Live

Security

Stay ahead with our essential Windows security news: Patch Tuesday updates, threat analyses, and expert guidance to safeguard your Microsoft environment.

13 stories in view AI assisted desk updated 7:50 PM
Latest Most Read Breaking
Sort
Windows 11 · PC Maintenance

Why Your Windows 11 PC Needs a Yearly Cleanup (And How to Do It Right)

An annual Windows 11 cleanup can reclaim storage, speed up boot times, and improve system hygiene, but the line between smart maintenance and risky debloating is thin. This guide walks through safe, evidence-based steps—from uninstalling unused apps to managing startup programs—while cautioning against scripts that can break system functionality or compromise security.

Security

Edge Management Service to Surface Critical Security Alerts Starting August 2026

Microsoft is introducing Security Update Alerts in its Edge management service, giving IT admins a way to set severity thresholds and receive notifications for critical browser patches. The feature enters general availability in August 2026 after a targeted-release preview that began in April, aiming to help organizations prioritize the most urgent Edge security updates, including zero-day fixes.

Security Desk·20h ago ·5 min
Security

A Tesla Employee's Tip Foiled a $1M Ransomware Hack. What Can Your Business Learn?

In 2020, a Tesla employee refused a $1 million bribe to install ransomware and instead alerted the FBI, foiling a double-extortion plot by Russian national Egor Kriuchkov. A new interview with Tesla's former security chief reveals the internal reporting process that saved the company's data. The case offers urgent lessons for Windows administrators on blending technical controls with a positive reporting culture to stop insider threats before they detonate.

Security Desk·21h ago ·5 min
Security

Veeam’s New California-Nevada Leads: ‘Test Your Recovery, Not Just Your Backups’

Veeam appointed Scott Strong and Tyler Raynes as public-sector contacts for California and Nevada, emphasizing that agencies must shift focus from backup success to proven recovery capability. The move signals a growing industry push for realistic recovery testing against ransomware, especially in Windows-dependent government IT.

Security Desk·21h ago ·5 min
Advertisement
Apuc · Cybersecurity

Attackers Claim 20-Year Data Theft in Scottish University Procurement Breach

Scotland’s university procurement hub APUC confirmed unauthorized access to historic data, with attackers claiming to have stolen two decades of records. No operational disruption occurred, but the scope of exposure remains unclear, raising risks of phishing and invoice fraud for universities and suppliers.

SE Security Desk·21h ago ·1 views
DHCP · Windows 11

One DHCP Lease Can Change Your Windows 11 DNS and Routes Without You Knowing

A Wireshark experiment reveals that DHCP can reconfigure Windows 11's DNS servers, search domains, and routing tables beyond just IP assignment. Users should audit DHCP-delivered settings to avoid unintended network changes, and admins need to secure DHCP scopes to prevent misconfigurations.

SE Security Desk·1d ago ·1 views
Azure Arc · Azure Machine Configuration

Azure Machine Configuration Now Audits Linux Against CIS Benchmarks — No Scripts Required

Microsoft has brought native CIS Benchmark auditing for Linux into Azure Machine Configuration, letting Azure VM and Azure Arc administrators assess compliance directly through Azure Policy without third-party scanners. The generally available capability supports custom rule selection, exports policy-as-code JSON, and provides per-rule evidence through Guest Assignments and Resource Graph. It’s audit-only, so admins need to plan manual remediation, but the integration unifies hybrid-server compliance monitoring under a single control plane.

SE Security Desk·1d ago ·1 views
Azure Cosmos Db · Cloud Security

CosmosEscape Flaw Fixed: What Azure Cosmos DB Users Need to Know Despite 'No Action Required'

Microsoft has patched CosmosEscape, a cross-tenant vulnerability in Azure Cosmos DB that could have allowed attackers to access other customers' databases. The fix was provider-side, with no customer action required, but experts advise reviewing logs and hardening security measures to mitigate any undetected exploitation.

SE Security Desk·1d ago ·2 views
CISA · Johnson Controls

Critical File Upload Flaw in OpenBlue Employee Puts Facilities at Risk Despite Low Score

CISA's July 30 advisory details three vulnerabilities in Johnson Controls OpenBlue Employee, including an unrestricted file-upload bug that could let attackers compromise facility management systems. While the CVSS score is just 2.4, the software's presence in critical infrastructure makes immediate action essential. Windows administrators need to contact the vendor for updates and harden their deployments.

SE Security Desk·1d ago ·1 views
CISA Alert · Water Utility Security

Hackers Are Locking Water Plant Operators Out of Their Own PLCs—CISA Issues Urgent Disconnect Order

CISA issued an urgent alert on July 30, 2026, warning water utilities that threat actors are increasingly targeting internet-exposed programmable logic controllers, locking out operators and forcing boil-water notices. The agency calls for immediate disconnection of all exposed PLCs and provides guidance on securing remote access, password protection, and recovery.

SE Security Desk·1d ago ·2 views
Azure Cosmos Db · Remote Code Execution

Microsoft Flags Azure Cosmos DB RCE Vulnerability; Here's What You Need to Do Now

On July 30, 2026, Microsoft published a security advisory for CVE-2026-66803, a remote code execution vulnerability in Azure Cosmos DB. The advisory lacks technical details, forcing organizations to take proactive defense measures while awaiting further guidance. This article explains the known facts, practical impacts for different users, and a step-by-step hardening checklist.

SE Security Desk·1d ago ·1 views
Dns Over Https · Windows 11

What Windows 11's DNS Over HTTPS Setting Actually Does (and Doesn't Do) for Your Privacy

Windows 11 has included DNS over HTTPS for years, but a recent how-to guide has reignited interest. We explain exactly what the setting does, how to enable it, and why it isn't a substitute for a VPN. The feature encrypts domain name lookups, preventing ISPs from logging which sites you visit, but it does not hide your overall internet traffic. We cover step-by-step setup, browser conflicts, enterprise caveats, and the history of DNS encryption.

SE Security Desk·2d ago
Apple · Android

Apple's Android Apps Every Windows User Should Know — Security, Switching, and Surprise

Apple maintains three little-known Android apps that fill specific needs: Tracker Detect for manual AirTag scanning, Move to iOS for switching phones, and Apple Music Classical for enhanced classical streaming. While Android now offers built-in tracker alerts, each app still has practical value for Windows users who use Android or plan to move to iPhone.

SE Security Desk·2d ago ·1 views