Cyberattack
The latest Cyberattack coverage — news, analysis, and updates from the WindowsNews.AI desk.
Safeguarding Service Principals: Lessons from the Commvault Azure Security Breach
Overview In early 2025, Commvault, a leading data protection and information management company, experienced a significant security incident within its Azure environment. This breach, attributed to a...
Critical CVE-2025-4338 Vulnerability Discovered in Lantronix Device Installer Threatening Legacy Devices
Lantronix Device Installer, a utility long relied upon by IT administrators for device discovery, configuration, and upgrade management across Lantronix networking hardware, now finds itself at the...
Microsoft and Global Agencies Dismantle Lumma Malware Network in Landmark Cybercrime Takedown
Introduction In a significant stride against cybercrime, Microsoft, in collaboration with global law enforcement agencies, has successfully dismantled the Lumma malware network. This operation...
CISA's 2025 KEV Catalog: Essential Guide to Active Cyber Threats & Defense Strategies
The digital battlefield is more volatile than ever, with state-sponsored hackers, ransomware syndicates, and opportunistic cybercriminals weaponizing software flaws at unprecedented speeds—making...
Safeguarding Microsoft 365 Against the Surge in HTML-Based Phishing Attacks
In recent months, cybersecurity experts have observed a significant uptick in sophisticated phishing attacks targeting Microsoft 365 users. These attacks often employ malicious HTML attachments to...
Windows 11 Flaws Exposed in 3-Day Pwn2Own Berlin Hacking Event
Introduction The Pwn2Own Berlin 2025 competition, held from May 15 to 17 at the OffensiveCon conference in Berlin, Germany, showcased the prowess of ethical hackers in uncovering zero-day...
Pwn2Own Berlin 2025 Uncovers Critical Vulnerabilities in Windows 11, Linux, Virtualization, and AI Systems
Introduction The cybersecurity community was electrified by the revelations at Pwn2Own Berlin 2025, a high-profile hacking competition organized by Trend Micro's Zero Day Initiative (ZDI) and hosted...
Critical Windows Scripting Engine Exploit (CVE-2025-30397) Threatens Unpatched Systems
A chilling wave of cyberattacks targeting unpatched Windows systems has begun exploiting a critical memory corruption vulnerability in the legacy Scripting Engine, designated CVE-2025-30397, which...
Critical Windows Media Vulnerability CVE-2025-29962 Exposes Systems to Remote Takeover
A newly discovered vulnerability in Windows Media components has sent shockwaves through the cybersecurity community, exposing millions of systems to potential takeover by remote attackers....
Defending Microsoft Dynamics 365 from Phishing: Multi-Layered Security Strategies
The familiar rhythm of daily business operations increasingly pulses through cloud platforms like Microsoft Dynamics 365 (D365), making them the lifeblood of modern enterprises. Yet, this critical...
Legacy Windows Telnet Zero-Click Flaw Grants Remote Admin Access via NTLM Bypass
Overview Microsoft’s Telnet Server, a legacy component rooted in the early days of Windows networking, is now the focus of serious cybersecurity concerns due to the discovery of a critical...