Security Defaults
The latest Security Defaults coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2023-31486: How HTTP::Tiny's Insecure Defaults Threatened Global Supply Chains
A seemingly minor security oversight in a fundamental Perl module has exposed the fragility of modern software supply chains, revealing how a single insecure default can propagate vulnerabilities...
Azure Ships One-Click Kubernetes: AKS Automatic Now Generally Available
Microsoft has flipped the switch on general availability for Azure Kubernetes Service (AKS) Automatic, a fully managed cluster mode that ships with hardened security, autoscaling, and observability...
Senator Wyden Demands FTC Investigation Into Microsoft’s Insecure Defaults Following Ascension Ransomware Attack
A US Senator is demanding a federal investigation into Microsoft’s security practices after default system configurations were blamed for a devastating ransomware attack that paralyzed one of...
Copilot Studio Now Lets Security Teams Block Agent Actions in Under One Second
Microsoft has handed enterprise defenders a powerful new capability: the ability to inspect and veto every planned action of an autonomous AI agent before execution, all within a single second....
SQL Server 2025 RC0 Lands with Native Vector Search, JSON, and Mandatory Encryption
SQL Server 2025’s first release candidate arrived August 22, 2025, and it’s a clear signal that Microsoft intends to keep its flagship database engine not just relevant but foundational for the...
Microsoft's SQL Server 2025 RC0 Arrives: Ubuntu 24.04, TLS 1.3, and Docker Caveats
Microsoft has shipped the first public release candidate of SQL Server 2025, delivering two long-awaited changes for teams that mix Windows infrastructure with Linux development: official support for...
Microsoft Store Removes App Update Off Switch, Imposes Pause-Only Model
Microsoft has quietly stripped away a decade-old user control in the Microsoft Store, eliminating the permanent toggle for automatic app updates and replacing it with a mandatory pause system that...
Microsoft Opens Gated Preview for Windows 365 Reserve: 10-Day Cloud PCs for Emergencies
Microsoft has started inviting organizations to trial Windows 365 Reserve, a new managed Cloud PC service that gives each licensed user up to 10 days of temporary desktop access per year. The...
NTLM Relay Attacks Surge in 2025: Top AD Defense Strategies
NTLM relay attacks, once considered a legacy threat, have made a dangerous resurgence in modern Active Directory environments. As organizations continue to rely on Windows-based infrastructure,...
Microsoft Integrates CISO into AI & Cloud Teams to Boost Security Strategy
Microsoft is making waves in the cybersecurity world by repositioning its Chief Information Security Officer (CISO), Igor Tsyganskiy, directly within its AI and cloud operations teams. This strategic...
Windows 365 Cloud PCs Get Mandatory VBS and Lockdowns Starting in 2025
Microsoft is taking a bold step forward in cloud security with its 2025 overhaul of Windows 365 Cloud PC. The company announced sweeping changes that will enforce default lockdowns and automatically...
Windows 365 Secure-by-Default: Credential Guard & HVCI Pre-Configured for Zero Trust
Microsoft’s latest push toward secure-by-default cloud desktops marks a significant milestone in enterprise cybersecurity. With the introduction of enhanced security defaults for Windows 365 Cloud...