Cve 2026 52930
The latest Cve 2026 52930 coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Extends Consumer Windows 10 Security Updates to 2027, Delaying Windows 11 Upgrades
Microsoft has quietly extended its consumer Windows 10 Extended Security Updates program until October 2027, giving home users extra time to receive critical patches. The move eases pressure to upgrade to Windows 11 but raises questions about long-term security and hardware compatibility. Enrollment fees apply, but the extension provides a crucial bridge for those reluctant or unable to switch.
Apple Supply Chain Breach: 200,000 Files Stolen in Tata Cyberattack
Hackers published 200,000 files (630GB) stolen from Tata Electronics, exposing confidential Apple manufacturing data. The breach, caused by an unpatched VPN, highlights severe supply chain security gaps. Both companies are investigating, while experts call for zero-trust architectures and stronger vendor oversight.
Kali365 Phishing-as-a-Service Exploits OAuth Device Code Flow to Steal Microsoft 365 Tokens, FBI Cautions
The FBI has issued a warning about Kali365, a phishing-as-a-service platform that abuses Microsoft's device code authentication to steal OAuth tokens, bypassing passwords and MFA. Organizations should educate users, monitor for suspicious logins, and consider disabling device code flow where not needed.
FBI Alert: Kali365 Phishing Kit Bypasses MFA via Device Code Phishing on Microsoft 365
The FBI warned in May 2026 about Kali365, a phishing-as-a-service platform that abuses Microsoft’s device code flow to hijack Microsoft 365 accounts without fake login pages. Distributed via Telegram, Kali365 enables attackers to bypass MFA by tricking users into entering a device code at the legitimate Microsoft login site. Organizations can mitigate risk by blocking or restricting device code authentication via Conditional Access and educating users about this specific attack pattern.
Microsoft Quietly Adds Second Year to Windows 10 Consumer ESU Program Through 2027
Microsoft has quietly extended its Consumer Extended Security Updates program for Windows 10, now offering a second year of critical security patches through October 12, 2027. Home users can enroll for $30 per year, buying two years of protection for $60 total, easing the pressure to upgrade to Windows 11 or replace incompatible hardware.
Microsoft Teams Wi-Fi Check-In Sparks Privacy Debate as It Automatically Tracks Office Attendance
Microsoft is introducing automatic Wi‑Fi‑based check‑in for Teams and Places in June 2026, eliminating manual location updates but raising significant privacy concerns. The feature integrates deeply with hybrid work tools, promising efficiency gains while forcing organizations to confront surveillance‑era ethics and compliance challenges.
Stack Exhaustion Bug in libxml2's RelaxNG Parser Exposes Windows Apps to Denial of Service
CVE-2026-0989 is a low-severity denial-of-service flaw in libxml2’s RelaxNG parser caused by uncontrolled recursion during nested schema includes. An attacker can craft a malicious XML schema to exhaust stack space and crash applications using the library. Windows users of popular third-party tools like Inkscape and GIMP are at risk, with patches now being distributed by software vendors.
Linux Kernel Patch Resolves Critical Intel Oak Trail Graphics Hang (CVE-2026-53279)
CVE-2026-53279 is a Linux kernel vulnerability in the gma500 DRM driver for Intel Oak Trail hardware, where a failed LVDS initialization leads to an I2C adapter hang and a system freeze. The fix, now available in stable kernels 6.10.7+, 6.6.46+, and 5.15.165+, ensures proper cleanup of the I2C adapter on failure. Although the hardware is rare, users of affected devices should update immediately to prevent potential denial-of-service attacks.
Critical AMD Linux GPU Bug Fixed: Deadlock Risk Spotted in AMDGPU Driver
Linux maintainers have patched CVE-2026-53293, a high-severity deadlock flaw in the AMDGPU driver that could freeze systems when reading GPU registers during a reset. The fix reorders locks to prevent concurrency conflicts. While the bug directly impacts Linux, Windows users running WSL2 or dual-boot setups with AMD GPUs should update their kernels to avoid potential host instability.
Linux Kernel ALSA Flaw Exposes Audio Subsystem: What Windows WSL Users Need to Know About CVE-2026-53291
CVE-2026-53291 is a newly disclosed Linux kernel vulnerability in the ALSA HDA Conexant audio driver that could crash systems due to a missing error check. The fix has been backported to stable kernels, and Windows users relying on WSL or dual-boot setups should ensure their Linux instances are updated to maintain stability and security.
CVE-2026-53297: Microsoft’s Azure MANA Driver Flaw Crashes Linux VMs with Kernel Panic
CVE-2026-53297 is a high-severity vulnerability in the Microsoft Azure MANA driver for Linux that causes kernel panics due to a NULL pointer dereference during failed power-management resume operations. Windows admins with Linux VMs in Azure should urgently apply kernel patches from their distribution to prevent denial-of-service attacks. The flaw underscores the need for robust patch management across hybrid cloud environments.
Linux SCSI Driver Flaw CVE-2026-53304 Triggers CPU Soft Lockup—Local DoS Threat for Many Systems
CVE-2026-53304 is a local denial-of-service vulnerability in the Linux kernel's SCSI generic driver. An attacker with local write access to sysfs can set the def_reserved_size parameter to an invalid value, causing an infinite loop and a CPU soft lockup. The flaw affects most Linux distributions, including those used in Windows Subsystem for Linux and VMs, and requires no special privileges beyond what many containers already provide.
CVE-2026-53313: A NULL Pointer in AMD’s Linux Display Driver Can Crash Your System – Here’s the Fix
The Linux kernel’s AMD display driver contains a NULL pointer dereference vulnerability (CVE-2026-53313) in the dc_dmub_srv error handling path, where diagnostic logging can crash the system. Published on June 26, 2026, the flaw allows local denial-of-service attacks on systems with AMD GPUs. A patch addressing the missing NULL check is available, and users are urged to update their kernels immediately.