Live
Macquarie Government's Azure Practice Targets 26% Cost Cuts for Australian Agencies·MSFT +2.1%Samsung Ditches Free Storage Upgrades for Fold 8 Preorders: What You’ll Pay Now·NVDA +0.2%Samsung Health Assistant Beta Launches in the US: AI Now Turns Your Wearable Data Into Personalized Answers·GOOGL +1.7%Microsoft's Copilot Removal Policy Has a 28-Day Clock—Here's What to Do Instead of Waiting·AMZN +1.1%Microsoft Stock Could Surge to $600 on Azure Capacity Gains and Copilot’s Three-Engine Strategy·MSFT +2.1%Microsoft's AMD Helios Deal Aims to Shatter Azure's AI Capacity Ceiling·NVDA +0.2%New Memory Tech from SK hynix Cuts AI Power Draw by 90.23% — What Windows Users Need to Know·GOOGL +1.7%ASML's Next-Gen Lithography Tool Arrives at Albany—How It Could Power Future Windows Devices·AMZN +1.1%Macquarie Government's Azure Practice Targets 26% Cost Cuts for Australian Agencies·MSFT +2.1%Samsung Ditches Free Storage Upgrades for Fold 8 Preorders: What You’ll Pay Now·NVDA +0.2%Samsung Health Assistant Beta Launches in the US: AI Now Turns Your Wearable Data Into Personalized Answers·GOOGL +1.7%Microsoft's Copilot Removal Policy Has a 28-Day Clock—Here's What to Do Instead of Waiting·AMZN +1.1%Microsoft Stock Could Surge to $600 on Azure Capacity Gains and Copilot’s Three-Engine Strategy·MSFT +2.1%Microsoft's AMD Helios Deal Aims to Shatter Azure's AI Capacity Ceiling·NVDA +0.2%New Memory Tech from SK hynix Cuts AI Power Draw by 90.23% — What Windows Users Need to Know·GOOGL +1.7%ASML's Next-Gen Lithography Tool Arrives at Albany—How It Could Power Future Windows Devices·AMZN +1.1%

Cygnet Vulnerabilities

The latest Cygnet Vulnerabilities coverage — news, analysis, and updates from the WindowsNews.AI desk.

13 stories in view AI assisted desk updated 6:59 AM
Latest Most Read Breaking
Sort
Microsoft Azure · Australian Government

Macquarie Government's Azure Practice Targets 26% Cost Cuts for Australian Agencies

Macquarie Government has launched a co-managed Microsoft Azure practice for Australian federal and state agencies, promising an average 26% reduction in cloud costs through continuous optimization and governance. The move extends the company’s long-standing government cybersecurity business into public cloud services for the first time, offering PROTECTED-ready landing zones, managed security, virtual desktops, and hybrid Azure Local options. Agencies are advised to carefully evaluate the co-management model, validate cost savings, and plan for exit strategies before signing on.

Security

Microsoft 365 Email Routing Alert: Why Your Inline Security Setup Needs a Second Look

Microsoft’s renewed warnings about routing Exchange Online mail through third-party security services have put a spotlight on inline email solutions like Check Point’s. While Check Point argues its architecture is safe, administrators must meticulously verify that their connectors, authentication, and security rules don’t undermine Microsoft 365’s native protections or create new vulnerabilities.

Security Desk·6h ago ·5 min
Security

Endpoint DLP Alerts in Microsoft Purview Will Soon Feed into In-Depth Content Investigations

Microsoft will enable security analysts to launch Data Security Investigations directly from endpoint DLP alerts in Microsoft Purview starting August 2026. The integration lets teams query and collect related files across users and devices, then apply AI-assisted analysis to understand the full scope of a potential data breach. Organizations need to prepare by validating DLP coverage, enabling evidence collection, configuring tight access controls, and running pilots to avoid governance or cost pitfalls.

Security Desk·7h ago ·5 min
Security

Microsoft Purview DLP Targets Your Google Workspace and AWS Data Starting September 2026

Microsoft Purview is expanding Data Loss Prevention and auto-labeling to Google Workspace, Box, Dropbox, Salesforce, ServiceNow, AWS, and Cisco Webex. Preview in July 2026 and general availability in September 2026 will let organizations enforce consistent policies across non-Microsoft clouds, but connector capabilities will vary. Administrators must prepare a migration from Defender for Cloud Apps file policies, which retire in January 2027.

Security Desk·7h ago ·5 min
Advertisement
Microsoft Purview · DLP

Microsoft Purview’s File Quarantine: Sensitive Docs Will Be Plucked from SharePoint and OneDrive This July

Microsoft Purview's new File Quarantine action for SharePoint and OneDrive, rolling out globally in July 2026, physically removes sensitive files that violate DLP policies and replaces them with a tombstone message. This article explains how it works, why it's a major shift from simple blocking, and offers practical guidance for administrators to prepare and deploy the feature safely.

SE Security Desk·7h ago
Cloud Security · Government Cloud

Macquarie Government Unveils Managed Azure for Australian Agencies as New Cloud Policy Takes Hold

Macquarie Government has launched a comprehensive managed Azure practice for Australian federal and state agencies, offering infrastructure, security, virtual desktops, and data analytics under one roof. The launch aligns with the new whole-of-government cloud computing policy and addresses critical gaps in governance, cyber security, and AI readiness. Agencies gain a path to disciplined cloud operations, but must negotiate clear ownership, exit plans, and retain internal skills to avoid long-term dependency.

SE Security Desk·8h ago
Windows 11 · Insider Preview

Windows 11 Experimental Build Brings Braille Out-of-Box Setup, Tightens Cloud Session Security

Windows 11 Insider Preview Build 28120.2546 rolls out to the Experimental (26H1) channel with plug-and-play HID braille support in Narrator, a smart-card removal policy for Entra-authenticated virtual desktops, Voice Access in Portuguese and Korean, gamepad navigation in Quick Settings, and other fixes. The update may appear minor but delivers meaningful gains for accessibility users, IT admins, and handheld PC gamers.

SE Security Desk·8h ago ·1 views
Microsoft Account Security · Xbox Account Recovery

Xbox Hack Victims Finally Get a Lifeline: Microsoft Promises Human Review After Years of Broken Support

Microsoft is under intense pressure to fix its broken support for hacked Xbox and Microsoft accounts, with internal sources revealing a review that could finally deliver human-led recovery processes. After a content creator’s viral ordeal exposed the system’s failures, the company is promising to honor user trust and keep them connected to years of purchases and personal data. The article details what’s changing, who’s at risk, how we arrived here, and specific steps victims and proactive users should take immediately.

SE Security Desk·8h ago
ConsentFix · Microsoft 365 Security

Drag-and-Drop Attack Steals Microsoft 365 Access After You Pass MFA

ConsentFix uses a deceptively simple drag-and-drop trick to steal Microsoft 365 OAuth tokens even after users complete MFA. This analysis explains the attack chain, what attackers can do with stolen access, why MFA alone can't stop it, and how users and admins should respond immediately.

SE Security Desk·11h ago
Authentication Bypass · Cve-2026-56451

Critical Siemens Opcenter X Bug Lets Attackers Forge Admin Tokens, CVSS 10 — Patch V2604 Now

Siemens has released an emergency patch for Opcenter X V2604 to fix a critical JWT authentication bypass (CVE-2026-56451, CVSS 10) that allows unauthenticated attackers to forge tokens and impersonate any user, including administrators. Affected versions earlier than V2604 must be updated immediately; there is no workaround. Administrators should also review network exposure, user accounts, and integration logs for signs of compromise.

SE Security Desk·12h ago
Factorytalk Services Platform · Industrial Cybersecurity

Your FactoryTalk Directory Might Be Trusting Forged Tokens — Here’s the Fix

Rockwell Automation has patched a critical JWT authentication bypass (CVE-2026-10714) in FactoryTalk Services Platform 6.60 that let a low-privilege user impersonate any other user. The flaw, found during internal testing, allows forged tokens by setting the algorithm to “none.” All affected organizations should apply the patch immediately, review configuration changes, and harden their identity validation pipelines.

SE Security Desk·12h ago
Siemens CADRA · Security Advisory

Why Patching to CADRA V2511 Alone Won’t Secure Your Engineering Workstation

Siemens' CADRA V2511 update fixes seven severe zlib vulnerabilities but leaves three additional flaws unpatched across all versions, including a known-exploited V8 type-confusion bug. This analysis explains the dual threat, why engineering workstations are especially exposed, and the concrete steps users and enterprises must take beyond patching—such as web isolation, file controls, and network segmentation—to protect proprietary design data.

SE Security Desk·12h ago
Industrial Cybersecurity · Rockwell Automation

Urgent: Rockwell Patches Three Studio 5000 Vulnerabilities—Check Your Version Now

Rockwell Automation has released patches for three security flaws in Studio 5000 Logix Designer that could allow an attacker with local access or via a malicious project file to write files anywhere and execute code. Affecting versions 32 through 36, the fixes require precise upgrades; admins must verify their exact build and apply compatible patches to avoid operational disruption.

SE Security Desk·12h ago ·2 views