Live
Windows 10 August Update Opens ESU Enrollment, Hardens Secure Boot Against Rollback·MSFT +2.1%Domain Controllers at Risk: Microsoft’s August Update Closes Kerberos dMSA Vulnerability Amid 100+ Fixes·NVDA +0.2%Microsoft Teams Flaw CVE-2025-53783: Unauthenticated RCE via Heap Overflow Sparks Urgent Patching·GOOGL +1.7%CVE-2025-47957: Decoding Microsoft’s Critical Word Use-After-Free Vulnerability·AMZN +1.1%Microsoft Patches Dynamics 365 On-Prem Flaw CVE-2025-53728 That Exposes Sensitive Data·MSFT +2.1%Uninitialized Resource Bug in Windows RRAS Could Expose Corporate VPN Secrets, Microsoft Urges Patch·NVDA +0.2%CVE-2025-33057: Microsoft Patches LSASS Null Pointer DoS That Can Crash Domain Controllers·GOOGL +1.7%Critical MSMQ Type‑Confusion Bug Allows Remote Code Execution, Microsoft Urges Immediate Patching·AMZN +1.1%Windows 10 August Update Opens ESU Enrollment, Hardens Secure Boot Against Rollback·MSFT +2.1%Domain Controllers at Risk: Microsoft’s August Update Closes Kerberos dMSA Vulnerability Amid 100+ Fixes·NVDA +0.2%Microsoft Teams Flaw CVE-2025-53783: Unauthenticated RCE via Heap Overflow Sparks Urgent Patching·GOOGL +1.7%CVE-2025-47957: Decoding Microsoft’s Critical Word Use-After-Free Vulnerability·AMZN +1.1%Microsoft Patches Dynamics 365 On-Prem Flaw CVE-2025-53728 That Exposes Sensitive Data·MSFT +2.1%Uninitialized Resource Bug in Windows RRAS Could Expose Corporate VPN Secrets, Microsoft Urges Patch·NVDA +0.2%CVE-2025-33057: Microsoft Patches LSASS Null Pointer DoS That Can Crash Domain Controllers·GOOGL +1.7%Critical MSMQ Type‑Confusion Bug Allows Remote Code Execution, Microsoft Urges Immediate Patching·AMZN +1.1%

Cybersecurity

The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 11:13 PM
Latest Most Read Breaking
Sort
21h2 · 22h2

Windows 10 August Update Opens ESU Enrollment, Hardens Secure Boot Against Rollback

Microsoft’s cumulative update KB5063709, released on August 12, 2025, arrives at a critical juncture for Windows 10 users. With the end-of-support deadline looming on October 14, 2025, the patch...

Advertisement
Cross-site Scripting · Csp

Microsoft Patches Dynamics 365 On-Prem Flaw CVE-2025-53728 That Exposes Sensitive Data

Microsoft has released a security update to fix an information disclosure vulnerability in Dynamics 365 on-premises versions, tracked as CVE-2025-53728. The flaw, classified as allowing an...

SE Security Desk·49w ago
Cve-2025-53719 · Cybersecurity

Uninitialized Resource Bug in Windows RRAS Could Expose Corporate VPN Secrets, Microsoft Urges Patch

Microsoft has disclosed a new information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS), tracked as CVE-2025-53719, that could allow an authenticated attacker to...

SE Security Desk·49w ago
Active Directory · Authentication

CVE-2025-33057: Microsoft Patches LSASS Null Pointer DoS That Can Crash Domain Controllers

Microsoft has released a security update for a vulnerability that allows an attacker with network access to crash the Local Security Authority Subsystem Service (LSASS) and trigger a...

SE Security Desk·49w ago
Attack Surface · Cve-2025-53145

Critical MSMQ Type‑Confusion Bug Allows Remote Code Execution, Microsoft Urges Immediate Patching

Microsoft has released a security update addressing CVE-2025-53145, a type confusion vulnerability in Windows Message Queuing (MSMQ) that could allow an authenticated attacker to remotely execute...

SE Security Desk·49w ago
Afd.sys · Cve-2025-53147

New AFD.sys Use-After-Free (CVE-2025-53147) Demands Immediate Patching as Kernel Exploit Chains Resurface

A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) tracked as CVE-2025-53147 allows a local attacker to escalate privileges to SYSTEM, Microsoft disclosed...

SE Security Desk·49w ago
Cve · Cve-2024-49095

Patch Now: Critical Windows PrintWorkflowUserSvc Flaws Allow Attackers to Gain SYSTEM Privileges

Microsoft's December 2024 Patch Tuesday included a fix for CVE-2024-49095, a high-severity elevation of privilege vulnerability in the Windows PrintWorkflowUserSvc service that could give attackers...

SE Security Desk·49w ago
Cve-2025-50176 · Cybersecurity

Microsoft Patches CVE-2025-50176: DirectX Kernel Type-Confusion Bug Allows SYSTEM Compromise

Microsoft has issued a critical security update for CVE-2025-50176, a type-confusion vulnerability in the DirectX Graphics Kernel (dxgkrnl) that allows an authenticated attacker to execute arbitrary...

SE Security Desk·49w ago
Acl · Cisa

Microsoft Discloses Critical RRAS Heap Overflow (CVE-2025-50164) — Patch Now to Block Remote Code Execution

Microsoft has issued a high-severity security advisory for a heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) that could allow unauthenticated attackers to execute...

SE Security Desk·49w ago