Cybersecurity
The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.
Fortinet fixes 9.8-rated SSL-VPN bug; patch CVE-2023-27997 now.
Fortinet has released critical security updates addressing multiple vulnerabilities in its products, including those commonly used by Windows-based enterprises. These patches come as cybersecurity...
Ivanti Security Updates: Critical Patches for Endpoint Manager and Other Key Products
Ivanti has released a series of critical security updates addressing vulnerabilities across multiple enterprise products, including Endpoint Manager, Application Control Engine, and Avalanche. These...
Critical Security Alert: Vulnerability in Schneider Electric’s Vijeo Designer Exposes Industrial Systems to Risk
A newly discovered vulnerability in Schneider Electric’s Vijeo Designer software has raised alarms across industrial control system (ICS) environments. Tracked as CVE-2024-8306, this critical flaw...
Critical Hitachi Energy FOXMAN-UN Flaws Risk Power Grid Attacks
Hitachi Energy has issued a critical security advisory regarding multiple vulnerabilities in its FOXMAN-UN platform, a widely used industrial control system (ICS) solution. These flaws could allow...
CISA details 42% rise in ICS flaws; legacy systems, cloud risks top 2025 threats
The Cybersecurity and Infrastructure Security Agency (CISA) has released its 2025 Industrial Control Systems (ICS) advisories, highlighting critical vulnerabilities and emerging threats targeting...
78 patches, 12 critical: Microsoft’s January 2025 Patch Tuesday lands with active zero-day exploits.
Microsoft's January 2025 Patch Tuesday has arrived with critical security updates, performance improvements, and notable changes to Windows ecosystems. This month's release addresses 78...
Microsoft Launches Legal Offensive Against Cybercriminal Network Exploiting Azure OpenAI Security
Microsoft Targets Storm-2139: A Global Cybercrime Network Abusing Azure OpenAI Services Microsoft has taken a decisive legal stance against a sophisticated cybercrime syndicate known as Storm-2139,...
FastHTTP tool fuels 300% rise in Microsoft 365 brute-force attacks since Q2 2023.
Microsoft 365 users are facing a new wave of brute-force attacks leveraging the FastHTTP library to bypass security measures. Cybersecurity researchers have identified a sophisticated campaign where...
CISA Flags Critical BeyondTrust and Qlik Sense Flaws Under Active Attack
The Cybersecurity and Infrastructure Security Agency (CISA) has issued critical alerts regarding newly discovered vulnerabilities in BeyondTrust Privileged Remote Access (PRA) and Qlik Sense...
Microsoft Sues Hackers Over Stolen Azure OpenAI API Keys, Sets New Security Precedent
Microsoft has filed a lawsuit against unidentified hackers for allegedly stealing Azure OpenAI API keys, marking a significant escalation in the tech giant's efforts to protect its AI infrastructure....
Microsoft Azure OpenAI Breach: Unveiling Security Vulnerabilities and Their Implications
Introduction The advent of artificial intelligence (AI) has revolutionized industries, offering unprecedented efficiency, automation, and creativity. However, this rapid advancement has also...
Microsoft Files Lawsuit Against Cybercriminals Exploiting Azure AI for Hacking-as-a-Service
Microsoft has launched a landmark legal action against cybercriminals allegedly abusing its Azure AI infrastructure to power hacking-as-a-service operations. The case represents one of the first...