Live
Microsoft Opens Windows Update to Third-Party Apps as Office Hours Tackles IT's Toughest 2025 Challenges·MSFT +2.1%Leading GenAI Browser Assistants Found Hoovering Up Social Security Numbers, Medical Data Without Consent·NVDA +0.2%Tenable AI Exposure Debuts at Black Hat to Tackle Generative AI’s Hidden Attack Surface·GOOGL +1.7%Microsoft’s August Patches Slam Shut 107+ Holes, Including Public Kerberos Flaw and Critical GDI+ RCE·AMZN +1.1%ChatGPT Gets Gmail and Calendar Access: OpenAI's Productivity Play Raises Security Flags·MSFT +2.1%Windows 10 August Update Opens ESU Enrollment, Hardens Secure Boot Against Rollback·NVDA +0.2%Critical Word Flaw CVE-2025-53784 Lets Attackers Hijack PCs via Malicious Docs — Patch Immediately·GOOGL +1.7%WSL 2.5.10 Fixes TOCTOU Bug: Microsoft Acts Fast on CVE-2025-53788 Privilege Escalation·AMZN +1.1%Microsoft Opens Windows Update to Third-Party Apps as Office Hours Tackles IT's Toughest 2025 Challenges·MSFT +2.1%Leading GenAI Browser Assistants Found Hoovering Up Social Security Numbers, Medical Data Without Consent·NVDA +0.2%Tenable AI Exposure Debuts at Black Hat to Tackle Generative AI’s Hidden Attack Surface·GOOGL +1.7%Microsoft’s August Patches Slam Shut 107+ Holes, Including Public Kerberos Flaw and Critical GDI+ RCE·AMZN +1.1%ChatGPT Gets Gmail and Calendar Access: OpenAI's Productivity Play Raises Security Flags·MSFT +2.1%Windows 10 August Update Opens ESU Enrollment, Hardens Secure Boot Against Rollback·NVDA +0.2%Critical Word Flaw CVE-2025-53784 Lets Attackers Hijack PCs via Malicious Docs — Patch Immediately·GOOGL +1.7%WSL 2.5.10 Fixes TOCTOU Bug: Microsoft Acts Fast on CVE-2025-53788 Privilege Escalation·AMZN +1.1%

Enterprise Security

The latest Enterprise Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 1:52 PM
Latest Most Read Breaking
Sort
Autopilot · Cloud Native

Microsoft Opens Windows Update to Third-Party Apps as Office Hours Tackles IT's Toughest 2025 Challenges

Microsoft is quietly testing a major expansion of Windows Update that will allow any third-party application or driver to be patched through the same built-in mechanism used for OS updates. The...

Advertisement
Calendar · Chatgpt

ChatGPT Gets Gmail and Calendar Access: OpenAI's Productivity Play Raises Security Flags

OpenAI has quietly breached the walls of Google Workspace. Starting this week, ChatGPT Pro users can grant the AI direct access to their Gmail inboxes, Google Calendars, and Google Contacts—turning...

AI AI & Copilot Desk·49w ago
21h2 · 22h2

Windows 10 August Update Opens ESU Enrollment, Hardens Secure Boot Against Rollback

Microsoft’s cumulative update KB5063709, released on August 12, 2025, arrives at a critical juncture for Windows 10 users. With the end-of-support deadline looming on October 14, 2025, the patch...

SE Security Desk·49w ago
Attack Surface Reduction · Cve-2025-53784

Critical Word Flaw CVE-2025-53784 Lets Attackers Hijack PCs via Malicious Docs — Patch Immediately

Microsoft’s latest security advisory warns of a memory-corruption flaw in Word—CVE-2025-53784—that hands attackers a local-code-execution foothold from nothing more than a booby-trapped...

SE Security Desk·49w ago
Cve-2025-53788 · Edr

WSL 2.5.10 Fixes TOCTOU Bug: Microsoft Acts Fast on CVE-2025-53788 Privilege Escalation

Microsoft released an out-of-band Windows Subsystem for Linux (WSL) update on August 6, 2025, patching a local elevation-of-privilege vulnerability that could let attackers break out of WSL2...

SE Security Desk·49w ago
Cve-2025-53766 · Defense In Depth

Unverified GDI+ RCE Vulnerability CVE-2025-53766 Prompts Urgent Patch Verification Call

Microsoft’s Security Update Guide has quietly listed a new vulnerability tracked as CVE-2025-53766, describing a heap-based buffer overflow in the GDI+ graphics library that could allow remote code...

SE Security Desk·49w ago
Afd.sys · Cve-2025-53147

New AFD.sys Use-After-Free (CVE-2025-53147) Demands Immediate Patching as Kernel Exploit Chains Resurface

A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys) tracked as CVE-2025-53147 allows a local attacker to escalate privileges to SYSTEM, Microsoft disclosed...

SE Security Desk·49w ago
Cve-2025-53140 · Edr Telemetry

Patch Now: CVE-2025-53140 Kernel Transaction Manager Use-After-Free Enables Local Privilege Escalation on Windows

Microsoft has released a security update for CVE-2025-53140, a use-after-free vulnerability in the Windows Kernel Transaction Manager (KTM) that allows an authorized local attacker to elevate...

SE Security Desk·49w ago
Cloud Providers · Cve-2025-50167

Urgent Fix: Hyper-V Race Condition CVE-2025-50167 Lets Attackers Seize Host Control

Microsoft has confirmed a dangerous race condition in Windows Hyper-V that gives an attacker with low-level access a path to full host compromise, escalating privileges to the kernel level. Tagged...

SE Security Desk·49w ago