Enterprise Security
The latest Enterprise Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2025-10200: Chrome 140 Patches ServiceWorker Use-After-Free, Edge Users Must Update Immediately
Google has shipped a critical patch for a use-after-free vulnerability in the ServiceWorker component of Chromium, tracked as CVE-2025-10200, with the release of Chrome version 140.0.7339.80/81 and...
SAP NetWeaver 10.0-Rated Exploits Eclipse Microsoft's Patch Tuesday as Enterprises Race to Patch
September’s Patch Tuesday delivered a predictable mix of Windows security updates and the usual Office headaches, but for enterprise security teams, the real fire alarm is ringing over SAP...
CVE-2025-55224: Windows Win32K Race Condition Allows Hyper-V Escape and SYSTEM Access
A recently patched vulnerability in the Windows Win32K graphics subsystem allows an authenticated attacker—or a low-privileged process inside a Hyper-V virtual machine—to exploit a race condition...
Critical Office Heap Overflow (CVE-2025-54910) Patched for Windows, Mac Fixes Still Pending
Microsoft has released security updates to patch a critical heap-based buffer overflow in Microsoft Office, tracked as CVE-2025-54910, that could allow attackers to execute arbitrary code after a...
Excel CVE-2025-54901: Patch Now for Critical Memory Disclosure, Mac Users Wait
Microsoft has released emergency security updates to patch a significant information-disclosure vulnerability in Microsoft Excel, tracked as CVE-2025-54901, that can expose sensitive process memory...
Path Equivalence Flaw in Windows MapUrlToZone Lets Attackers Bypass Security Zoning
Microsoft’s March 2025 Patch Tuesday included fixes for a dangerous vulnerability in the Windows MapUrlToZone API that could allow attackers to trick the operating system into treating remote or...
Critical Windows Graphics Race Condition (CVE-2025-53807) Hands Out SYSTEM Access—Urgent Patch Guide
A race condition in the Windows Graphics Component can hand authenticated attackers full SYSTEM privileges, Microsoft disclosed this week. The vulnerability, cataloged as CVE-2025-53807, lurks in the...
Critical Bluetooth Flaw CVE-2025-27490 Patched: Full System Compromise Possible via Airborne Attack
Microsoft’s April 2025 Patch Tuesday included a fix for a critical Bluetooth elevation-of-privilege vulnerability, CVE-2025-27490, that allows an attacker within Bluetooth range to escalate...
Urgent Excel Security Fix: Use-After-Free Bug Opens Door to Code Execution — Mac LTSC Patches Delayed
Microsoft has issued a security advisory for CVE-2025-54903, a critical use-after-free vulnerability in Microsoft Excel that allows an attacker to execute code locally when a victim opens a...
Microsoft Patches Excel Vulnerability CVE-2025-54898: Out-of-Bounds Read Could Allow Code Execution
Microsoft has issued a security update for CVE-2025-54898, an out-of-bounds read vulnerability in Microsoft Excel that could be exploited by attackers to achieve local code execution when a user...
Copilot Studio Now Intercepts Agent Actions for Real-Time Security Vetoes
Microsoft has shifted the security model for its Copilot Studio from passive guardrails to active, inline enforcement. Organizations can now route an AI agent’s planned actions—including prompts,...
Microsoft Tests AI Image Editing in Windows 11 File Explorer—Privacy Questions Remain
Windows Insiders on the bleeding-edge Canary channel are discovering a new context menu that puts generative AI image edits—including background removal, object erasing, and Bing Visual...