Security Research
The latest Security Research coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows Defender Exploit: RedSun 0day Uses Race Condition for System32 Privilege Escalation
A newly disclosed Windows Defender vulnerability allows attackers to achieve local privilege escalation by exploiting a race condition in the antivirus engine's file handling. Dubbed "RedSun" by...
Chrome 145 Emergency Update Fixes 10 Critical CVEs: What Windows Users Need to Know
Google has issued an urgent security update for Chrome 145, addressing ten critical vulnerabilities that could potentially allow attackers to execute arbitrary code, escape sandbox protections, or...
Password Manager Zero-Knowledge Promise Broken: ETH Zurich Research Exposes Critical Flaws
A groundbreaking research paper from cryptographers at ETH Zurich and the Università della Svizzera italiana has shattered one of the most fundamental security promises in the password management...
Windows 11 Default Browser: How EU DMA Forced Microsoft's One-Click Switch
Microsoft has fundamentally transformed the Windows 11 default browser experience, implementing a streamlined one-click switching mechanism that represents a significant departure from years of user...
8 Chrome, Edge extensions with 2M+ installs stole ChatGPT, Gemini chats
Security researchers have uncovered a startling privacy breach in plain sight: several widely used Google Chrome and Microsoft Edge extensions — marketed as privacy and security tools — were...
XChat’s Encryption Promise Crumbles: GPS-Tagged Photos and Server Keys Put Users at Risk
Images sent over X’s new encrypted chat service retain full EXIF metadata, including GPS coordinates, device information, and timestamps, Straight Arrow News (SAN) revealed this week. The finding,...
Critical Chromium Use-After-Free Flaw CVE-2025-8576 Triggers Urgent Edge, Chrome Updates
A severe use-after-free vulnerability in the Chromium extensions engine, tracked as CVE-2025-8576, is driving urgent updates across the browser ecosystem. The flaw, which carries high severity,...
Black Hat Demo Exposes Windows Hello Biometric Flaw: Admin Rights Enable Face Injection Attack
German security researchers at the Black Hat USA 2025 conference in Las Vegas have demonstrated a stark vulnerability in Microsoft’s Windows Hello biometric authentication system. The live demo...
Zenity Labs’ AgentFlayer Exposes Zero-Click Exploits: Microsoft Copilot, ChatGPT AI Agents Hijacked Without User Action
At Black Hat USA 2025, security researchers from Zenity Labs pulled back the curtain on a dangerously overlooked attack surface: enterprise AI agents that can be silently hijacked with zero user...
Sophisticated Microsoft 365 Phishing Attacks: Exploiting Security Features from Within
The digital arms race between cyber defenders and adversaries has reached a new inflection point, one that rattles the very foundations of trust in modern email and identity security. For Microsoft...
EchoLeak: The Critical Microsoft Copilot Vulnerability Reshaping Enterprise AI Security
A storm has swept through the cybersecurity and Windows enterprise communities following the exposure of a critical vulnerability in Microsoft Copilot Enterprise, code-named “EchoLeak.” This...
Critical Microsoft Entra ID SAML Exploit Enables Global Administrator Privilege Escalation
Security researchers have sounded the alarm over a newly discovered exploit chain in Microsoft Entra ID, a service formerly known as Azure Active Directory, that enables attackers to seize Global...