Enterprise Security
The latest Enterprise Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch Now: CVE-2025-49761 Windows Kernel UAF Flaw Enables SYSTEM Takeover
A newly disclosed use-after-free vulnerability in the Windows kernel, tracked as CVE-2025-49761, hands a reliable privilege escalation path to any attacker who already has a toehold on a target...
GB WhatsApp’s New Look Conceals the Same Old Security Nightmares
A freshly minted APK for GB WhatsApp is making the rounds, promising a revamped interface and a beefed-up feature set that official WhatsApp refuses to deliver. The update, circulated through...
AgentFlayer Unleashed: Zero-Click Chains Turn Enterprise AI Agents into Stealth Insider Threats
At Black Hat USA 2025, Zenity Labs peeled back the curtain on a threat that security teams have long feared but rarely seen weaponized at scale: zero-click prompt injection attacks that silently...
Microsoft Copilot 3D Turns Photos into 3D Models in Seconds—But Not Without Risks
{ "title": "Microsoft Copilot 3D Turns Photos into 3D Models in Seconds—But Not Without Risks", "content": "Microsoft’s Copilot 3D can turn a single photograph into a downloadable 3D model in...
Windows Security Future Tied to Hardware: NPUs, Rust, and Post-Quantum Crypto Require New Devices
Microsoft is drawing a hard line between next-generation Windows security and the silicon that runs it. A sweeping vision penned by David Weston, the company’s Vice President of Enterprise and OS...
Live Hack Exposes Windows Hello Biometric Loophole—Researchers Say Disable It Now
A packed auditorium at Black Hat 2025 in Las Vegas watched in silence as security researcher Tillmann Osswald remotely enrolled his own face onto his colleague’s Windows Hello-protected...
Ghost Calls: Stealthy C2 Tunnels Exploit Microsoft Teams and Zoom Relays
Attackers can now turn Microsoft Teams and Zoom into invisible command-and-control backchannels without exploiting a single software flaw. Researchers from Praetorian have detailed a...
SendQuick Conexa Claims FIDO2 Server Certification, Paving the Way for Phishing-Resistant Windows Sign-Ins
SendQuick's Conexa authentication platform has achieved FIDO2 server certification from the FIDO Alliance, the company announced, positioning the multi-factor authentication platform as a...
Zero-Click Data Leak in Microsoft 365 Copilot BizChat Exposes Enterprise Secrets
A newly disclosed vulnerability in Microsoft 365 Copilot BizChat can expose sensitive business information without any user interaction, Microsoft warned in a security advisory published this week....
Akira Ransomware Exploits Intel ThrottleStop Driver to Disable Windows Defender in Stealthy BYOVD Campaign
A potent ransomware campaign has turned a trusted Intel CPU tuning driver into a weapon, allowing attackers to evade Windows 11's built-in defenses by disabling Microsoft Defender with surgical...
Black Hat Demo Exposes Windows Hello Biometric Flaw: Admin Rights Enable Face Injection Attack
German security researchers at the Black Hat USA 2025 conference in Las Vegas have demonstrated a stark vulnerability in Microsoft’s Windows Hello biometric authentication system. The live demo...
Check Point, Menlo, SentinelOne Redefine BYOD and AI Security at Black Hat 2025
At this week’s Black Hat 2025 conference in Las Vegas, three security vendors made announcements that could reshape how enterprises secure unmanaged devices, enable zero-trust collaboration, and...