Live
Windows 11 Release Preview Adds Voice Isolation, Touchpad Controls, and Wider Biometric Security·MSFT +2.1%GPT-5.6 Claims to Solve Erdős Problem #119 with a One-Page Proof: Here’s Why Skeptics Are Wary·NVDA +0.2%Windows 11 Beta Build 26220.8925: Start Menu Sections Become Optional, Sizes Go Small or Large, and File Explorer Drops the Kilobyte Obsession·GOOGL +1.7%Windows 11’s Start Menu Can Finally Be Resized—and That’s Just the Start·AMZN +1.1%NotebookLM’s AI Podcasts Can Distort News Stories: What Windows Users Need to Know·MSFT +2.1%Microsoft 365 Copilot Gets Granular Web Control: Admins Can Exclude Specific Sites from Grounding·NVDA +0.2%Microsoft Cancels Teams Frontline BYOD Wizard, Retires Preview This August·GOOGL +1.7%Microsoft Cancels Copilot License Justification Field: What IT Admins Need to Do Now·AMZN +1.1%Windows 11 Release Preview Adds Voice Isolation, Touchpad Controls, and Wider Biometric Security·MSFT +2.1%GPT-5.6 Claims to Solve Erdős Problem #119 with a One-Page Proof: Here’s Why Skeptics Are Wary·NVDA +0.2%Windows 11 Beta Build 26220.8925: Start Menu Sections Become Optional, Sizes Go Small or Large, and File Explorer Drops the Kilobyte Obsession·GOOGL +1.7%Windows 11’s Start Menu Can Finally Be Resized—and That’s Just the Start·AMZN +1.1%NotebookLM’s AI Podcasts Can Distort News Stories: What Windows Users Need to Know·MSFT +2.1%Microsoft 365 Copilot Gets Granular Web Control: Admins Can Exclude Specific Sites from Grounding·NVDA +0.2%Microsoft Cancels Teams Frontline BYOD Wizard, Retires Preview This August·GOOGL +1.7%Microsoft Cancels Copilot License Justification Field: What IT Admins Need to Do Now·AMZN +1.1%

Cve 2025 40205

The latest Cve 2025 40205 coverage — news, analysis, and updates from the WindowsNews.AI desk.

13 stories in view AI assisted desk updated 12:38 AM
Latest Most Read Breaking
Sort
Microsoft 365 · Sharepoint

Microsoft Finally Forces Internal SharePoint Links to Expire — What Admins Must Do Now

Microsoft launched expiration policies for internal “People in your organization” sharing links in SharePoint and OneDrive, giving admins control to set maximum and recommended lifetimes. The change closes a governance gap but requires careful rollout to avoid breaking permanent navigation links, automations, and user workflows. This service-journalism piece explains what the policy does, practical impacts for employees, site owners, and IT pros, and provides a step-by-step implementation guide.

Security

Microsoft 365 Calendar Hijacked as C2 Channel in New HOLLOWGRAPH Malware

HOLLOWGRAPH, a newly discovered Windows malware, abuses Microsoft 365 calendar events via Microsoft Graph API to covertly receive commands and exfiltrate data, while using DNS tunneling to refresh stolen credentials. Discovered by Group-IB, the implant has targeted a handful of Israeli entities, blending into legitimate Microsoft 365 traffic to evade traditional security controls.

Security Desk·6h ago ·5 min
Security

Microsoft Fixes WSUS Sync for New Servers, But Existing Ones Wait for July 2026 Patches

Microsoft fixed a WSUS synchronization outage for new and rebuilt servers on July 18, 2026, but administrators running long‑standing WSUS instances still cannot access July’s security patches. The incident, caused by an accumulation of publishing metadata at Microsoft’s end, disrupted patch deployment pipelines for organizations relying on WSUS and Configuration Manager. Microsoft is preparing guidance to help existing servers safely remove the problematic metadata, but until then, the July updates remain out of reach for many.

Security Desk·6h ago ·5 min
Security

Why Microsoft Is Forcing a 72-Hour Patch Deadline on Windows PCs—and What IT Must Do Now

Microsoft is now recommending enterprises deploy Windows quality updates within three days, with a deadline that forces restarts if users postpone. This article explains the new baseline settings, the AI-driven security threat that prompted the shift, and practical steps IT admins must take to implement the 3-day cycle without disrupting operations. It covers policy configuration, exception management, and user communication strategies, emphasizing that lengthy patch delays are no longer a safe default.

Security Desk·8h ago ·5 min
Advertisement
Hollowgraph · Microsoft 365 Security

HOLLOWGRAPH: Attackers Turn Outlook Calendar Into a Secret Command Channel

Group-IB has exposed a targeted malware campaign, HOLLOWGRAPH, that turns Outlook calendar appointments into a covert command-and-control channel by hiding encrypted tasking in events dated 2050. The malware abuses the Microsoft Graph API with valid credentials, blending into legitimate cloud traffic, and refreshes access via DNS tunneling. This article breaks down the attack mechanics, explains who is most at risk, and delivers actionable steps for hunting signs of compromise and strengthening Microsoft 365 security postures.

SE Security Desk·9h ago ·2 views
NVIDIA · GTX 1060

NVIDIA Ends Game Ready Driver Support for GTX 1060: Security Updates Only Until 2028

NVIDIA has ended Game Ready driver support for the GeForce GTX 1060, providing only critical security updates through October 2028. This marks the end of an era for the once-dominant Steam GPU, and owners should plan upgrades or ensure security patches are installed.

SE Security Desk·9h ago
WSUS · Patch Management

WSUS Sync Failures: Microsoft Delivers Partial Fix, Leaving Production Servers in Limbo

Microsoft has acknowledged severe WSUS synchronization failures caused by accumulated publishing metadata, impacting enterprises since mid-July 2026. A fix is available only for new or rebuilt installations, leaving existing servers without a workaround and disrupting patch deployment through WSUS and Configuration Manager.

SE Security Desk·9h ago
Microsoft Entra Domain Services · RC4 Deprecation

Entra Domain Services RC4 Kerberos Encryption Shutdown Starts July 6: Prepare Now with These Audit Steps

Microsoft is running an advance dependency test for RC4 encryption in Entra Domain Services starting July 6, 2026, to help organizations find and fix legacy Kerberos dependencies before the cipher is permanently disabled a week later. The test forces AES-only authentication, which can break apps and services that still use RC4. IT admins can prepare by enabling security audits, running a specific query for events 4768 and 4769, and methodically remediating each found dependency. A temporary rollback option exists during the test, but the real fix means moving all workloads to AES before the July 13 enforcement date.

SE Security Desk·10h ago
Microsoft Entra · Passkeys

Your SMS MFA Is Expiring: Microsoft’s 2027 Passkey Push and How to Prepare

Microsoft is retiring SMS and voice authentication in Entra ID by February 1, 2027. Starting September 1, 2026, users will be automatically prompted to set up passkeys. Organizations need to migrate users now to avoid lockouts.

SE Security Desk·11h ago
Windows 11 · End Of Servicing

Windows 11 Enterprise 23H2 Drops Support in 2026: Why 25H2, Not 24H2, Is the Upgrade You Need

Windows 11 Enterprise version 23H2 reaches end of support on November 10, 2026. IT administrators face a critical choice: upgrade to 24H2 and face another migration in 2027, or leap directly to 25H2 for a support window extending to 2028. This article explains why 25H2 is the strategic default and provides a phased migration plan to beat the deadline.

SE Security Desk·13h ago
KB5121767 · Dell Laptops

Dell Windows 11 Overheating Fix: KB5121767 Emergency Patch Ends Shutdowns and Battery Drain

Microsoft has released an out-of-band update, KB5121767, to fix overheating, shutdowns, and battery drain on select Dell laptops running Windows 11 24H2 or 25H2. The emergency patch resolves a conflict between the July 2026 Patch Tuesday update and Intel’s Innovation Platform Framework driver, which disrupted power and thermal management. While only a limited set of Dell models are affected, users experiencing symptoms should install the update via Windows Update to restore normal operation and security patch levels.

SE Security Desk·13h ago
ServiceNow · CVE-2024-4879

Critical ServiceNow RCE Flaws Under Active Attack: What Users Must Do Now

ServiceNow users are facing active attacks targeting two critical unauthenticated RCE flaws, CVE-2024-4879 and CVE-2024-5217. CISA added both to its Known Exploited Vulnerabilities catalog in July 2024, confirming exploitation. This article explains who is affected, the patch levels required, and step-by-step actions for hosted, self-hosted, and partner-managed deployments to secure their instances immediately.

SE Security Desk·15h ago
Microsoft Edge · Microsoft Purview

Screenshot Block for Protected PDFs Arrives on OneDrive Web Next Month—But There's a Browser Catch

Microsoft will enforce screenshot blocking for PDFs with Purview sensitivity labels that deny copy permissions when viewed through OneDrive or SharePoint in Edge, starting August 2026. Other browsers and mobile are unsupported, making Edge the only compliant viewer. IT admins must review label configurations, browser policies, and user training to avoid disruptions.

SE Security Desk·15h ago