Live
July Security Update Stops AD CS 'Certighost' Attack That Could Let Users Take Over Entire Domains·MSFT +2.1%Microsoft Pulls Two Long-Awaited Search Features from Teams and Outlook Roadmap·NVDA +0.2%Stop Cluttering Your Taskbar: The Windows 11 Guide to Pinning Apps, Folders, and Websites·GOOGL +1.7%New Windows 11 Update Lets Admins Silently Accept SSO Permissions on Enterprise PCs·AMZN +1.1%Echo Weaver's Time-Loop Metroidvania Rewards Player Insight Over Grinding – Demo Out Now on Steam·MSFT +2.1%HackerNoon’s 220-Post Developer Reading List Lands: How Windows Users Can Cut Through the Noise·NVDA +0.2%Microphone Testing in 2026: Why Old Windows Tricks No Longer Work and What to Do Instead·GOOGL +1.7%The Hidden Windows Setting That Repairs Microsoft Edge Without Losing Your Data·AMZN +1.1%July Security Update Stops AD CS 'Certighost' Attack That Could Let Users Take Over Entire Domains·MSFT +2.1%Microsoft Pulls Two Long-Awaited Search Features from Teams and Outlook Roadmap·NVDA +0.2%Stop Cluttering Your Taskbar: The Windows 11 Guide to Pinning Apps, Folders, and Websites·GOOGL +1.7%New Windows 11 Update Lets Admins Silently Accept SSO Permissions on Enterprise PCs·AMZN +1.1%Echo Weaver's Time-Loop Metroidvania Rewards Player Insight Over Grinding – Demo Out Now on Steam·MSFT +2.1%HackerNoon’s 220-Post Developer Reading List Lands: How Windows Users Can Cut Through the Noise·NVDA +0.2%Microphone Testing in 2026: Why Old Windows Tricks No Longer Work and What to Do Instead·GOOGL +1.7%The Hidden Windows Setting That Repairs Microsoft Edge Without Losing Your Data·AMZN +1.1%

Cve 2025 0451

The latest Cve 2025 0451 coverage — news, analysis, and updates from the WindowsNews.AI desk.

13 stories in view AI assisted desk updated 10:34 PM
Latest Most Read Breaking
Sort
CVE-2026-54121 · Certighost

July Security Update Stops AD CS 'Certighost' Attack That Could Let Users Take Over Entire Domains

Microsoft's July 2026 security updates fix CVE-2026-54121, a critical AD CS flaw that let low-privilege users impersonate Domain Controllers and compromise entire Windows domains. The patch adds validation to the CA's chase enrollment fallback, and administrators should apply it immediately to prevent domain takeover.

Advertisement
Bing Images · Remote Code Execution

A Bug in Bing Images Let Hackers Run Code on Microsoft’s Servers—It’s Already Fixed

Microsoft fixed three critical vulnerabilities in Bing Images and the Devices Pricing Program that allowed remote code execution on production servers via crafted images. Because the patches were server-side, Bing users need take no action. The incident highlights the hidden danger in every image upload pipeline and offers urgent lessons for developers and IT administrators who handle untrusted content.

SE Security Desk·4h ago
CMMC Level 2 · CUI Security

CMMC Level 2 Uncertainty Isn’t a Break—New Kiteworks–A-LIGN Pact Pushes Data Governance First

Kiteworks and A-LIGN have partnered to help Defense Industrial Base organizations prepare for CMMC Level 2 assessments by combining a data governance platform with independent auditing services. The announcement comes amid a federal review that has paused new third-party assessment mandates, but contractors still must protect Controlled Unclassified Information under existing DFARS rules. The piece explains what the partnership offers, where common compliance gaps occur, and how MSPs can build recurring services around CMMC readiness.

SE Security Desk·6h ago
Windows 10 · NVIDIA

After October 2026, Your Windows 10 Gaming PC Won't Get New NVIDIA Drivers. Here's What to Do Now.

NVIDIA’s Game Ready driver support for Windows 10 ends in October 2026, cutting off day-one optimizations for new games. Combined with Windows 10’s end of support, gamers face growing security risks and diminishing compatibility. This guide explains the timeline, the impact on different GPU owners, and the steps to take now—from enrolling in ESU to upgrading to Windows 11.

SE Security Desk·7h ago ·1 views
Apple · Hide My Email

Apple Patches Year-Long Hide My Email Flaw That Exposed Real Addresses in Mail Logs

Apple's July 2026 patch for the Hide My Email flaw ends a year-long risk that real email addresses were exposed through bounce messages. While future use is safe, aliases created before July 7, 2026 may still exist in third-party server logs. Users should replace sensitive older aliases and secure their primary inboxes.

SE Security Desk·9h ago
LG Monitors · McAfee Ads

LG Monitors Secretly Installed McAfee Ads on Windows 11 Until Microsoft Stepped In

Windows 11 users found that connecting an LG monitor could silently install a companion app that pushed McAfee trial promotions. After intervention by Microsoft, LG agreed to disable the ads, but the app remains. We explain what happened, how to remove it, and how to prevent similar auto-installs.

SE Security Desk·10h ago ·1 views
Lg Monitors · Mcafee

LG kills McAfee ads in monitor app after Microsoft steps in — what Windows 11 users need to know

After user backlash, LG has disabled the McAfee pop-up in its monitor software following intervention from Microsoft. The fix removes the most intrusive advertisement, but the broader issue of driver-delivered promotional software remains unresolved. Windows 11 users should check installed apps and startup items for unwanted utilities.

SE Security Desk·11h ago ·2 views
Dns Poisoning · Microsoft 365

Hotel Wi‑Fi Gateways Are Now Stealing Microsoft 365 Sessions—Here’s What to Do Before Your Next Trip

A new attack campaign compromises hotel Wi‑Fi gateways to redirect Microsoft 365 users to fake login pages and steal credentials, session tokens, and MFA approvals. Active since June 2026, it uses DNS poisoning, WPAD abuse, and device‑code authentication tricks to target business travelers. The most effective defense is an always‑on, full‑tunnel VPN combined with Entra ID policy restrictions.

SE Security Desk·11h ago
Windows 10 · Extended Security Updates

Windows 10 Free Security Update Program Extended to October 2027: How to Enroll Right Now

Microsoft has extended the free consumer Extended Security Updates program for Windows 10 by an additional year, now ending on October 12, 2027. Existing enrollees receive the extension automatically, while new users can still sign up for free by syncing Windows settings to a Microsoft account. The move offers a practical security lifeline for the roughly 28% of Windows users still on Windows 10, many on hardware that cannot run Windows 11.

SE Security Desk·12h ago
Software Supply Chain · Federal Cybersecurity

The White House just killed software attestation rules—here’s how to secure your development pipeline anyway

The Trump administration’s rollback of federal software attestation rules leaves agencies to secure their own development pipelines. This article explains how centrally managed Windows environments can close the gap and provides a step-by-step action plan for federal IT teams to achieve software sovereignty now.

SE Security Desk·14h ago