Tag: microsoft
702 articles

Cyberattackers Favor Repeatable Playbooks Over Innovative Tactics
Cyberattackers are ditching creative tactics for a straightforward, repeatable playbook - and it's surprisingly effective, with a simple trick called ClickFix accounting for 47% of attacks. This sneaky method involves guiding users through a CAPTCHA-style interaction, then tricking them into pasting a command into a terminal, all without needing attachments or vulnerabilities.

Microsoft Warns of TerminalFix Malware Hiding in PNGs
Microsoft researchers have uncovered a sneaky malware campaign, dubbed TerminalFix, that hides in plain sight by masquerading as harmless PNG images - only to delete them after extraction, leaving behind a trail of PowerShell commands that can compromise your system. This fresh variant of the ClickFix social-engineering trick tricks victims into pasting malicious commands into Windows Terminal or PowerShell.

Microsoft Disables Faulty Driver Behind Windows 11 Gaming Crashes
Microsoft has pinpointed a problematic driver, inpoutx64.sys, as the culprit behind Windows 11 gaming crashes, and has taken swift action to disable it and prevent further system crashes and game failures. This fix aims to put an end to frustrating errors and glitches, ensuring a smoother gaming experience for Windows 11 users.

CISA Flags Six Exploited Flaws in Microsoft, Linux, Citrix Products
The US Cybersecurity and Infrastructure Security Agency (CISA) has just sounded the alarm, adding six new vulnerabilities to its Known Exploited Vulnerabilities catalog in a single day - a stark reminder that threat actors are relentlessly targeting both old and newly discovered software weaknesses. This urgent move underscores the need for immediate action to patch these flaws and prevent exploitation.

Microsoft Bolsters Windows 11 with Granular App Permission Controls
Take control of your digital privacy with Windows 11's latest update, which introduces granular app permission controls for camera, microphone, and location access - giving you the power to customize permissions for each desktop app. This new feature, available to Windows Insiders, makes it easier to manage and understand app permissions.

Microsoft Issues Workaround for Windows 11 Gaming Glitches
If you've noticed glitches while gaming on Windows 11 after installing the August 11 update (KB5121003) or later, you're not alone - Microsoft has confirmed the issue and linked it to problematic drivers from RGB devices. A workaround is now available to help you get back to gaming smoothly.

Microsoft Points to RGB Devices as Likely Cause of Windows Gaming Issues
If you're experiencing frustrating gaming issues on Windows, such as crashes, freezes, or failure to launch, after installing the August 11, 2026 update (KB5121003) or later, Microsoft may have identified the culprit: RGB devices.

Microsoft Probes Gaming Issues Tied to August Windows Updates
Microsoft is on the case, investigating reports that some Windows 11 games have become unresponsive after installing the August updates, and is working to determine if the updates are the culprit. The company has promised to provide an update as soon as more information becomes available.

Microsoft Fixes Bug Disrupting Windows Defender Scans
Windows Defender was acting up, causing scans to fail and crashes with annoying error messages - but thankfully, Microsoft has swooped in to fix the problem. The update resolves issues with 0xc0000005 access violation errors and pesky "Threat service has stopped" messages on Windows 10 and 11 devices.

Hackers Actively Exploit Windows IKE Flaw
Hackers are actively exploiting a critical Windows flaw, known as CVE-2026-33824, that lets them execute code over a network, putting your system at risk. This vulnerability, found in the Windows Internet Key Exchange (IKE) Service Extensions, affects all supported Windows 10 and other Windows systems.

Microsoft Warns of Impending Windows 11 Support Cutoff
Mark your calendars: October 13, 2026, is the deadline for Windows 11 version 24H2 Home and Pro editions to receive crucial security and non-security updates, after which devices will be vulnerable to the latest security threats. Don't risk being left exposed - take note of this important support cutoff date.

Microsoft Overhauls File Explorer to Bolster Speed, Security
Microsoft's revamped File Explorer is here to make your life easier, streamlining everyday tasks with a focus on speed, security, and seamless performance. Say goodbye to frustrating interruptions, like file renames being disrupted by background syncs, and hello to instant updates for filename changes.

Ransomware gangs exploit Windows Task Host flaw
Ransomware gangs are exploiting a high-severity flaw in Windows Task Host, a core component that could allow them to escalate privileges and wreak havoc on your system. This vulnerability, already patched by Microsoft, poses significant risks to users, especially those with basic user permissions.

Microsoft Phases Out WMIC Tool Amid Cybercrime Exploits
Microsoft has pulled the plug on the Windows Management Instrumentation Command-line (WMIC) tool, removing it from Windows 11 versions 24H2 and 25H2, and phasing it out from future updates. This move marks the end of an era for a utility that's been a favorite among cybercriminals.

Microsoft Flags 60-Day Countdown for Windows Server 2022 Support Shift
Mark your calendars: Windows Server 2022 will reach the end of its mainstream support on October 13, 2026, and transition to extended support, where you'll still receive free monthly security updates until October 14, 2031.

Microsoft Delays Exchange Update Citing AI-Driven Bug Discovery
Microsoft's Exchange team is working on Cumulative Update 1 (CU1) for Exchange Server Subscription Edition, but has delayed its release due to an unexpected bug discovery driven by AI, leaving customers waiting a bit longer for the update that packs recent bug fixes, new features, and code refinements. The team promises it's on the way, but a new timeline isn't available just yet.

Microsoft patches LegacyHive zero-day vulnerability
Microsoft just patched a nasty zero-day vulnerability, known as LegacyHive, that could let hackers gain administrator privileges on your Windows PC - but thankfully, it's now fixed in the August Patch Tuesday updates.

Microsoft's Shared Responsibility Model Exposes SaaS Backup Gaps
Many organizations mistakenly assume Microsoft handles data restoration, but the reality is their Shared Responsibility Model leaves SaaS backup gaps that can expose customers to data loss and ransomware attacks. Native recovery tools only address short-term data issues, not long-term cyber resilience.

Attackers Exploit SharePoint Flaw After Public PoC Release
Microsoft warned that a critical SharePoint flaw, patched in July 2026, could allow attackers to bypass authentication and disclose files or modify data. This vulnerability, tracked as CVE-2026-55040, has now been exploited by attackers following the public release of a proof-of-concept exploit.

Microsoft Patch Tuesday Disrupts 400 Vulnerabilities, Zero-Day Exploits
Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 vulnerabilities, including an actively exploited zero-day threat that demands immediate attention from sysadmins. With high-risk impacts on confidentiality, integrity, and availability, these fixes should be top priority.

Microsoft Disrupts Hundreds of Flaws in Massive Patch Update
Microsoft just dropped a massive patch update to fix a whopping 398 security flaws in Windows and its software, including a critical vulnerability that's already being exploited by hackers. This crucial update tackles a range of weaknesses, from a zero-day privilege-escalation flaw in a key Windows driver to other publicly known vulnerabilities.

Lazarus Group Exploits Microsoft Zero-Day in Global Defense Sector Attacks
North Korea's notorious Lazarus Group has been exploiting a Microsoft zero-day vulnerability, CVE-2026-68820, since early June, targeting the global defense sector with alarming precision. This high-severity flaw, patched in August, allowed attackers to execute code with SYSTEM-level privileges, putting countless systems at risk.

Microsoft Patches Zero-Day Windows Driver Flaw Under Active Attack
Microsoft just patched a high-severity Windows driver flaw, known as CVE-2026-68820, that was already being exploited by hackers in the wild. This zero-day vulnerability, with a CVSS score of 7.0, could be triggered by a race condition, allowing attackers to gain a foothold in targeted systems.

Microsoft Patch Tuesday Disrupts 400 Flaws, Zero-Day Exploits
Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 security flaws, including a zero-day vulnerability that's already being exploited by hackers. This massive release also includes fixes for two other zero-day vulnerabilities that were publicly disclosed.