Windows Security
The latest Windows Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch Chrome Now: CVE-2026-7990 LPE Gives SYSTEM Access on Windows
Google pushed out a critical security update for its Chrome browser on May 6, 2026, addressing a local privilege escalation (LPE) vulnerability in the Chrome Updater component for Windows. Tracked as...
CVE-2026-8000: ChromeDriver Input Validation Flaw Puts Windows Users at RCE Risk — Update to Chrome 148.0.7778.96 Now
Google has disclosed a high‑severity vulnerability in ChromeDriver, a component of Chrome used for browser automation, that could enable remote attackers to execute arbitrary code on Windows...
Windows 10 users risk boot failure after Secure Boot certificate expiration in June 2026
Microsoft's Secure Boot ecosystem faces a watershed moment in June 2026 when the original 2011 root certificates begin to expire, threatening the bootability of millions of Windows PCs that fall...
ZDNET’s Windows Security Wake-Up Call: 5 Optional Protections You Should Turn On Now
{ "title": "ZDNET’s Windows Security Wake-Up Call: 5 Optional Protections You Should Turn On Now", "content": "ZDNET recently published a stark reminder: the most hardened Windows PC isn't the...
Secure Boot Warning Escalates May 2026—Update Firmware Now to Avoid Failure
Microsoft will begin displaying escalating Secure Boot certificate warnings in Windows Security starting May 13, 2026 for Windows 10, and May 16, 2026 for Windows 11. The alerts target PCs that have...
Microsoft Agent 365 GA Delivers Unified AI Agent Governance for Windows and Multicloud
Microsoft flipped the switch on general availability for Agent 365 on May 1, 2026, giving commercial customers a dedicated control plane to discover, govern, and secure the rapidly multiplying AI...
Patch Python Requests Now: CVE-2026-25645 Temp-File Flaw on Windows
Microsoft's Security Update Guide now lists CVE-2026-25645, a medium-severity vulnerability in the ubiquitous Python Requests library. The flaw, present in versions before 2.33.0, stems from the...
CVE-2026-7360: How a Chromium Compositing Flaw in Chrome 147 Bypasses Site Isolation and What It Means for Windows Security
{ "title": "CVE-2026-7360: How a Chromium Compositing Flaw in Chrome 147 Bypasses Site Isolation and What It Means for Windows Security", "content": "Google’s April 28, 2026 security update for...
Poetry 2.3.3 Patches a Path Traversal Bug That Let Malicious Wheels Escape Install Dirs
Python developers who rely on Poetry for dependency management need to update immediately to version 2.3.3, which patches a path traversal vulnerability in how the tool installs wheel packages. The...
CVE-2026-23360: Why Windows Users Must Patch This Linux Kernel NVMe Leak
CVE-2026-23360, a Linux kernel vulnerability in the NVMe storage subsystem, may look like a niche server issue at first glance. But Microsoft’s Security Response Center is tracking it, and Windows...
Why a Linux NFC vulnerability just showed up on Microsoft’s patch radar – and who needs to act
Microsoft’s Security Response Center (MSRC) added a Linux kernel vulnerability to its advisory feed this week — CVE-2026-31622, a heap overflow in the NFC subsystem. If you’re a Windows user,...
PhantomRPC Windows Flaw Lets Attackers Hijack RPC for SYSTEM Access
PhantomRPC: A New Class of Windows Privilege Escalation Security researchers have uncovered a novel attack vector targeting Windows Remote Procedure Call (RPC) infrastructure, dubbed PhantomRPC. This...