Cisa
The latest Cisa coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Patches Publicly Disclosed ‘BadSuccessor’ Kerberos Zero-Day and Exchange Hybrid Cloud Threat in August 2025 Update
Microsoft’s August 2025 security update patches a publicly disclosed Kerberos privilege escalation flaw and a dangerous Exchange hybrid vulnerability that could let attackers hop from on-premises...
CISA Orders Patching of 2007 Excel Bug, 2013 IE Flaw, and 2025 WinRAR Zero-Day
On August 12, the Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog—two of them first disclosed during the...
CVE-2025-33057: Microsoft Patches LSASS Null Pointer DoS That Can Crash Domain Controllers
Microsoft has released a security update for a vulnerability that allows an attacker with network access to crash the Local Security Authority Subsystem Service (LSASS) and trigger a...
Actively Exploited Windows AFD.sys Flaw Earns CISA KEV Status Amid Patching Confusion
Microsoft’s February 2025 Patch Tuesday delivered a fix for CVE-2025-21418, a heap-based buffer overflow in the Windows Ancillary Function Driver (afd.sys), but sysadmins are grappling with a...
CVE-2025-50171: Critical RDP Flaw Allows Spoofing—Patch Now, Warns Microsoft
Microsoft has published details of a new vulnerability in its Remote Desktop Services that could allow an unauthenticated attacker to perform spoofing attacks over a network. Tracked as...
Windows SMB Bug CVE-2025-50169 Opens Door to Remote Code Execution — Patch Now
Microsoft’s June 2025 Patch Tuesday included a fix for a race-condition vulnerability in the Windows Server Message Block (SMB) protocol that can be exploited over the network to run malicious code...
Microsoft Discloses Critical RRAS Heap Overflow (CVE-2025-50164) — Patch Now to Block Remote Code Execution
Microsoft has issued a high-severity security advisory for a heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) that could allow unauthenticated attackers to execute...
CVE-2025-25005: The Windows Vulnerability Shrouded in Uncertainty and What Admins Must Do Now
The discovery of a new Windows vulnerability always triggers a scramble for details, but CVE-2025-25005 has presented an unusual challenge: the Microsoft Security Response Center (MSRC) advisory...
Microsoft Warns of Excel RCE Flaw CVE-2025-53759, Workarounds Provided
A newly disclosed vulnerability in Microsoft Excel, tracked as CVE-2025-53759, allows attackers to execute arbitrary code on a victim’s machine by tricking them into opening a specially crafted...
CISA August 2025 Advisory Exposes Critical Flaw in Rail Brake Protocol, Demands Broad ICS Patching
The U.S. rail industry faces a safety-critical vulnerability that cannot be fixed with a simple software update. A flaw in the remote linking protocol used by End-of-Train (EoT) and Head-of-Train...
Immediate Hotfixes Released for Schneider Electric PME Vulnerabilities, CISA Urges Swift Action
Schneider Electric has released hotfixes for a cluster of high-impact vulnerabilities in its EcoStruxure Power Monitoring Expert (PME) software, addressing flaws that could allow remote code...
Critical 8.4 CVSS Flaws in Ashlar-Vellum Cobalt/Xenon/Argon Allow Code Execution via Malicious CAD Files
A CISA advisory published this week warns that multiple Ashlar‑Vellum professional CAD and 3D modeling applications harbor memory‑corruption vulnerabilities carrying a CVSS v4 base score of 8.4....