Live
How CVE-2025-53148 Can Leak Your VPN Secrets: Windows RRAS Patch and Mitigation Guide·MSFT +2.1%Microsoft-Backed Capture the Flag Competition Boosts Thailand's Cybersecurity Resilience·NVDA +0.2%Microsoft 365 PDF Export Flaw: LFI Vulnerability Exposes Sensitive Data·GOOGL +1.7%Critical Windows Vulnerability CVE-2025-49694: Risks, Mitigation, and Best Practices·AMZN +1.1%Microsoft Secure Boot Vulnerability CVE-2024-28923: What You Need to Know·MSFT +2.1%EchoLeak CVE-2025-32711: Protecting Microsoft 365 Copilot from Zero-Click AI Attacks·NVDA +0.2%CVE-2025-32711: EchoLeak zero-click flaw in M365 Copilot lets emails exfiltrate data·GOOGL +1.7%CVE-2025-33067: Critical Windows Task Scheduler Privilege Escalation Exploit Explained·AMZN +1.1%How CVE-2025-53148 Can Leak Your VPN Secrets: Windows RRAS Patch and Mitigation Guide·MSFT +2.1%Microsoft-Backed Capture the Flag Competition Boosts Thailand's Cybersecurity Resilience·NVDA +0.2%Microsoft 365 PDF Export Flaw: LFI Vulnerability Exposes Sensitive Data·GOOGL +1.7%Critical Windows Vulnerability CVE-2025-49694: Risks, Mitigation, and Best Practices·AMZN +1.1%Microsoft Secure Boot Vulnerability CVE-2024-28923: What You Need to Know·MSFT +2.1%EchoLeak CVE-2025-32711: Protecting Microsoft 365 Copilot from Zero-Click AI Attacks·NVDA +0.2%CVE-2025-32711: EchoLeak zero-click flaw in M365 Copilot lets emails exfiltrate data·GOOGL +1.7%CVE-2025-33067: Critical Windows Task Scheduler Privilege Escalation Exploit Explained·AMZN +1.1%

Infosec

The latest Infosec coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 11:52 PM
Latest Most Read Breaking
Sort
Cve-2025-53148 · Detection

How CVE-2025-53148 Can Leak Your VPN Secrets: Windows RRAS Patch and Mitigation Guide

Microsoft’s latest Patch Tuesday brought to light CVE-2025-53148, a serious information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS). The flaw, categorized as a...

Advertisement
Cve-2024-28923 · Cyber Threats

Microsoft Secure Boot Vulnerability CVE-2024-28923: What You Need to Know

Microsoft's Secure Boot feature, a critical component of Windows security, has come under scrutiny with the disclosure of CVE-2024-28923. This vulnerability, classified as a "Secure Boot Security...

SE Security Desk·57w ago
Ai Security · Ai Vulnerabilities

EchoLeak CVE-2025-32711: Protecting Microsoft 365 Copilot from Zero-Click AI Attacks

In early 2024, cybersecurity researchers uncovered a critical vulnerability in Microsoft 365 Copilot, designated as CVE-2025-32711 and nicknamed "EchoLeak." This zero-click exploit could allow...

AI AI & Copilot Desk·57w ago
Ai Risks · Ai Security

CVE-2025-32711: EchoLeak zero-click flaw in M365 Copilot lets emails exfiltrate data

In June 2025, cybersecurity researchers uncovered a critical zero-click vulnerability (CVE-2025-32711) in Microsoft 365 Copilot, marking one of the most severe AI-assisted security flaws to date....

AI AI & Copilot Desk·57w ago
Cve-2025-33067 · Cybersecurity

CVE-2025-33067: Critical Windows Task Scheduler Privilege Escalation Exploit Explained

Microsoft's Windows Task Scheduler, a fundamental system component responsible for automating tasks, has been found vulnerable to a dangerous privilege escalation flaw (CVE-2025-33067). This local...

SE Security Desk·58w ago
Ai Security · Ai Vulnerabilities

Windows 11 Flaws Exposed in 3-Day Pwn2Own Berlin Hacking Event

Introduction The Pwn2Own Berlin 2025 competition, held from May 15 to 17 at the OffensiveCon conference in Berlin, Germany, showcased the prowess of ethical hackers in uncovering zero-day...

AI AI & Copilot Desk·61w ago
Account Compromise · Authorized Access

Russian Hackers Exploit OAuth 2.0 to Compromise Microsoft 365 Accounts in 2025

Introduction In early 2025, cybersecurity researchers uncovered a series of sophisticated attacks orchestrated by Russian-linked threat actors targeting Microsoft 365 accounts. These adversaries...

SE Security Desk·64w ago
Account Hijacking · Cloud Security

Exploiting Trust: How Russian Hackers Hijacked Microsoft 365 Accounts via OAuth 2.0 in 2023

Introduction In 2023, cybersecurity researchers uncovered a series of sophisticated attacks orchestrated by Russian state-sponsored hackers targeting Microsoft 365 accounts. These adversaries...

SE Security Desk·64w ago
Av Bypass Techniques · Cyber Defense

PowerShell scripts now drive 70% of stealthy cyber attacks, evading traditional defenses

Introduction In today's digital landscape, cyber threats are evolving rapidly, with attackers increasingly leveraging script-based malware to execute sophisticated and stealthy attacks. Unlike...

SE Security Desk·64w ago