Cybersecurity
The latest Cybersecurity coverage — news, analysis, and updates from the WindowsNews.AI desk.
Windows 10 August Update Opens ESU Enrollment, Hardens Secure Boot Against Rollback
Microsoft’s cumulative update KB5063709, released on August 12, 2025, arrives at a critical juncture for Windows 10 users. With the end-of-support deadline looming on October 14, 2025, the patch...
Domain Controllers at Risk: Microsoft’s August Update Closes Kerberos dMSA Vulnerability Amid 100+ Fixes
Microsoft’s August 2025 Patch Tuesday release lands with an urgent fix for a Kerberos vulnerability that could allow attackers to escalate to domain administrator, alongside more than a dozen other...
Microsoft Teams Flaw CVE-2025-53783: Unauthenticated RCE via Heap Overflow Sparks Urgent Patching
Microsoft has published a security advisory for CVE-2025-53783, a heap-based buffer overflow in Microsoft Teams that allows an unauthorized attacker to execute code remotely over a network. The...
CVE-2025-47957: Decoding Microsoft’s Critical Word Use-After-Free Vulnerability
Microsoft’s security team recently pushed out a fix for a critical vulnerability in Microsoft Word that, if left unpatched, could give attackers a direct path to executing malicious code on a...
Microsoft Patches Dynamics 365 On-Prem Flaw CVE-2025-53728 That Exposes Sensitive Data
Microsoft has released a security update to fix an information disclosure vulnerability in Dynamics 365 on-premises versions, tracked as CVE-2025-53728. The flaw, classified as allowing an...
Uninitialized Resource Bug in Windows RRAS Could Expose Corporate VPN Secrets, Microsoft Urges Patch
Microsoft has disclosed a new information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS), tracked as CVE-2025-53719, that could allow an authenticated attacker to...
CVE-2025-33057: Microsoft Patches LSASS Null Pointer DoS That Can Crash Domain Controllers
Microsoft has released a security update for a vulnerability that allows an attacker with network access to crash the Local Security Authority Subsystem Service (LSASS) and trigger a...
Critical MSMQ Type‑Confusion Bug Allows Remote Code Execution, Microsoft Urges Immediate Patching
Microsoft has released a security update addressing CVE-2025-53145, a type confusion vulnerability in Windows Message Queuing (MSMQ) that could allow an authenticated attacker to remotely execute...
New AFD.sys Use-After-Free (CVE-2025-53147) Demands Immediate Patching as Kernel Exploit Chains Resurface
A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) tracked as CVE-2025-53147 allows a local attacker to escalate privileges to SYSTEM, Microsoft disclosed...
Patch Now: Critical Windows PrintWorkflowUserSvc Flaws Allow Attackers to Gain SYSTEM Privileges
Microsoft's December 2024 Patch Tuesday included a fix for CVE-2024-49095, a high-severity elevation of privilege vulnerability in the Windows PrintWorkflowUserSvc service that could give attackers...
Microsoft Patches CVE-2025-50176: DirectX Kernel Type-Confusion Bug Allows SYSTEM Compromise
Microsoft has issued a critical security update for CVE-2025-50176, a type-confusion vulnerability in the DirectX Graphics Kernel (dxgkrnl) that allows an authenticated attacker to execute arbitrary...
Microsoft Discloses Critical RRAS Heap Overflow (CVE-2025-50164) — Patch Now to Block Remote Code Execution
Microsoft has issued a high-severity security advisory for a heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) that could allow unauthenticated attackers to execute...