Enterprise Security
The latest Enterprise Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Power Pages Studio Now Lets You Turn Web Forms into AI Copilot Agents Instantly
A new preview capability in Microsoft Power Pages is bridging the gap between static web forms and conversational AI agents, promising to slash weeks of custom integration work into minutes of...
Microsoft Opens Windows Update to Third-Party Apps as Office Hours Tackles IT's Toughest 2025 Challenges
Microsoft is quietly testing a major expansion of Windows Update that will allow any third-party application or driver to be patched through the same built-in mechanism used for OS updates. The...
Leading GenAI Browser Assistants Found Hoovering Up Social Security Numbers, Medical Data Without Consent
A sweeping new audit of the most popular generative AI browser assistants reveals that several widely used extensions silently capture and transmit highly sensitive information from ordinary web...
Tenable AI Exposure Debuts at Black Hat to Tackle Generative AI’s Hidden Attack Surface
Tenable today took the wraps off Tenable AI Exposure, a new module within its Tenable One exposure management platform designed to help enterprises discover, prioritize, and govern risks introduced...
Microsoft’s August Patches Slam Shut 107+ Holes, Including Public Kerberos Flaw and Critical GDI+ RCE
On August 12, 2025, Microsoft’s monthly Patch Tuesday arrived with a payload heavy enough to keep IT admins working through the night. The security slate covers at least 107 distinct...
ChatGPT Gets Gmail and Calendar Access: OpenAI's Productivity Play Raises Security Flags
OpenAI has quietly breached the walls of Google Workspace. Starting this week, ChatGPT Pro users can grant the AI direct access to their Gmail inboxes, Google Calendars, and Google Contacts—turning...
Windows 10 August Update Opens ESU Enrollment, Hardens Secure Boot Against Rollback
Microsoft’s cumulative update KB5063709, released on August 12, 2025, arrives at a critical juncture for Windows 10 users. With the end-of-support deadline looming on October 14, 2025, the patch...
Critical Word Flaw CVE-2025-53784 Lets Attackers Hijack PCs via Malicious Docs — Patch Immediately
Microsoft’s latest security advisory warns of a memory-corruption flaw in Word—CVE-2025-53784—that hands attackers a local-code-execution foothold from nothing more than a booby-trapped...
WSL 2.5.10 Fixes TOCTOU Bug: Microsoft Acts Fast on CVE-2025-53788 Privilege Escalation
Microsoft released an out-of-band Windows Subsystem for Linux (WSL) update on August 6, 2025, patching a local elevation-of-privilege vulnerability that could let attackers break out of WSL2...
Unverified GDI+ RCE Vulnerability CVE-2025-53766 Prompts Urgent Patch Verification Call
Microsoft’s Security Update Guide has quietly listed a new vulnerability tracked as CVE-2025-53766, describing a heap-based buffer overflow in the GDI+ graphics library that could allow remote code...
New AFD.sys Use-After-Free (CVE-2025-53147) Demands Immediate Patching as Kernel Exploit Chains Resurface
A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) tracked as CVE-2025-53147 allows a local attacker to escalate privileges to SYSTEM, Microsoft disclosed...
Patch Now: CVE-2025-53140 Kernel Transaction Manager Use-After-Free Enables Local Privilege Escalation on Windows
Microsoft has released a security update for CVE-2025-53140, a use-after-free vulnerability in the Windows Kernel Transaction Manager (KTM) that allows an authorized local attacker to elevate...