Incident Response
The latest Incident Response coverage — news, analysis, and updates from the WindowsNews.AI desk.
ESET Exposes GhostRedirector: China-Aligned Hackers Deploy IIS SEO Fraud and Custom Backdoor on 65 Windows Servers
In June 2025, ESET researchers unearthed a previously unknown threat actor they call GhostRedirector, which had compromised at least 65 Windows servers around the globe. The attackers deployed two...
Actively Exploited TP-Link Router Flaws Land in CISA’s KEV—Windows Networks Face Credential Theft and Remote Takeover
CISA has dropped two TP-Link router vulnerabilities into its Known Exploited Vulnerabilities (KEV) catalog, confirming that attackers are actively chaining credential disclosure and command injection...
ChatGPT's Frontend Meltdown: How a UI Glitch Triggered Mass Outage and an Enterprise AI Wake-Up Call
On September 3, 2025, at 10:23 AM Eastern, OpenAI marked as resolved a ChatGPT service disruption that sent millions of users into a productivity spiral. The outage, which began earlier that morning,...
Exposed appsettings.json Files Unleash 'Master Key' to Azure Tenants via OAuth Token Abuse
A single, publicly exposed appsettings.json file containing Azure Active Directory (now Entra ID) application credentials can act as a master key to an organization’s entire cloud estate, security...
ChatGPT Blank-Screens Global Workforce, Prompting Urgent Shift to Copilot and Gemini
On September 3, 2025, thousands of ChatGPT users opened their browsers to find not answers but blank white spaces where model outputs should have been. OpenAI's flagship chatbot had stumbled into a...
ChatGPT’s September 3 Outage Exposes Single-Provider AI Risks for Business
On September 3, 2025, millions of ChatGPT users opened their browsers to a frustrating sight: error messages and stalled replies. OpenAI's flagship chatbot had suffered a partial outage that...
Critical Bluetooth Flaw in SunPower Inverters Grants Attackers Full Device Control
A newly disclosed vulnerability in SunPower PVS6 solar inverters exposes critical energy infrastructure to takeovers by attackers who merely need to be within Bluetooth range. The U.S. Cybersecurity...
FreePBX Zero-Day Exploited in Wild: CISA Orders Emergency Patching for CVSS 10 RCE
CISA on August 29, 2025, added a critical vulnerability in Sangoma’s FreePBX telephony platform to its Known Exploited Vulnerabilities (KEV) Catalog, warning that attackers have been exploiting the...
Active Directory Disaster Recovery Is a Cybersecurity Emergency—Here’s the Identity-First Playbook
A single corrupted Active Directory forest can lock employees out of every app, revoke access to file shares, break DNS, and sever the sync between on-premises and cloud identities—all within...
Critical ANGLE Use-After-Free Fix in Chrome 139 Forces Urgent Edge and Enterprise Patching
Microsoft has confirmed that a freshly disclosed use-after-free vulnerability in the Chromium ANGLE graphics layer, tracked as CVE-2025-9478, is now resolved in the latest Edge stable channel —...
Patch Now: Delta COMMGR Critical Vulnerabilities Allow Remote Code Execution via .isp Files
Delta Electronics has issued an urgent security advisory and released COMMGR version 2.10.0 to fix two high-severity vulnerabilities that could let attackers execute arbitrary code on industrial...
Phison Finds No Bug, Yet Testers Reproduce Windows 11 NVMe Failures
Phison says it can't reproduce the reported NVMe failures tied to the August 2025 Windows 11 update, but independent test benches continue to document repeatable drive disappearances under heavy...