Cve 2024 2756
The latest Cve 2024 2756 coverage — news, analysis, and updates from the WindowsNews.AI desk.
HOLLOWGRAPH: Attackers Turn Outlook Calendar Into a Secret Command Channel
Group-IB has exposed a targeted malware campaign, HOLLOWGRAPH, that turns Outlook calendar appointments into a covert command-and-control channel by hiding encrypted tasking in events dated 2050. The malware abuses the Microsoft Graph API with valid credentials, blending into legitimate cloud traffic, and refreshes access via DNS tunneling. This article breaks down the attack mechanics, explains who is most at risk, and delivers actionable steps for hunting signs of compromise and strengthening Microsoft 365 security postures.
NVIDIA Ends Game Ready Driver Support for GTX 1060: Security Updates Only Until 2028
NVIDIA has ended Game Ready driver support for the GeForce GTX 1060, providing only critical security updates through October 2028. This marks the end of an era for the once-dominant Steam GPU, and owners should plan upgrades or ensure security patches are installed.
WSUS Sync Failures: Microsoft Delivers Partial Fix, Leaving Production Servers in Limbo
Microsoft has acknowledged severe WSUS synchronization failures caused by accumulated publishing metadata, impacting enterprises since mid-July 2026. A fix is available only for new or rebuilt installations, leaving existing servers without a workaround and disrupting patch deployment through WSUS and Configuration Manager.
Entra Domain Services RC4 Kerberos Encryption Shutdown Starts July 6: Prepare Now with These Audit Steps
Microsoft is running an advance dependency test for RC4 encryption in Entra Domain Services starting July 6, 2026, to help organizations find and fix legacy Kerberos dependencies before the cipher is permanently disabled a week later. The test forces AES-only authentication, which can break apps and services that still use RC4. IT admins can prepare by enabling security audits, running a specific query for events 4768 and 4769, and methodically remediating each found dependency. A temporary rollback option exists during the test, but the real fix means moving all workloads to AES before the July 13 enforcement date.
Your SMS MFA Is Expiring: Microsoft’s 2027 Passkey Push and How to Prepare
Microsoft is retiring SMS and voice authentication in Entra ID by February 1, 2027. Starting September 1, 2026, users will be automatically prompted to set up passkeys. Organizations need to migrate users now to avoid lockouts.
Windows 11 Enterprise 23H2 Drops Support in 2026: Why 25H2, Not 24H2, Is the Upgrade You Need
Windows 11 Enterprise version 23H2 reaches end of support on November 10, 2026. IT administrators face a critical choice: upgrade to 24H2 and face another migration in 2027, or leap directly to 25H2 for a support window extending to 2028. This article explains why 25H2 is the strategic default and provides a phased migration plan to beat the deadline.
Dell Windows 11 Overheating Fix: KB5121767 Emergency Patch Ends Shutdowns and Battery Drain
Microsoft has released an out-of-band update, KB5121767, to fix overheating, shutdowns, and battery drain on select Dell laptops running Windows 11 24H2 or 25H2. The emergency patch resolves a conflict between the July 2026 Patch Tuesday update and Intel’s Innovation Platform Framework driver, which disrupted power and thermal management. While only a limited set of Dell models are affected, users experiencing symptoms should install the update via Windows Update to restore normal operation and security patch levels.
Critical ServiceNow RCE Flaws Under Active Attack: What Users Must Do Now
ServiceNow users are facing active attacks targeting two critical unauthenticated RCE flaws, CVE-2024-4879 and CVE-2024-5217. CISA added both to its Known Exploited Vulnerabilities catalog in July 2024, confirming exploitation. This article explains who is affected, the patch levels required, and step-by-step actions for hosted, self-hosted, and partner-managed deployments to secure their instances immediately.
Screenshot Block for Protected PDFs Arrives on OneDrive Web Next Month—But There's a Browser Catch
Microsoft will enforce screenshot blocking for PDFs with Purview sensitivity labels that deny copy permissions when viewed through OneDrive or SharePoint in Edge, starting August 2026. Other browsers and mobile are unsupported, making Edge the only compliant viewer. IT admins must review label configurations, browser policies, and user training to avoid disruptions.
CVE-2026-63794: Linux KVM Host Bug Exposes AMD SEV-Protected Windows VMs to Memory Overflow
A buffer overflow vulnerability in Linux KVM's AMD SEV code, tracked as CVE-2026-63794, can compromise the memory encryption that protects virtual machines, including Windows guests. While Windows updates won't fix it, host administrators must patch their Linux KVM servers with a kernel version that includes the fix (e.g., 5.10.260 or later), and then reboot. Cloud customers should verify their provider has addressed the issue; on-prem admins have clear steps to patch and verify.
Realtek Wi-Fi Memory Leak Patched in Linux: What Windows Users Need to Know
A memory leak in the Linux kernel's Realtek rtw88 USB Wi-Fi driver has been patched in the latest stable kernel updates. While the flaw, tracked as CVE-2026-63821, can lead to system memory exhaustion under specific conditions, it does not affect Windows systems. Users of affected Linux devices should update their kernels; Windows users need take no action.
WSL 2 Kernel Vulnerability Allows BPF Programs to Modify File Cache — Here’s How to Update
A new Linux kernel vulnerability, CVE-2026-63830, allows BPF programs to write to file-backed page-cache data due to a missing ownership tag in scatterlist transforms. WSL 2 on Windows runs a vulnerable Linux kernel and needs an immediate update via `wsl --update`. The patch is available in stable kernel series; all Linux systems should be updated to prevent integrity failures.
MediaTek Wi-Fi Kernel Bug Patched: Why Windows PCs Are Safe and Who Still Needs to Update
Linux kernel CVE-2026-63832 fixes a MediaTek MT7925 Wi-Fi driver bug causing kernel list corruption and crashes. Windows is not affected because it uses different drivers. However, users with dual-boot systems or Linux VMs with passthrough should update to kernel 6.18.38 or 7.1.3. This article explains the flaw, who really needs to act, and how to stay safe.