Live
CISA Emergency Directive Targets Exchange Hybrid Flaw in August Patch Tuesday Deluge·MSFT +2.1%Microsoft Patches Publicly Disclosed ‘BadSuccessor’ Kerberos Zero-Day and Exchange Hybrid Cloud Threat in August 2025 Update·NVDA +0.2%Microsoft patches Kerberos 'BadSuccessor' flaw and critical image-parsing bugs in August update·GOOGL +1.7%Microsoft’s August Update Plugs Kerberos Zero-Day; Two 9.8-Rated RCEs Demand Immediate Patching·AMZN +1.1%Epic Unlocks Fortnite for Snapdragon PCs with Native Arm Anti-Cheat in EOS SDK Update·MSFT +2.1%Six Free Tools That Expose the Real Reason Your Windows PC Is Slow·NVDA +0.2%WSL 2.5.10 Fixes TOCTOU Bug: Microsoft Acts Fast on CVE-2025-53788 Privilege Escalation·GOOGL +1.7%CVE-2025-50155: Critical Windows Push Notifications EoP Flaw Exposes Systems to Full Takeover·AMZN +1.1%CISA Emergency Directive Targets Exchange Hybrid Flaw in August Patch Tuesday Deluge·MSFT +2.1%Microsoft Patches Publicly Disclosed ‘BadSuccessor’ Kerberos Zero-Day and Exchange Hybrid Cloud Threat in August 2025 Update·NVDA +0.2%Microsoft patches Kerberos 'BadSuccessor' flaw and critical image-parsing bugs in August update·GOOGL +1.7%Microsoft’s August Update Plugs Kerberos Zero-Day; Two 9.8-Rated RCEs Demand Immediate Patching·AMZN +1.1%Epic Unlocks Fortnite for Snapdragon PCs with Native Arm Anti-Cheat in EOS SDK Update·MSFT +2.1%Six Free Tools That Expose the Real Reason Your Windows PC Is Slow·NVDA +0.2%WSL 2.5.10 Fixes TOCTOU Bug: Microsoft Acts Fast on CVE-2025-53788 Privilege Escalation·GOOGL +1.7%CVE-2025-50155: Critical Windows Push Notifications EoP Flaw Exposes Systems to Full Takeover·AMZN +1.1%

Windows Security

The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 7:59 PM
Latest Most Read Breaking
Sort
Cisa-ed-25-02 · Cloud-mitigations

CISA Emergency Directive Targets Exchange Hybrid Flaw in August Patch Tuesday Deluge

The Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive late Tuesday, ordering federal agencies to secure on-premises Exchange servers within hours after a newly...

Advertisement
Anti-cheat · Arm64

Epic Unlocks Fortnite for Snapdragon PCs with Native Arm Anti-Cheat in EOS SDK Update

Epic Games and Qualcomm have shattered one of the most stubborn barriers holding back Windows on Arm: kernel-level anti-cheat. With a new Epic Online Services (EOS) SDK release, Easy Anti-Cheat (EAC)...

SE Security Desk·49w ago
Backup And Recovery · Chkdsk

Six Free Tools That Expose the Real Reason Your Windows PC Is Slow

Slow app launches, random freezes, and file transfers that crawl—most Windows performance problems aren’t mysterious gremlins. They’re the result of measurable issues: a failing hard drive with...

SE Security Desk·49w ago
Cve-2025-53788 · Edr

WSL 2.5.10 Fixes TOCTOU Bug: Microsoft Acts Fast on CVE-2025-53788 Privilege Escalation

Microsoft released an out-of-band Windows Subsystem for Linux (WSL) update on August 6, 2025, patching a local elevation-of-privilege vulnerability that could let attackers break out of WSL2...

SE Security Desk·50w ago
Cve-2025-50155 · Edr

CVE-2025-50155: Critical Windows Push Notifications EoP Flaw Exposes Systems to Full Takeover

A serious elevation-of-privilege vulnerability in Windows Push Notifications has been cataloged as CVE-2025-50155 by Microsoft, giving authenticated local attackers a clear path to SYSTEM-level...

SE Security Desk·50w ago
Active Directory · Authentication

CVE-2025-53779: New Kerberos Path Traversal Bug Opens Door to Privilege Escalation—Patch Now

Microsoft’s security team has published guidance for CVE-2025-53779, a newly disclosed vulnerability in Windows Kerberos that could let authenticated attackers on the network elevate their...

SE Security Desk·50w ago
Authentication Vulnerability · Cve-2025-53778

Windows Admins: CVE-2025-53778 Is a Patch-Now NTLM Privilege Escalation That Threatens Entire Domains

Microsoft has silently added CVE-2025-53778 to its Security Update Guide, flagging a improper authentication flaw in the Windows NTLM implementation that permits an authorized attacker to elevate...

SE Security Desk·50w ago
Cve-2025-47956 · Cwe-73

Windows Security App UI Spoofing Flaw CVE-2025-47956 Patched – But Local Attackers Can Still Fake Alerts

Microsoft’s June 2025 security updates address a spoofing vulnerability in the Windows Security App that lets a local user manipulate file names and paths to display forged security alerts. Tracked...

SE Security Desk·50w ago
Cve-2025-53766 · Defense In Depth

Unverified GDI+ RCE Vulnerability CVE-2025-53766 Prompts Urgent Patch Verification Call

Microsoft’s Security Update Guide has quietly listed a new vulnerability tracked as CVE-2025-53766, describing a heap-based buffer overflow in the GDI+ graphics library that could allow remote code...

SE Security Desk·50w ago