Live
CISA Warns: Rockwell ArmorBlock 5000 Flaws Allow Remote Session Hijack, Score Hits 8.8·MSFT +2.1%Patch for Windows Netlogon DoS Vulnerability Triggers NAS and Samba Issues, Secure Boot Deadlines Loom·NVDA +0.2%Microsoft's CVE-2025-53793 Advisory: Azure Stack Hub Authentication Flaw Exposes Sensitive Data·GOOGL +1.7%CVE-2025-53779: New Kerberos Path Traversal Bug Opens Door to Privilege Escalation—Patch Now·AMZN +1.1%CVE-2025-33057: Microsoft Patches LSASS Null Pointer DoS That Can Crash Domain Controllers·MSFT +2.1%CVE-2025-53138: Windows Server RRAS Vulnerability Leaks Sensitive Memory·NVDA +0.2%Microsoft Patches Critical Use-After-Free in Windows PPP EAP‑TLS, Enabling Local Privilege Escalation·GOOGL +1.7%Microsoft Patches Critical RCE Flaw in IIS Web Deploy – CVE-2025-53772 Threatens Exposed Servers·AMZN +1.1%CISA Warns: Rockwell ArmorBlock 5000 Flaws Allow Remote Session Hijack, Score Hits 8.8·MSFT +2.1%Patch for Windows Netlogon DoS Vulnerability Triggers NAS and Samba Issues, Secure Boot Deadlines Loom·NVDA +0.2%Microsoft's CVE-2025-53793 Advisory: Azure Stack Hub Authentication Flaw Exposes Sensitive Data·GOOGL +1.7%CVE-2025-53779: New Kerberos Path Traversal Bug Opens Door to Privilege Escalation—Patch Now·AMZN +1.1%CVE-2025-33057: Microsoft Patches LSASS Null Pointer DoS That Can Crash Domain Controllers·MSFT +2.1%CVE-2025-53138: Windows Server RRAS Vulnerability Leaks Sensitive Memory·NVDA +0.2%Microsoft Patches Critical Use-After-Free in Windows PPP EAP‑TLS, Enabling Local Privilege Escalation·GOOGL +1.7%Microsoft Patches Critical RCE Flaw in IIS Web Deploy – CVE-2025-53772 Threatens Exposed Servers·AMZN +1.1%

Authentication

The latest Authentication coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 12:05 PM
Latest Most Read Breaking
Sort
5032 · Armorblock

CISA Warns: Rockwell ArmorBlock 5000 Flaws Allow Remote Session Hijack, Score Hits 8.8

Two high-severity vulnerabilities in Rockwell Automation’s ArmorBlock 5000 I/O modules allow attackers to hijack web management sessions without credentials, CISA warned on August 14, 2025. The...

Advertisement
Active Directory · Authentication

CVE-2025-33057: Microsoft Patches LSASS Null Pointer DoS That Can Crash Domain Controllers

Microsoft has released a security update for a vulnerability that allows an attacker with network access to crash the Local Security Authority Subsystem Service (LSASS) and trigger a...

SE Security Desk·48w ago
Authentication · Cve-2025-53138

CVE-2025-53138: Windows Server RRAS Vulnerability Leaks Sensitive Memory

Microsoft's latest security advisory warns of CVE-2025-53138, a newly disclosed information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS). The flaw, rooted in the...

SE Security Desk·48w ago
Authentication · Certificate

Microsoft Patches Critical Use-After-Free in Windows PPP EAP‑TLS, Enabling Local Privilege Escalation

Microsoft has issued a security advisory for CVE‑2025‑50159, a use‑after‑free vulnerability in the Remote Access Point‑to‑Point Protocol (PPP) EAP‑TLS implementation that can allow an...

SE Security Desk·48w ago
Access Control · Authentication

Microsoft Patches Critical RCE Flaw in IIS Web Deploy – CVE-2025-53772 Threatens Exposed Servers

Microsoft has issued a high-priority security advisory for a deserialization vulnerability in its Web Deploy tool that could give authenticated attackers the ability to execute arbitrary code on...

SE Security Desk·48w ago
Auditing · Authentication

Microsoft Fixes SQL Server Flaw That Allows Privilege Escalation via SQL Injection

Microsoft’s July 2025 Patch Tuesday release includes a fix for a high-severity SQL injection vulnerability in SQL Server that enables authenticated attackers to escalate privileges and seize...

SE Security Desk·48w ago
Authentication · Biometrics

Live Hack Exposes Windows Hello Biometric Loophole—Researchers Say Disable It Now

A packed auditorium at Black Hat 2025 in Las Vegas watched in silence as security researcher Tillmann Osswald remotely enrolled his own face onto his colleague’s Windows Hello-protected...

SE Security Desk·49w ago
Account Security · Authentication

Microsoft Passkeys: Leading the Future of Secure, Passwordless Authentication

As technology evolves, the quest for both seamless user experience and robust security in digital authentication has intensified. With attacks on traditional password systems growing ever more...

SE Security Desk·50w ago
Account Compromise · Advanced Threats

The Evolution of Cloud Phishing: Microsoft OAuth Exploitation and AI-Driven Attacks

Phishing campaigns in the cloud era have undergone a fundamental evolution, leveraging both novel attack surfaces and the expanded reach of cloud identity management systems. Nowhere is this...

SE Security Desk·50w ago