Authentication
The latest Authentication coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Deploys SMB Relay Attack Auditing in CVE-2025-55234, Urges Phased Hardening Before Enforcement
Microsoft has released CVE-2025-55234 not as a traditional patch for a new vulnerability, but as a strategic operational toolkit designed to help administrators audit and harden their SMB...
Critical Windows LSASS Bug Exposes Domain Controllers to Authentication DoS Attacks
Microsoft’s latest security advisory for CVE-2025-53809 details a network-exploitable denial-of-service flaw in the Windows Local Security Authority Subsystem Service, the bedrock of authentication...
Windows NTLM Vulnerability Lets Attackers Escalate Privileges Over the Network — Patch Immediately
Microsoft is urging Windows administrators to patch a critical improper authentication vulnerability in NT LAN Manager (NTLM) that allows an authenticated attacker to elevate privileges over a...
Windows NEGOEX Integer Overflow Lets Attackers Escalate to SYSTEM—Patch Now
Microsoft has released a security update to plug a critical elevation-of-privilege hole in the Windows NEGOEX authentication mechanism. Tracked as CVE-2025-54895, the flaw stems from an integer...
Microsoft Copilot Outage Strikes on September 8, Leaving Users Scrambling for Workarounds
On Monday evening, September 8, 2025, Microsoft’s Copilot AI assistant became inaccessible for a wave of users, triggering a spike in outage reports across community forums and monitoring services....
Mandatory MFA Comes to Azure CLI, PowerShell, and IaC Tools—What You Need to Know Before October
Starting in October, Microsoft will begin enforcing multifactor authentication for all write operations performed through the Azure Resource Manager control plane—including Azure CLI, PowerShell,...
Exposed appsettings.json Files Unleash 'Master Key' to Azure Tenants via OAuth Token Abuse
A single, publicly exposed appsettings.json file containing Azure Active Directory (now Entra ID) application credentials can act as a master key to an organization’s entire cloud estate, security...
Windows 11 Gets a Sign-In Facelift and Power User Shortcuts in Latest Previews
Microsoft has shipped two new Insider preview builds—22635.4440 in the Beta Channel and 27754 in the Canary Channel—that overhaul the Windows Hello sign-in experience, tidy up the taskbar, and...
RDP Timing Attacks Explode to 30,000 Malicious IPs in Pre-Attack Reconnaissance on U.S. Schools
Last week, threat intelligence firm GreyNoise observed a coordinated scanning campaign targeting Microsoft Remote Desktop Protocol (RDP) services that rapidly escalated from an initial wave of nearly...
CISA Flags Zero-Day in INVT VT-Designer and HMITool: Remote Code Execution via Malicious Files
A zero-day vulnerability in INVT's VT-Designer and HMITool engineering software lets attackers run arbitrary code on industrial control system (ICS) workstations simply by tricking a user into...
Copilot and Office.com Outage Traced to Botched Microsoft Configuration Change
Microsoft’s cloud productivity suite hit a roadblock on August 20 when users across North America found themselves locked out of Office.com and the Copilot AI assistant. The company declared a...
Power Pages Studio Now Lets You Turn Web Forms into AI Copilot Agents Instantly
A new preview capability in Microsoft Power Pages is bridging the gap between static web forms and conversational AI agents, promising to slash weeks of custom integration work into minutes of...