Cybersecurity
The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows 10 Support Ends October 2025: Upgrade, Replace, or Pay for Security?
Microsoft will pull the plug on Windows 10 on October 14, 2025. After that date, the operating system that has powered hundreds of millions of PCs since 2015 will stop receiving security updates, bug...
5 Years After Support Ended, Windows 7 Users Are Playing a Deadly Game with Hackers
More than half a decade has passed since Microsoft issued the last free security update for Windows 7, yet millions of machines still run the defunct operating system, turning each into a ticking...
Bitwarden PDF XSS Flaw (CVE-2025-5138) Exposes Passwords: Users Urged to Patch Immediately
A critical cross-site scripting vulnerability in Bitwarden’s PDF file handling can allow attackers to hijack user vaults by simply uploading a malicious document. Tracked as CVE-2025-5138, the flaw...
91% of AD Environments Vulnerable to Windows Server 2025 BadSuccessor Exploit
A dangerous privilege escalation vulnerability nestled inside Windows Server 2025’s delegated Managed Service Account (dMSA) architecture hands attackers a trivially exploitable path to full Active...
Windows Server 2025’s dMSA Opens a Silent Domain Takeover Path – Here’s the Fix
Attackers can now hijack entire Windows domains by exploiting a fundamental design flaw in the new delegated Managed Service Accounts (dMSAs) introduced with Windows Server 2025, security experts...
Rising AI Workloads Crack Hybrid Cloud Security: 70% Deem Public Cloud Risky, Breaches Hit 55%
The rapid integration of artificial intelligence into business operations has triggered an unprecedented surge in cyber threats, with breach rates climbing to 55% and 70% of IT leaders now labeling...
Oracle TNS Flaw CVE-2025-30733: Memory Leak Exposes Sensitive Data Over Network Without Authentication
Oracle's April 2025 Critical Patch Update fixes a startling memory leak in the Transparent Network Substrate (TNS) listener that can spill sensitive system data to unauthenticated remote users....
SharpSuccessor Exploit Weaponizes Windows Server 2025 dMSA Flaw for Instant Domain Admin
A new proof-of-concept tool named SharpSuccessor is now publicly available, providing attackers with an automated method to exploit a critical privilege escalation vulnerability in Windows Server...
CERT-In Warns of Active Exploits: Critical Microsoft Vulnerabilities Threaten Millions of Indian Windows Users
On May 15, 2025, the Indian Computer Emergency Response Team (CERT-In) issued a stark warning to millions of Windows users across the country: multiple critical vulnerabilities in Microsoft’s...
Defendnot Exploits Undocumented Windows API to Silently Disable Microsoft Defender
{ "title": "Defendnot Exploits Undocumented Windows API to Silently Disable Microsoft Defender", "content": "A newly developed proof-of-concept tool named Defendnot can disarm Microsoft Defender,...
Microsoft Patches Hidden Danger in Old Windows Installation Images with Offline Defender Update
{ "title": "Microsoft Patches Hidden Danger in Old Windows Installation Images with Offline Defender Update", "content": "Windows ISOs are the backbone of PC deployment, but every time someone...
CERT-In Sounds Alarm: Critical Windows, Office, Azure Bugs Threaten Enterprises — Patch Now
India's premier cybersecurity agency, the Indian Computer Emergency Response Team (CERT-In), has issued a high-risk advisory warning that a slew of Microsoft products harbor severe vulnerabilities...