Security Updates
The latest Security Updates coverage — news, analysis, and updates from the WindowsNews.AI desk.
GPT-5 Lands Across Microsoft's Copilot, M365, and Azure, Sparking a New AI Era for Windows
Microsoft has completed a sweeping rollout of OpenAI’s GPT-5 across nearly every corner of its ecosystem, embedding the powerful model into Copilot in Windows, Microsoft 365, GitHub, Copilot...
GPT-5 arrives in Microsoft 365 Copilot: a dual-mode AI that scales from quick answers to deep strategy
Microsoft has begun rolling out GPT-5 to licensed Microsoft 365 Copilot users, marking the first time the tech giant has brought OpenAI’s most advanced reasoning model directly into its enterprise...
GPT-5 Arrives on Windows: Official ChatGPT Desktop App Unlocks Next-Gen AI, No Local Install Required
OpenAI flipped the switch on GPT-5 on August 7, 2025, and Windows users now have a direct pipeline to the company’s fastest, most capable model—but not in the way viral download guides suggest....
GPT-5 Now Open to All on Windows: How to Use It and Avoid Malware Traps
OpenAI has made GPT-5 the default model in ChatGPT, and Windows users can access it immediately—no separate download or subscription required. But as the AI rush intensifies, so do the risks: fake...
Microsoft Switches on GPT-5 Across Copilot, Office, and GitHub with New Smart Mode
Microsoft has flipped the switch on GPT-5 across its entire product range, making OpenAI’s newest reasoning model the default engine for Copilot, Microsoft 365, GitHub, and Azure AI Foundry as of...
Chrome 139 Patches UI Spoofing Flaw That Tricks Users Into Giving Away Permissions—Edge Users Are Protected Too
Google has shipped a critical security fix for Chrome that plugs a user interface spoofing hole attackers could use to trick people into giving websites access to their camera, microphone, or...
CVE-2025-8581: The Low-Risk Chrome Extension Bug That Still Requires an Immediate Update on Edge and Chrome
Google has patched a security vulnerability in Chrome’s Extensions framework that could have allowed attackers to siphon sensitive cross-origin data from unsuspecting users. Tracked as...
Akira Ransomware Exploits Intel ThrottleStop Driver to Disable Windows Defender in Stealthy BYOVD Campaign
A potent ransomware campaign has turned a trusted Intel CPU tuning driver into a weapon, allowing attackers to evade Windows 11's built-in defenses by disabling Microsoft Defender with surgical...
Windows 11 Privacy:Real-Time Alerts and Controls for Camera & Microphone Access
Microsoft has quietly built a privacy fortress around your webcam and microphone, and most users are unaware of its full capabilities. As video calls, remote work, and cloud-based collaboration...
CISA Orders Emergency Fix for Exchange Hybrid Bug Allowing 'Total Domain Compromise'
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive requiring federal agencies to patch a severe Microsoft Exchange vulnerability by August 11, warning...
Critical Exchange Hybrid Flaw CVE-2025-53786 Allows Undetectable Privilege Escalation—Patch Now
A dangerous authentication bypass has surfaced in Microsoft Exchange hybrid deployments, prompting coordinated alerts from both Microsoft and the U.S. Cybersecurity and Infrastructure Security Agency...
The Phishing Pipeline: How Attackers Weaponize Microsoft 365 Direct Send to Evade Every Defense
Microsoft 365’s Direct Send feature has become a double-edged sword. Designed to let printers, scanners, and applications relay mail without a dedicated mailbox, it now enables attackers to slip...