Live
Windows Defender Firewall Type Confusion Bug Opens Door to SYSTEM-Level Compromise·MSFT +2.1%Urgent Patch Alert: Windows VHD Bug CVE-2025-54112 Enables Full System Compromise·NVDA +0.2%Microsoft Patches Type Confusion Flaw in Windows Defender Firewall That Risks System Compromise·GOOGL +1.7%Critical Windows Graphics Race Condition (CVE-2025-53807) Hands Out SYSTEM Access—Urgent Patch Guide·AMZN +1.1%CVE-2025-53804: Windows Kernel Vulnerability Exposes Sensitive Data—Patch Now and Harden Defenses·MSFT +2.1%Microsoft AutoUpdate Vulnerability Lets Attackers Escalate to Root on macOS via Symlink Tricks·NVDA +0.2%Urgent Excel Security Fix: Use-After-Free Bug Opens Door to Code Execution — Mac LTSC Patches Delayed·GOOGL +1.7%CVE-2025-54902: Excel Out-of-Bounds Read Flaw Could Let Attackers Seize PCs—Mac Updates Still Missing·AMZN +1.1%Windows Defender Firewall Type Confusion Bug Opens Door to SYSTEM-Level Compromise·MSFT +2.1%Urgent Patch Alert: Windows VHD Bug CVE-2025-54112 Enables Full System Compromise·NVDA +0.2%Microsoft Patches Type Confusion Flaw in Windows Defender Firewall That Risks System Compromise·GOOGL +1.7%Critical Windows Graphics Race Condition (CVE-2025-53807) Hands Out SYSTEM Access—Urgent Patch Guide·AMZN +1.1%CVE-2025-53804: Windows Kernel Vulnerability Exposes Sensitive Data—Patch Now and Harden Defenses·MSFT +2.1%Microsoft AutoUpdate Vulnerability Lets Attackers Escalate to Root on macOS via Symlink Tricks·NVDA +0.2%Urgent Excel Security Fix: Use-After-Free Bug Opens Door to Code Execution — Mac LTSC Patches Delayed·GOOGL +1.7%CVE-2025-54902: Excel Out-of-Bounds Read Flaw Could Let Attackers Seize PCs—Mac Updates Still Missing·AMZN +1.1%

Endpoint Security

The latest Endpoint Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 9:46 PM
Latest Most Read Breaking
Sort
Cisa · Cve-2025-54109

Windows Defender Firewall Type Confusion Bug Opens Door to SYSTEM-Level Compromise

A severe type confusion vulnerability in the Windows Defender Firewall service, tracked as CVE-2025-54109, could allow an attacker with a low-privilege local account to seize complete SYSTEM control...

Advertisement
Asr · Cve-2025-53804

CVE-2025-53804: Windows Kernel Vulnerability Exposes Sensitive Data—Patch Now and Harden Defenses

Microsoft has confirmed a new information disclosure vulnerability in the Windows kernel, tracked as CVE-2025-53804, that allows a local attacker to extract sensitive data from protected kernel...

SE Security Desk·45w ago
Cve-2025-55317 · Cybersecurity

Microsoft AutoUpdate Vulnerability Lets Attackers Escalate to Root on macOS via Symlink Tricks

Microsoft has disclosed a fresh local elevation-of-privilege vulnerability in its Microsoft AutoUpdate (MAU) agent that allows an attacker with an existing foothold on a macOS machine to escalate to...

SE Security Desk·45w ago
Asr · Cve-2025-54903

Urgent Excel Security Fix: Use-After-Free Bug Opens Door to Code Execution — Mac LTSC Patches Delayed

Microsoft has issued a security advisory for CVE-2025-54903, a critical use-after-free vulnerability in Microsoft Excel that allows an attacker to execute code locally when a victim opens a...

SE Security Desk·45w ago
Applocker · Asr

CVE-2025-54902: Excel Out-of-Bounds Read Flaw Could Let Attackers Seize PCs—Mac Updates Still Missing

Microsoft has released a security update for a critical out-of-bounds read vulnerability in Excel that could allow remote code execution—but the patch is not yet available for Mac users. Tracked as...

SE Security Desk·45w ago
Asr · Cve-2025-54896

Microsoft Warns of Actively Targeted Excel Use-After-Free Flaw CVE-2025-54896

Microsoft has issued a critical security advisory for CVE-2025-54896, a use-after-free vulnerability in Microsoft Office Excel that could allow attackers to execute arbitrary code on Windows...

SE Security Desk·45w ago
Authentication · Cve-2025-54895

Windows NEGOEX Integer Overflow Lets Attackers Escalate to SYSTEM—Patch Now

Microsoft has released a security update to plug a critical elevation-of-privilege hole in the Windows NEGOEX authentication mechanism. Tracked as CVE-2025-54895, the flaw stems from an integer...

SE Security Desk·45w ago
Cdpsvc · Cve-2025-54102

Windows CDPSvc Elevation Flaw (CVE-2025-54102) Patched; Attackers Could Seize SYSTEM Control

A high-severity vulnerability in the Windows Connected Devices Platform Service (CDPSvc), cataloged as CVE-2025-54102, can be exploited by a low-privileged local attacker to gain NT AUTHORITY\SYSTEM...

SE Security Desk·45w ago
Attachment Preview · Availability

New Outlook for Windows Takes Major Step Toward Classic Parity with Offline Attachments, Ctrl+F, and More

Microsoft has finally patched one of the most glaring holes in its web-savvy "new Outlook" for Windows: you can now open classic email attachments without an internet connection. The update also...

SE Security Desk·45w ago