Infosec
The latest Infosec coverage — news, analysis, and updates from the WindowsNews.AI desk.
How CVE-2025-53148 Can Leak Your VPN Secrets: Windows RRAS Patch and Mitigation Guide
Microsoft’s latest Patch Tuesday brought to light CVE-2025-53148, a serious information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS). The flaw, categorized as a...
Microsoft-Backed Capture the Flag Competition Boosts Thailand's Cybersecurity Resilience
In an era where digital threats are escalating at an unprecedented pace, Thailand has emerged as a proactive player in fortifying its cybersecurity defenses. A significant milestone in this endeavor...
Microsoft 365 PDF Export Flaw: LFI Vulnerability Exposes Sensitive Data
Microsoft 365's PDF export functionality recently suffered a critical Local File Inclusion (LFI) vulnerability, allowing attackers to access sensitive server-side data. This vulnerability,...
Critical Windows Vulnerability CVE-2025-49694: Risks, Mitigation, and Best Practices
A newly discovered critical vulnerability, CVE-2025-49694, in Microsoft's Brokering File System (BrokerFS) has sent shockwaves through the cybersecurity community. This flaw, which affects multiple...
Microsoft Secure Boot Vulnerability CVE-2024-28923: What You Need to Know
Microsoft's Secure Boot feature, a critical component of Windows security, has come under scrutiny with the disclosure of CVE-2024-28923. This vulnerability, classified as a "Secure Boot Security...
EchoLeak CVE-2025-32711: Protecting Microsoft 365 Copilot from Zero-Click AI Attacks
In early 2024, cybersecurity researchers uncovered a critical vulnerability in Microsoft 365 Copilot, designated as CVE-2025-32711 and nicknamed "EchoLeak." This zero-click exploit could allow...
CVE-2025-32711: EchoLeak zero-click flaw in M365 Copilot lets emails exfiltrate data
In June 2025, cybersecurity researchers uncovered a critical zero-click vulnerability (CVE-2025-32711) in Microsoft 365 Copilot, marking one of the most severe AI-assisted security flaws to date....
CVE-2025-33067: Critical Windows Task Scheduler Privilege Escalation Exploit Explained
Microsoft's Windows Task Scheduler, a fundamental system component responsible for automating tasks, has been found vulnerable to a dangerous privilege escalation flaw (CVE-2025-33067). This local...
Windows 11 Flaws Exposed in 3-Day Pwn2Own Berlin Hacking Event
Introduction The Pwn2Own Berlin 2025 competition, held from May 15 to 17 at the OffensiveCon conference in Berlin, Germany, showcased the prowess of ethical hackers in uncovering zero-day...
Russian Hackers Exploit OAuth 2.0 to Compromise Microsoft 365 Accounts in 2025
Introduction In early 2025, cybersecurity researchers uncovered a series of sophisticated attacks orchestrated by Russian-linked threat actors targeting Microsoft 365 accounts. These adversaries...
Exploiting Trust: How Russian Hackers Hijacked Microsoft 365 Accounts via OAuth 2.0 in 2023
Introduction In 2023, cybersecurity researchers uncovered a series of sophisticated attacks orchestrated by Russian state-sponsored hackers targeting Microsoft 365 accounts. These adversaries...
PowerShell scripts now drive 70% of stealthy cyber attacks, evading traditional defenses
Introduction In today's digital landscape, cyber threats are evolving rapidly, with attackers increasingly leveraging script-based malware to execute sophisticated and stealthy attacks. Unlike...