Endpoint Security Microsoft Silently Mitigated Exploited LNK Vulnerability Windows now displays in the properties tab of LNK files critical information that could reveal malicious code. Ionut ArghireDecember 3, 2025
Artificial Intelligence Microsoft Highlights Security Risks Introduced by New Agentic AI Feature Without proper security controls, AI agents could perform malicious actions, such as data exfiltration and malware installation. Ionut ArghireNovember 24, 2025
Vulnerabilities Microsoft Patches Actively Exploited Windows Kernel Zero-Day Microsoft’s latest Patch Tuesday updates address more than 60 vulnerabilities in Windows and other products. Eduard KovacsNovember 11, 2025
Malware & Threats Chinese APT Exploits Unpatched Windows Flaw in Recent Attacks The Windows shortcut vulnerability has been seen in attacks conducted by Mustang Panda to drop the PlugX malware. Ionut ArghireOctober 31, 2025
Vulnerabilities Critical Windows Server WSUS Vulnerability Exploited in the Wild CVE-2025-59287 allows a remote, unauthenticated attacker to execute arbitrary code and a PoC exploit is available. Eduard KovacsOctober 24, 2025
Endpoint Security Microsoft Disables Downloaded File Previews to Block NTLM Hash Leaks In files downloaded from the internet, HTML tags referencing external paths could be used to leak NTLM hashes during file previews. Ionut ArghireOctober 24, 2025
Vulnerabilities CISA Warns of Exploited Apple, Kentico, Microsoft Vulnerabilities Leading to code execution, authentication bypass, and privilege escalation, the flaws were added to CISA’s KEV list. Ionut ArghireOctober 21, 2025
Endpoint Security Windows 10 Still on Over 40% of Devices as It Reaches End of Support Users can continue receiving important security updates for Windows 10 by enrolling in the ESU program. Eduard KovacsOctober 14, 2025
Endpoint Security Windows’ Infamous ‘Blue Screen of Death’ Will Soon Turn Black After more than 40 years of being set against a very recognizable blue, the updated error message will soon be displayed across a black... Associated PressJune 27, 2025
Endpoint Security Microsoft to Preview New Windows Endpoint Security Platform After CrowdStrike Outage Microsoft is preparing a private preview of new Windows endpoint security platform capabilities to help antimalware vendors create solutions that run outside the kernel. Eduard KovacsJune 27, 2025
Endpoint Security Microsoft Offers Free Windows 10 Extended Security Update Options as EOS Nears With end of support scheduled for October 2025, Windows 10 users will be able to continue receiving important security updates. Eduard KovacsJune 25, 2025
Vulnerabilities Fresh Windows NTLM Vulnerability Exploited in Attacks A Windows NTLM vulnerability patched in March has been exploited in attacks targeting government and private institutions. Ionut ArghireApril 18, 2025
Vulnerabilities Newly Patched Windows Zero-Day Exploited for Two Years Microsoft on Tuesday patched a zero-day vulnerability in the Windows Win32 kernel that has been exploited since March 2023. Ionut ArghireMarch 12, 2025
Vulnerabilities New Windows Zero-Day Exploited by Chinese APT: Security Firm ClearSky Cyber Security says it has seen a new Windows zero-day being exploited by a Chinese APT named Mustang Panda. Eduard KovacsFebruary 14, 2025
Vulnerabilities Exploit Code Published for Potentially Dangerous Windows LDAP Vulnerability Proof-of-concept (PoC) code was published for CVE-2024-49113, a denial-of-service (DoS) vulnerability in Windows LDAP. Ionut ArghireJanuary 3, 2025
Vulnerabilities CISA Warns of Exploited Adobe ColdFusion, Windows Vulnerabilities CISA has warned organizations that two vulnerabilities affecting Adobe ColdFusion and Windows have been exploited in the wild. Eduard KovacsDecember 17, 2024
Nation-State Russian APT Chained Firefox and Windows Zero-Days Against US and European Targets The Russia-linked RomCom APT has been observed chaining two zero-days in Firefox and Windows for backdoor delivery. Ionut ArghireNovember 27, 2024
Vulnerabilities Windows Zero-Day Exploited by Russia Triggered With File Drag-and-Drop, Delete Actions The exploit for a new zero-day vulnerability in Windows is executed by deleting files, drag-and-dropping them, or right clicking on them. Ionut ArghireNovember 14, 2024
Vulnerabilities More Details Shared on Windows Downgrade Attacks After Microsoft Rolls Out Mitigations Microsoft has rolled out mitigations for recently disclosed downgrade attacks targeting the Windows Update process. Ionut ArghireOctober 28, 2024
Endpoint Security Microsoft’s Take on Kernel Access and Safe Deployment Following CrowdStrike Incident SecurityWeek talked to David Weston, VP enterprise and OS security at Microsoft, to discuss Windows kernel access and safe deployment practices. Kevin TownsendOctober 10, 2024