Live
Microsoft Gave Outlook Its Own Browser Setting—Here’s How to Take Control·MSFT +2.1%Stop Installing Random USB Drivers: Microsoft's Official Tools Fix Problems Faster and Safer·NVDA +0.2%Why Your Windows 11 PC Can't Find Your Device and How to Get It Working Again·GOOGL +1.7%Microsoft Edge's Ad Blocker Misses Most Ads. Here's What Actually Works.·AMZN +1.1%Windows 11’s Enhanced Sign-in Security Is Confusing Users – Here’s How to Fix Your Biometric Login·MSFT +2.1%Weak Microsoft 365 Governance Means AI Will Expose Your Overshared Files, Experts Warn·NVDA +0.2%Microsoft Dynamics 365 Now Lets AI Agents Act Inside Your ERP — Under Strict Control·GOOGL +1.7%Microsoft 365 Outage Sprawls Across Teams, SharePoint, OneDrive—Partial Recovery Underway·AMZN +1.1%Microsoft Gave Outlook Its Own Browser Setting—Here’s How to Take Control·MSFT +2.1%Stop Installing Random USB Drivers: Microsoft's Official Tools Fix Problems Faster and Safer·NVDA +0.2%Why Your Windows 11 PC Can't Find Your Device and How to Get It Working Again·GOOGL +1.7%Microsoft Edge's Ad Blocker Misses Most Ads. Here's What Actually Works.·AMZN +1.1%Windows 11’s Enhanced Sign-in Security Is Confusing Users – Here’s How to Fix Your Biometric Login·MSFT +2.1%Weak Microsoft 365 Governance Means AI Will Expose Your Overshared Files, Experts Warn·NVDA +0.2%Microsoft Dynamics 365 Now Lets AI Agents Act Inside Your ERP — Under Strict Control·GOOGL +1.7%Microsoft 365 Outage Sprawls Across Teams, SharePoint, OneDrive—Partial Recovery Underway·AMZN +1.1%

Cve 2026 40406

The latest Cve 2026 40406 coverage — news, analysis, and updates from the WindowsNews.AI desk.

13 stories in view AI assisted desk updated 6:31 PM
Latest Most Read Breaking
Sort
Account Security · Sign-in Options

Windows 11’s Enhanced Sign-in Security Is Confusing Users – Here’s How to Fix Your Biometric Login

Windows 11’s Enhanced Sign-in Security (ESS) is blocking many external biometric devices, but the fix is a simple toggle in Settings—once you know which label to look for on your version. This guide walks through managing PINs, fingerprints, face recognition, passkeys, and password recovery on Windows 11 and 10, explaining the security trade-offs and offering a practical checklist to avoid lockouts.

Security

A Phishing Empire Fell, and Now the Calls Are Coming: Inside Microsoft's Q2 2026 Security Shakeup

Microsoft's disruption of the Tycoon2FA phishing platform slashed its attacks by 92% in Q2 2026, but attackers quickly pivoted to Microsoft Teams vishing, which now occurs at ten times the mid-2025 rate. This in-depth analysis explains the shifting threat landscape, the rise of calendar invite and multi-stage phishing, and offers seven concrete defense steps for organizations and Windows users.

Security Desk·31m ago ·5 min
Security

August 2026 KMS Alert: Why Your Windows Activation Server Now Needs a TPM

Starting in August 2026, Windows Server 2025 will display readiness alerts for a new KMS Hardware-Secured model that requires TPM 2.0 and Secure Boot. Microsoft plans to make TPM attestation mandatory for KMS hosts in a future Windows Server release, so IT administrators should inventory their activation servers and ensure hardware compliance now.

Security Desk·2h ago ·5 min
Security

Russia's LAUNDRY BEAR Hackers Steal 90 Days of Email with One-Preview Zimbra Exploit

A Russian state-sponsored hacking group is exploiting a Zimbra webmail vulnerability that steals 90 days of email, the organization directory, and authentication material when a user simply views a malicious message. Patches for CVE-2025-66376 are available in Zimbra 10.0.18 and 10.1.13. Organizations must update immediately, hunt for signs of compromise in logs and browser storage, revoke suspicious app passwords, and strengthen monitoring for future attacks.

Security Desk·3h ago ·5 min
Advertisement
KMS · TPM Attestation

Windows Volume Activation Goes Hardware-Secured: What Microsoft’s KMS TPM Attestation Means for Your Servers

Microsoft is introducing TPM attestation for KMS hosts starting with a readiness check in Windows Server 2025 in August 2026. The hardware-secured KMS will become mandatory with the next Windows Server LTSC release, requiring IT administrators to audit existing servers, verify TPM and firmware health, and plan hardware upgrades to avoid activation disruptions.

SE Security Desk·6h ago
KMS Activation · TPM Attestation

Microsoft Will Require TPM-Based Attestation for KMS Hosts: August 2026 Readiness Check Kicks Off Transition

Microsoft will require TPM-based hardware attestation for KMS activation hosts, starting with readiness checks in Windows Server 2025 in August 2026 and making it mandatory in the next LTSC release. IT administrators need to inventory their KMS infrastructure, assess hardware compatibility, and prepare for potential upgrades or changes to virtual hosts.

SE Security Desk·7h ago
Android 17 · Google Tensor

Google ends Pixel 6 and 6 Pro support: Your final Android 17 update plan

Google has confirmed that the Pixel 6 and Pixel 6 Pro will not receive the Android 17 QPR2 update, ending official support after the stable QPR1 release expected in September 2026. The phones will continue to work and integrate with Windows via Phone Link, but the loss of security patches after October 2026 means owners should plan to either repurpose the device, use it with caution, or upgrade to a newer phone for sensitive tasks.

SE Security Desk·8h ago ·1 views
Enterprise Security · Kms Activation

Microsoft to Require TPM Attestation for Enterprise Windows Activation Servers

Microsoft is introducing a mandatory hardware-backed trust requirement for KMS hosts, the servers that handle volume activation for Windows in enterprises. A readiness phase in Windows Server 2025 will alert IT admins to whether their activation infrastructure meets the new TPM attestation standards, ahead of full enforcement in the next Windows Server LTSC release. Organizations should audit their KMS hosts now to avoid last-minute compliance hurdles.

SE Security Desk·10h ago ·1 views
CVE-2026-54171 · Excon

Excon 1.5.0 Patches Credential Leak: Upgrade Your Ruby HTTP Client Now

A security flaw in Excon, a popular Ruby HTTP client, could leak sensitive headers like API keys and session cookies when automatically following redirects. The fixed version 1.5.0 is available, and developers should upgrade immediately to prevent credential disclosure. The update expands header redaction and removes risky cookie-capture middleware.

SE Security Desk·10h ago
Remote Access · Teamviewer

Remote Access in 2026: TeamViewer Tops Free, RemotePC Wins for Business, and Scammers Are Waiting

PCMag's 2026 remote access software roundup highlights TeamViewer as the best free personal tool, RemotePC as the top value for small businesses, and Zoho Assist as the go-to free solution for commercial use. However, the guide emphasizes that no single tool fits all and warns Windows users about the surging threat of tech support scams. Practical advice helps readers match a tool to their specific scenario—home user, freelancer, IT admin—and lock it down with security steps.

SE Security Desk·11h ago
Smart App Control · Windows 11

Windows 11's Smart App Control Lockout Isn't a Bug—It's a Design Choice. Here's What to Do About It.

Smart App Control's greyed-out toggle in Windows 11 is usually not a bug. It's a deliberate state caused by in-place upgrades, compatibility decisions, or device management. This article explains the real reasons the feature locks, separates normal behavior from glitches, and outlines when a Windows reset is the only reliable fix.

SE Security Desk·13h ago
Android Security · Google Play Protect

Google’s Built-In Malware Shield Blocked 266 Million Sideloads in 2025. Here’s Why You Should Leave It On.

Google’s 2025 security data shows Play Protect blocked 266 million risky sideload attempts and detected 27 million new malicious apps, underscoring that sideloading is the dominant malware vector on Android. The article explains how the service works, who is most affected by disabling it, and how to sideload safely without turning off this critical layer of defense.

SE Security Desk·15h ago
Windows Security · Tech Support Scams

Full-Screen Fakeout: The Browser Scam Posing as a Windows Update—and the One Shortcut That Kills It

A surge of full-screen browser scams is tricking Windows users into calling fake support lines or downloading malware by impersonating legitimate Windows Update screens. Real updates never appear through a browser pop-up, don’t show phone numbers, and don’t demand immediate action. The article details how to recognize the scam, escape safely using keyboard shortcuts, verify actual system updates, clean any leftover browser permissions or malicious downloads, and lock down protections for the future.

SE Security Desk·21h ago