Cybersecurity
The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.
June 2025 Windows Patch Tuesday: Critical Zero-Day Fixes and Legacy Protocol Risks
Microsoft's June 2025 Patch Tuesday arrived with urgent security updates, addressing 67 newly discovered vulnerabilities—including two actively exploited zero-day flaws and multiple critical remote...
June Patch Tuesday: Two Active Zero-Days, Critical Fixes for MSMQ, Edge & Legacy Risks
Every month, Microsoft’s Patch Tuesday looms as a critical date on the IT administrator’s calendar, and this cycle is no exception. Microsoft has sounded the alarm on 66 vulnerabilities, with two...
Critical Microsoft Word Vulnerability (CVE-2025-32717): How to Protect Against Malicious Document Exploits
A newly discovered critical vulnerability in Microsoft Word, tracked as CVE-2025-32717, is being actively exploited in the wild, putting millions of users at risk of remote code execution attacks....
Outlook to Block Two File Types from 2025 as Exploits Like Follina Rise
Microsoft is taking another decisive step in its ongoing battle against cyber threats by announcing that Outlook will block 'library-ms' and 'search-ms' file attachments starting in 2025. This move...
Outlook 2025 Now Blocks Executable Files, Scripts to Thwart Email Malware
Microsoft has taken a significant step forward in email security by expanding its list of blocked file attachments in Outlook 2025. This latest update targets potentially dangerous file types that...
CISA KEV Updates Reveal Critical Exploits in Wazuh and WebDAV: What You Need to Patch Now
The Cybersecurity and Infrastructure Security Agency (CISA) has once again updated its Known Exploited Vulnerabilities (KEV) catalog, spotlighting two critical flaws actively being weaponized in the...
Microsoft June 2025 Patch Tuesday: 75 Flaws, 6 Active Zero-Days, Emergency Fixes
Microsoft's June 2025 Patch Tuesday has arrived with one of the most urgent security update packages in recent memory, putting IT administrators worldwide on high alert. The update addresses 75...
June 2025 Windows Security Patch Tuesday: Critical Zero-Day Fixes & New Features
Microsoft's June 2025 Patch Tuesday has arrived, delivering a critical set of security updates alongside notable feature enhancements for Windows 10, Windows 11, and Windows Server. This month's...
Securing Nuance NDEP: How to Mitigate CVE-2025-47977 XSS Vulnerability
The Nuance Digital Engagement Platform (NDEP), a widely used customer interaction solution, has been found vulnerable to a critical cross-site scripting (XSS) flaw (CVE-2025-47977) that could allow...
CVE-2025-47968: Microsoft AutoUpdate Flaw Exposes Privilege Escalation Risks
A critical vulnerability (CVE-2025-47968) in Microsoft AutoUpdate (MAU) has been uncovered, exposing systems to privilege escalation attacks due to improper input validation. This flaw, affecting...
Visual Studio CVE-2025-47959: Patch Now to Block Command Injection Attacks
Visual Studio users have long enjoyed a robust integrated development environment, complete with advanced debugging capabilities, intelligent code completion, and seamless integration with...
Microsoft Outlook Zero-Click RCE: Patch CVE-2025-47176 Now
In early 2025, cybersecurity researchers uncovered a critical vulnerability in Microsoft Outlook, designated as CVE-2025-47176, which poses severe risks to millions of users worldwide. This remote...