Cve
The latest Cve coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2025-54905: Critical Microsoft Office Vulnerability Patched—Users Urged to Update Now
Microsoft has released a security patch for CVE-2025-54905, a dangerous untrusted pointer dereference vulnerability in Microsoft Office that could let attackers seize control of an unpatched system...
How to Prioritize Patching with Microsoft’s Confidence Metric: Lessons from CVE-2025-54894
A single metric buried inside every Microsoft Security Response Center (MSRC) advisory could be the difference between a patching strategy that works and one that wastes precious time. Security teams...
Microsoft Copilot’s ‘No Link’ Prompt Trick Caused Monthslong Audit Log Gaps, No Customer Warning
Microsoft 365 Copilot silently suppressed document access records for months whenever users asked it to summarize a file without including a source link, leaving security teams with empty audit...
Microsoft Silently Patches Copilot Audit Blind Spot That Allowed Silent Data Exfiltration
Microsoft quietly fixed a critical gap in Microsoft 365 Copilot’s audit logging in mid‑August 2025 after researchers proved that a simple prompt tweak could make the AI assistant summarize...
Microsoft Quietly Patches Copilot Flaw That Let Insiders Access Files Without Audit Traces
A security researcher discovered that a simple prompt technique could make Microsoft 365 Copilot summarize sensitive corporate files without leaving the required Purview audit records. Microsoft...
Microsoft Quietly Patches Copilot Audit-Log Bypass, Keeps Customers in the Dark
Security researchers have uncovered a critical blind spot in Microsoft’s Purview audit logging for Copilot: certain prompts can retrieve sensitive file contents without leaving any trace in audit...
CISA's August 19 ICS Alert: Siemens Desigo CC SAML Bypass, Tigo Hardcoded Credentials, and EG4 Inverter Firmware Risks Exposed
Four industrial control system advisories released by CISA on August 19, 2025, pack an urgent punch for critical infrastructure operators, exposing dangerous flaws across building management...
Siemens Patches Critical Remote Exploits in SINEC Management Suite and Embedded OS, Urging Immediate ICS Updates
Siemens has delivered patches for a cascade of high-severity vulnerabilities across its SINEC network management system and embedded operating system, fixing flaws that could allow attackers to...
Siemens SINEC OS Advisory Exposes Over 100 Third-Party Kernel Flaws, Shifts Patch Burden to ProductCERT
Siemens has released a sprawling security advisory covering third-party components inside its SINEC operating system, cataloguing more than a hundred Linux kernel and userland vulnerabilities that...
Patch Now: Critical Windows PrintWorkflowUserSvc Flaws Allow Attackers to Gain SYSTEM Privileges
Microsoft's December 2024 Patch Tuesday included a fix for CVE-2024-49095, a high-severity elevation of privilege vulnerability in the Windows PrintWorkflowUserSvc service that could give attackers...
Windows File Explorer NTLM Leak: CVE-2025-50154 Exposes Credentials in Stealthy Attacks
A single unassuming ZIP archive can now become a weapon to steal Windows credentials, thanks to a newly patched flaw in Windows File Explorer. Microsoft's March 11, 2025 Patch Tuesday update fixed a...
Critical 8.4 CVSS Flaws in Ashlar-Vellum Cobalt/Xenon/Argon Allow Code Execution via Malicious CAD Files
A CISA advisory published this week warns that multiple Ashlar‑Vellum professional CAD and 3D modeling applications harbor memory‑corruption vulnerabilities carrying a CVSS v4 base score of 8.4....