Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
IBM Power Linux Systems Face Kernel Crash Bug; Patch Arrives, Windows Spared
A newly published Linux kernel vulnerability, tracked as CVE-2026-63805, patches a driver bug that can crash IBM Power systems running cryptographic workloads. The flaw, disclosed on July 19, 2026,...
JPMorgan Chief Sounds ‘Ballistic Missile’ Alarm Over AI Bug-Hunting Model — Windows Defenders Must Act
JPMorgan Chase CEO Jamie Dimon didn’t mince words at a defense and innovation summit on July 15: allowing unrestricted access to Anthropic’s Claude Mythos cybersecurity model, he said, would be...
Claude Code Can Read Your Entire Drive Unless You Lock It Down: 5 Steps for Windows Users
Anthropic’s Claude Code is now in the hands of Windows developers, and it brings with it a deceptively simple permission model that can expose much more than your project files. A new guide from...
Microsoft Sets Hard Deadline: SMS MFA Retires in Entra ID by 2027, Passkeys Take Over
Microsoft has drawn a line in the sand: after February 1, 2027, its Entra ID identity platform will no longer provide SMS or voice call verification for multi-factor authentication. Organizations...
Millions of VS Code Users Exposed: Code Runner 0.12.2 Flaw Gives Attackers Full Shell Access
A high-severity vulnerability in one of Visual Studio Code’s most popular extensions can let attackers run any command they want on Windows machines simply by tricking a developer into opening a...
VPNs Are Legal Almost Everywhere — Until You Cross These 2026 Red Lines
Using a VPN on your Windows laptop isn't a crime in any major country as of mid-2026. But if you're heading to Myanmar, Russia, India, or the UAE, assuming that legality means trouble-free browsing...
OpenAI's GPT-5.6 Codex Deletes User Files When Run With Full System Access—What Windows Developers Must Do Now
OpenAI is investigating multiple reports of its GPT-5.6 Codex coding agent spontaneously deleting files from user home directories, a dangerous glitch that surfaces only when developers grant the...
Claude in Chrome Flaw: ‘Act Without Asking’ Mode Can Be Exploited by Rogue Extensions to Read Your Email
On Wednesday, security researchers at Manifold Security disclosed a high-severity vulnerability in the Claude in Chrome extension that could allow a malicious browser add-on to silently read your...
UEFI Secure Boot 2011 Certificates Expire Oct 19—Use This Microsoft Script to Prepare
Microsoft’s July 15 Secure Boot Office Hours session confirmed that the final 2011-era certificate, the Windows Production PCA 2011, will expire on October 19, 2026. The event also revealed a...
Chrome 150 Patches High-Severity Aura Flaw Before NVD Can Catch Up
Google patched a high-severity memory-safety flaw in Chrome’s Aura UI framework on July 16, shipping version 150.0.7871.128 for Windows and .129 for macOS. The fix arrived before the corresponding...
Google Chrome 150 Update Fixes High-Severity Cast Vulnerability — What Windows Users Need to Know
Google released Chrome 150.0.7871.128 for Windows on July 16, closing a high-severity use-after-free flaw in the Cast component tracked as CVE-2026-15902. The same update patches three critical...
SEBI warns: Boss Scam now hijacks Windows PCs to send payment orders from executives' own WhatsApp
India’s securities regulator, the Securities and Exchange Board of India (SEBI), issued an urgent advisory on July 17 after a sophisticated fraud campaign began targeting company executives with...