Cybersecurity
The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Discloses Critical RRAS Heap Overflow (CVE-2025-50164) — Patch Now to Block Remote Code Execution
Microsoft has issued a high-severity security advisory for a heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) that could allow unauthenticated attackers to execute...
Microsoft Patches Actively Exploited Windows DWM Use-After-Free Vulnerability CVE-2025-30400
A critical vulnerability in Windows Desktop Window Manager (DWM) gave attackers a direct path to SYSTEM privileges, and Microsoft confirmed it was being exploited in real-world attacks before May...
Microsoft Drops Limited Details on CVE-2025-25006 Exchange Spoofing Bug—Here’s How to Protect Your Network
Microsoft has posted a new Exchange Server vulnerability, CVE-2025-25006, with a terse description that points to a spoofing weakness in how the mail server handles special header elements. The...
CVE-2025-25005: The Windows Vulnerability Shrouded in Uncertainty and What Admins Must Do Now
The discovery of a new Windows vulnerability always triggers a scramble for details, but CVE-2025-25005 has presented an unusual challenge: the Microsoft Security Response Center (MSRC) advisory...
Microsoft Discloses Critical PowerPoint Use-After-Free Flaw, CVE-2025-53761, Enabling Local Code Execution
Microsoft has issued a security advisory for a new use-after-free vulnerability in PowerPoint, tracked as CVE-2025-53761, that allows an unauthorized attacker to execute code locally. The flaw, which...
SharePoint 'ToolShell' Zero-Day Exploited: Critical RCE Patched Amid Active Attacks
Microsoft has released an emergency security update to patch a critical remote code execution (RCE) vulnerability in SharePoint Server that has been actively exploited in the wild. Tracked as...
Microsoft Fixes SQL Server Flaw That Allows Privilege Escalation via SQL Injection
Microsoft’s July 2025 Patch Tuesday release includes a fix for a high-severity SQL injection vulnerability in SQL Server that enables authenticated attackers to escalate privileges and seize...
Dow Cuts SOC Investigation Time, Upskills Analysts with Microsoft Security Copilot
Inside Dow’s Cyber Security Operations Center (CSOC), a simple question has become routine: “Have you asked Copilot?” The 125‑year‑old materials science giant—better known for industrial...
AgentFlayer Unleashed: Zero-Click Chains Turn Enterprise AI Agents into Stealth Insider Threats
At Black Hat USA 2025, Zenity Labs peeled back the curtain on a threat that security teams have long feared but rarely seen weaponized at scale: zero-click prompt injection attacks that silently...
PowerShell 2.0 Removal from Windows 11 24H2 and Server 2025 Begins August 2025
PowerShell 2.0 is finally vanishing from Windows. Microsoft confirmed the legacy runtime will be stripped from Windows 11 version 24H2 starting August 2025, with Windows Server 2025 following in...
Microsoft Sets August–September 2025 Deadline for PowerShell 2.0 Removal from Windows 11 and Server 2025
Microsoft will strip the long-deprecated PowerShell 2.0 engine from Windows 11 version 24H2 in August 2025, and from Windows Server 2025 the following month, closing a chapter that began with the...
Windows 10 End-of-Support Lawsuit Accuses Microsoft of Forcing Upgrades to Cement AI Dominance
A Southern California man has thrown an unexpected wrench into Microsoft's Windows 10 retirement plans, filing a federal lawsuit that seeks to force the tech giant to continue providing free security...