Live
Russian Hackers Weaponize 7-Year-Old Cisco Smart Install Bug for Stealthy Network Spying·MSFT +2.1%70% Faster Threat Analysis: Inside TÜV SÜD’s AI-Powered Security Overhaul with Microsoft Copilot·NVDA +0.2%SolanaScan npm Malware Strips Wallet Keys from Windows Developer Environments·GOOGL +1.7%Security Copilot Deep Dive: AI Incident Summaries, Automation Agents, and the 84 Trillion Signal Question·AMZN +1.1%Microsoft patches Kerberos 'BadSuccessor' flaw and critical image-parsing bugs in August update·MSFT +2.1%Domain Controllers at Risk: Microsoft’s August Update Closes Kerberos dMSA Vulnerability Amid 100+ Fixes·NVDA +0.2%CISA Orders Patching of 2007 Excel Bug, 2013 IE Flaw, and 2025 WinRAR Zero-Day·GOOGL +1.7%Active SharePoint RCE Exploits Chain Deserialization Bug to Deploy Web Shells and Ransomware·AMZN +1.1%Russian Hackers Weaponize 7-Year-Old Cisco Smart Install Bug for Stealthy Network Spying·MSFT +2.1%70% Faster Threat Analysis: Inside TÜV SÜD’s AI-Powered Security Overhaul with Microsoft Copilot·NVDA +0.2%SolanaScan npm Malware Strips Wallet Keys from Windows Developer Environments·GOOGL +1.7%Security Copilot Deep Dive: AI Incident Summaries, Automation Agents, and the 84 Trillion Signal Question·AMZN +1.1%Microsoft patches Kerberos 'BadSuccessor' flaw and critical image-parsing bugs in August update·MSFT +2.1%Domain Controllers at Risk: Microsoft’s August Update Closes Kerberos dMSA Vulnerability Amid 100+ Fixes·NVDA +0.2%CISA Orders Patching of 2007 Excel Bug, 2013 IE Flaw, and 2025 WinRAR Zero-Day·GOOGL +1.7%Active SharePoint RCE Exploits Chain Deserialization Bug to Deploy Web Shells and Ransomware·AMZN +1.1%

Threat Intelligence

The latest Threat Intelligence coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 11:42 PM
Latest Most Read Breaking
Sort
Cisco · Cve-2018-0171

Russian Hackers Weaponize 7-Year-Old Cisco Smart Install Bug for Stealthy Network Spying

An urgent FBI advisory and new research from Cisco Talos confirm that Russian state‑sponsored hackers have spent years quietly breaching enterprise networks through a critical vulnerability in...

Advertisement
Active Directory · Azure Security

Microsoft patches Kerberos 'BadSuccessor' flaw and critical image-parsing bugs in August update

On August 12, 2025, Microsoft shipped its monthly security bundle, and it's one of those months that makes sysadmins reach for extra coffee. Two critical remote code execution (RCE) vulnerabilities...

SE Security Desk·48w ago
Cve-2025-53779 · Cybersecurity

Domain Controllers at Risk: Microsoft’s August Update Closes Kerberos dMSA Vulnerability Amid 100+ Fixes

Microsoft’s August 2025 Patch Tuesday release lands with an urgent fix for a Kerberos vulnerability that could allow attackers to escalate to domain administrator, alongside more than a dozen other...

SE Security Desk·48w ago
Bod 22-01 · Cisa

CISA Orders Patching of 2007 Excel Bug, 2013 IE Flaw, and 2025 WinRAR Zero-Day

On August 12, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog—two of them first disclosed during the...

SE Security Desk·49w ago
Amsi · Cve-2025-49704

Active SharePoint RCE Exploits Chain Deserialization Bug to Deploy Web Shells and Ransomware

Attackers are actively chaining a deserialization vulnerability in on-premises SharePoint Server with an authentication bypass to gain remote code execution without credentials—then stealing the...

SE Security Desk·49w ago
Asr · Cve-2025-53740

CVE-2025-53740: Urgent Patch Needed as Office Use-After-Free RCE Threatens Enterprise Security

Microsoft has confirmed a critical use-after-free vulnerability in Microsoft Office, tracked as CVE-2025-53740, that could let attackers run arbitrary code when a user opens a maliciously crafted...

SE Security Desk·49w ago
Cve-2025-53766 · Defense In Depth

Unverified GDI+ RCE Vulnerability CVE-2025-53766 Prompts Urgent Patch Verification Call

Microsoft’s Security Update Guide has quietly listed a new vulnerability tracked as CVE-2025-53766, describing a heap-based buffer overflow in the GDI+ graphics library that could allow remote code...

SE Security Desk·49w ago
Application Guard · Asr

CVE-2025-53733: Patch Microsoft Word RCE Now – Numeric Conversion Flaw Exploited

Microsoft has published advisory CVE-2025-53733, warning of a remote code execution vulnerability in Microsoft Word that stems from an incorrect conversion between numeric types during document...

SE Security Desk·49w ago
Cve-2025-53153 · Firewall

CVE-2025-53153: Microsoft Patches Information-Disclosure Flaw in Windows RRAS — What Admins Must Do

Microsoft’s April 2025 Patch Tuesday brought a crucial fix for CVE-2025-53153, an information-disclosure vulnerability residing in the Windows Routing and Remote Access Service (RRAS). The...

SE Security Desk·49w ago