Microsoft Security
The latest Microsoft Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Retires Purview Audit (Standard): DLP Migration Deadline March 2025
Microsoft's announcement to retire Purview Audit (Standard) by March 2025 has left many organizations scrambling to transition to Data Loss Prevention (DLP) solutions. This comprehensive guide walks...
Storm-2372 Phishing Bypasses MFA: Device Code Attack Exposes Windows Users
The Storm-2372 phishing campaign has emerged as a sophisticated threat targeting Windows users, exploiting Device Code Authentication vulnerabilities to bypass multi-factor authentication (MFA). This...
February Patch Tuesday: 4 zero-days exploited in wild, 55 bugs fixed including critical NTLM, Excel, DHCP flaws.
Microsoft's February 2025 Patch Tuesday has arrived with critical security updates addressing 55 vulnerabilities across Windows and other Microsoft products, including four zero-day flaws already...
CVE-2025-21400: Critical SharePoint Server RCE Vulnerability - Risks & Mitigation
CVE-2025-21400: SharePoint Server RCE Vulnerability Explained Microsoft has disclosed a critical remote code execution (RCE) vulnerability in SharePoint Server tracked as CVE-2025-21400, which could...
Critical Excel RCE Flaw CVE-2025-21394 Exploited; Microsoft Issues Emergency Patch
Microsoft Excel users face a new critical security threat with the discovery of CVE-2025-21394, a remote code execution (RCE) vulnerability that could allow attackers to take control of affected...
CVE-2025-21359: Critical Windows Kernel Security Vulnerability Explained and Mitigation Steps
Microsoft has issued a critical security alert regarding CVE-2025-21359, a newly discovered vulnerability in the Windows kernel that could allow attackers to execute arbitrary code with system-level...
CVE-2025-21349: Critical Windows Remote Desktop Vulnerability Exposed - What You Need to Know
CVE-2025-21349: New Vulnerability in Windows Remote Desktop Configuration Microsoft has disclosed a critical security vulnerability (CVE-2025-21349) affecting Windows Remote Desktop Services that...
Microsoft CVE-2025-21347: Remote attackers can crash WDS servers with crafted network packets.
CVE-2025-21347: Understanding the DoS Vulnerability in Windows Deployment Services Windows Deployment Services (WDS), a critical component for enterprise network administrators, has been found...
CVE-2025-21223: Critical Windows Telephony Service Vulnerability Exposes Systems to Remote Code Execution
CVE-2025-21223: Urgent Telephony Vulnerability in Windows Exposed Microsoft has issued an emergency security advisory regarding CVE-2025-21223, a critical remote code execution (RCE) vulnerability...
Critical RCE Bug CVE-2025-21240 Hits All Windows—Patch Now
Microsoft has disclosed a critical Windows vulnerability (CVE-2025-21240) affecting the Telephony Service, allowing remote code execution (RCE) on unpatched systems. This zero-day flaw poses...
Microsoft Warns: Critical Windows Telephony Zero-Day Under Active Attack
Microsoft has issued an urgent security alert regarding CVE-2025-21246, a critical remote code execution (RCE) vulnerability affecting Windows Telephony Service. This zero-day flaw, currently being...
CVE-2025-21326: Attackers Exploit Retired IE, Microsoft Urges Emergency Patching
CVE-2025-21326: Critical Internet Explorer Vulnerability Explained Microsoft has issued a critical security alert regarding CVE-2025-21326, a newly discovered remote code execution (RCE)...