereignty
politics6 months ago

France Bets on Linux as it Ditches Windows for Digital Sovereignty

France will move some government systems from Windows to Linux, starting with the Interministerial Directorate for Digital Affairs (DINUM), as part of a broader push for digital sovereignty and reduced reliance on American tech. The plan follows bans on American videoconferencing tools and signals a move toward open-source software amid security and implementation challenges, with policymakers seeking greater control over data, infrastructure, and rollout timelines.

"Mozilla Condemns Microsoft's 'Harmful Designs' to Promote Edge to Windows Users"
technology2 years ago

"Mozilla Condemns Microsoft's 'Harmful Designs' to Promote Edge to Windows Users"

Mozilla has commissioned a report highlighting Microsoft's alleged use of harmful design practices to influence Windows users into using its Edge browser over Google Chrome. The report claims that Microsoft employs tactics such as interruptions during Chrome installation, promoting Edge's benefits, and injecting ads into the search and install process. Mozilla argues that these practices inhibit user choice and competition, calling for regulatory action to restore browser choice and competition across major platforms.

Zero-Click Outlook RCE Exploits: New Details and Disclosures
email-security-vulnerability2 years ago

Zero-Click Outlook RCE Exploits: New Details and Disclosures

Security researchers have revealed technical details about two now-patched security flaws in Microsoft Windows that could be exploited by threat actors to achieve remote code execution on the Outlook email service without any user interaction. The vulnerabilities, CVE-2023-35384 and CVE-2023-36710, were addressed by Microsoft in August and October 2023, respectively. CVE-2023-35384 is a bypass for a critical security flaw that Microsoft patched in March 2023, and it can be used to steal NTLM credentials and conduct a relay attack. The vulnerabilities can be chained together to create a full zero-click remote code execution exploit against Outlook clients. Organizations are advised to use microsegmentation to block outgoing SMB connections to remote public IP addresses and to disable NTLM or add users to the Protected Users security group to mitigate the risks.