Enterprise Security
The latest Enterprise Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Zenity's Real-Time Agent Security Hits Azure Marketplace Preview for Copilot Studio
Microsoft Copilot Studio agents now have a dedicated inline security layer that can block prompt injections, data exfiltration, and secrets misuse mid-execution, following Zenity’s expanded...
Copilot Studio Now Lets Security Teams Block Agent Actions in Under One Second
Microsoft has handed enterprise defenders a powerful new capability: the ability to inspect and veto every planned action of an autonomous AI agent before execution, all within a single second....
Edge's SmartScreen Now Uses On-Device AI to Block Scareware Without Phoning Home
Microsoft has armed its Edge browser with a new weapon against online scams: an on-device AI that can detect and disrupt full-screen scareware pages before they trick users into handing over cash or...
Microsoft Copilot’s NFL Verdict: Give the Ball to Marshawn Lynch
Artificial intelligence is now officially on the NFL sideline, and when it replays the one play Seattle fans can never forget—the goal-line pass intercepted in Super Bowl XLIX—it delivers a...
Microsoft Warns of Network-Exploitable Edge Bypass Flaw CVE-2025-53791, Urges Immediate Patching
Microsoft has disclosed CVE-2025-53791, a security feature bypass vulnerability in its Chromium-based Edge browser that can be triggered by an attacker over a network. The advisory, published in the...
Google Rushes Chrome 140 Fix for CVE-2025-9864 V8 Memory Bug, Microsoft Edge Also Patched
Google has released a critical security update for its Chrome browser, patching a high-severity use-after-free vulnerability in the V8 JavaScript engine that could let attackers hijack systems...
CVE-2025-9866: Chrome and Edge Fix CSP Bypass That Could Let Attackers Steal Data via Extensions
A high-severity security flaw in Chromium’s Extensions subsystem allows attackers to bypass Content Security Policy (CSP) protections using a maliciously crafted HTML page, potentially exposing...
Chrome 140 for Android Fixes UI Spoofing Bug That Could Trick Users into Malicious Downloads
Google’s September 2025 stable channel update for Chrome, version 140, patches a UI spoofing vulnerability in the Downloads component that could allow attackers to mislead Android users into...
UK-OpenAI MoU Exposes Tensions in Enterprise AI: UX vs. Governance, Vendor Lock-in vs. Sovereignty
When OpenAI opened ChatGPT to the public at no charge, it did more than ignite a consumer frenzy—it set a ticking clock for every enterprise software vendor. Within two months of its November 2022...
Black Hat Demo Shows Local Admins Hijacking Windows Hello Biometrics, Forcing Identity Reckoning
Security researchers from ERNW, Dr. Baptiste David and Tillmann Osswald, took the stage at Black Hat to demonstrate a practical, low-noise attack against Windows Hello for Business. Dubbed...
Firefox Nightly Now Lets You Chat with Copilot Without Leaving Your Tabs
Firefox Nightly users can now add Microsoft Copilot to their browser's sidebar, bringing the AI assistant's chat, voice, and page summarization capabilities into Mozilla's experimental channel. The...
PowerToys v0.94 Tackles Settings Overload with Fuzzy Search and Hotkey Conflict Alerts
PowerToys v0.94 has arrived, and it’s more than just a routine update—it’s a deliberate push to tame the growing complexity of Windows power-user settings and shortcuts. When a utility suite...