Incident Response
The latest Incident Response coverage — news, analysis, and updates from the WindowsNews.AI desk.
AI Agents Get Corporate IDs: Inside Microsoft and Workday’s Landmark Integration
Enterprise AI agents are about to get their own set of corporate credentials. Microsoft and Workday have quietly stitched together a system that assigns verified, directory-backed identities to...
Outlook Outage Timeline: How Microsoft Restored Service After 14-Hour Exchange Online Failure
Microsoft engineers have restored the majority of degraded infrastructure after a 14-hour Outlook and Exchange Online outage that left North American users locked out of email, calendars, and...
48-Hour Exchange Hybrid Free/Busy Blackout Hits Unprepared Tenants September 16
At 07:00 UTC on September 16, 2025, Microsoft will flip a switch that breaks free/busy lookups, MailTips, and profile picture sharing between on-premises Exchange and Exchange Online for any hybrid...
Windows 10 Still Runs on 53% of PCs: Your Urgent Migration Roadmap Before October 14
More than half of the world’s PCs—53% to be precise—are still running Windows 10, a staggering statistic just weeks before Microsoft officially retires the operating system on October 14, 2025....
How Azure DDoS Protection Absorbed a 3.47 Tbps Attack: Per-IP ML, Global Scrubbing, and What IT Teams Must Do Next
In late 2021, Microsoft's networks absorbed a massive 3.47 Tbps UDP reflection attack—among the largest ever recorded—on behalf of an Azure customer in Asia. This single incident, which also...
CVE-2025-10200: Chrome 140 Patches ServiceWorker Use-After-Free, Edge Users Must Update Immediately
Google has shipped a critical patch for a use-after-free vulnerability in the ServiceWorker component of Chromium, tracked as CVE-2025-10200, with the release of Chrome version 140.0.7339.80/81 and...
CISA Flags Active Exploitation of Critical DELMIA Apriso RCE Vulnerability
CISA has added CVE-2025-5086, a critical deserialization of untrusted data vulnerability in Dassault Systèmes’ DELMIA Apriso, to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence...
Siemens, Schneider, Daikin ICS Flaws Could Let Attackers Remotely Cripple Operations
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on September 11, 2025, released eleven industrial control systems (ICS) advisories detailing urgent security defects in Siemens,...
Microsoft Sentinel UEBA Now Ingests AWS, GCP, Okta Logs for AI-Driven Threat Detection
Microsoft has quietly rolled out a major update to its cloud-native SIEM, Microsoft Sentinel, significantly expanding the data sources its User and Entity Behavior Analytics (UEBA) engine can digest....
Vendor Won't Fix Daikin Gateway Pre-Auth Password Reset Bug—Public Exploit Code Heightens Risk for Energy Sector
A critical pre-authentication password reset vulnerability in Daikin Security Gateways, tracked as CVE-2025-10127, has entered a dangerous phase: public proof-of-concept exploit code is circulating,...
Windows OT Security Alert: Siemens Flaw CVE-2025-40757 Leaks Device Databases Over BACnet
A newly disclosed vulnerability in Siemens APOGEE PXC and TALON TC building automation controllers allows unauthenticated attackers to pull encrypted database files directly over the BACnet protocol,...
Zero-Click AgentFlayer Exploits Redefine Enterprise AI Security as Zenity Earns Gartner Nod
Zenity’s designation as a 2025 Gartner Cool Vendor for Agentic AI Trust, Risk and Security Management (TRiSM) coincides with the public disclosure of “AgentFlayer”—a class of zero-click...