Cybersecurity
The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.
Sophos and Rubrik Erase the Gap Between Threat Detection and Recovery for Microsoft 365
Black Hat USA 2025 witnessed the unveiling of a solution that could redefine how security teams respond to ransomware and data loss within Microsoft 365. Sophos and Rubrik announced a deep...
Sophisticated Microsoft 365 Phishing Attacks Exploit SVG Images and Trusted Tools to Steal Credentials
A new wave of phishing attacks targeting Microsoft 365 users is bypassing conventional email filters by weaponizing SVG image files and repurposing legitimate security tools as cloaking devices. The...
Exchange Hybrid Bug Lets Attackers Quietly Escalate to Cloud Admin — Patch Now
A single compromise on a dusty, overlooked Exchange Server can now silently hand an attacker the keys to your entire Microsoft 365 kingdom — with no alarm raised and no audit trail left behind....
Poisoned Calendars, Hijacked Chips, and Stealthy Phishing: Inside the Latest Cybersecurity Onslaught
A single poisoned Google Calendar invite can now raise your smart blinds and start a Zoom call without your consent. That unsettling reality emerged at this year’s Black Hat conference, where...
WSL 2.5.10 Lands: Microsoft’s Secret Security Patch for Windows 11 Explained
Microsoft shipped a terse, single-line update to the Windows Subsystem for Linux on January 15, 2025. Version 2.5.10 of WSL arrived through the Microsoft Store with no fanfare, no CVE identifiers,...
CISA Alerts to Critical EG4 Inverter Flaws That Expose Solar Infrastructure to Remote Sabotage
A cluster of high-severity vulnerabilities in every major EG4 Electronics solar inverter model has set off alarm bells across the global energy sector, with the U.S. Cybersecurity and Infrastructure...
Four Yealink IP Phone Vulnerabilities Expose Enterprise VoIP to Brute-Force and Certificate Attacks
Four newly disclosed security vulnerabilities in Yealink’s widely deployed IP phones and cloud-based Redirect and Provisioning Service (RPS) have thrust business communications security into urgent...
Critical Authentication Bypass in Burk ARC Solo Exposes Broadcast Systems to Remote Takeover
A critical vulnerability in Burk Technology's ARC Solo remote site controller allows attackers to change the device password without any credentials, enabling full device takeover and raising alarms...
CISA Drops 10 ICS Advisories: Flaws Threaten Delta, JCI, EG4 Inverters and Critical Infrastructure
A flood of industrial vulnerabilities hit the cybersecurity landscape last week as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) dropped ten Industrial Control Systems (ICS)...
After Year-Long Silence, Dreame Patches Smart Home Apps Vulnerable to Credential-Theft Attacks
Dreame Technology has finally released a patch for its popular smart home applications after researchers exposed a certificate validation flaw that left millions of users defenseless against...
Rockwell Automation Patches Three High-Severity Arena Simulation Bugs Poised to Cripple Critical Manufacturing
Three newly disclosed vulnerabilities in Rockwell Automation’s Arena simulation software have shaken the industrial security landscape, exposing global manufacturers to file-based attacks that can...
Critical 8.4 CVSS Flaw in Johnson Controls FX Controllers Threatens Building Automation Systems Worldwide
Critical infrastructure operators worldwide are scrambling to apply emergency patches after a dangerous new vulnerability was disclosed in Johnson Controls’ FX80, FX90, and FX Server platforms....