Incident Response
The latest Incident Response coverage — news, analysis, and updates from the WindowsNews.AI desk.
ReliaQuest Exposes OP-512: Chinese Hackers Use Modular IIS Web Shells to Steal Credentials
A sophisticated three-part web shell framework, linked to Chinese threat actors and tracked as OP-512, is actively compromising Internet Information Services (IIS) servers, according to research...
Cisco Warns of Critical SD-WAN Flaw CVE-2026-20182: Unauthenticated Admin Access Risk
Cisco dropped a security bombshell on May 14, 2026: a vulnerability tracked as CVE-2026-20182 lets unauthenticated attackers bypass authentication entirely and seize administrative control of...
Exchange Online EX1331830 Outage: Global Mail Flow Delays Enter Second Day, No ETA on Fix
Microsoft’s Exchange Online service is in the grip of a major incident, EX1331830, that is delaying email delivery for enterprise customers across three continents. The outage began on June 2,...
Teams File Access Restored After 6-Hour Microsoft 365 Outage—Admins Urged to Audit Auth Settings
Microsoft confirmed that it restored file access for Microsoft Teams and Office for the web on June 1, 2026, after a service incident (tracked as MO1329446) left users unable to open documents. The...
HPE Ops Tools Weaponized in Third-Party Breach to Steal Credentials
Microsoft Incident Response revealed on May 12, 2026, that attackers compromised a third-party IT services provider and used the provider's legitimate HPE Operations Manager and HPE Operations Agent...
Sohaib Akhter Convicted: Offboarding Gaps, Plaintext Passwords, and AI Prompt Risks Exposed
A federal jury in Alexandria, Virginia convicted former federal contractor Sohaib Akhter on May 7, 2026 for his role in deleting roughly 96 U.S. government records. Prosecutors said Sohaib and his...
Dirty Frag Linux Flaw Grants Root: Microsoft Patches WSL Kernel
Microsoft issued an urgent security advisory on May 8, 2026, confirming limited active exploitation of a Linux local privilege escalation vulnerability tracked as Dirty Frag. The attack chain...
FIRESTARTER Malware on Cisco ASA/FTD Survives Patching, Forces Hardware Replacement
FIRESTARTER: A Persistent Threat to Cisco ASA/FTD Firepower Appliances CISA and the U.K.’s National Cyber Security Centre (NCSC) have jointly issued an urgent advisory detailing a sophisticated...
CISA Adds Critical Citrix NetScaler Vulnerability to KEV Catalog—Patch Immediately
The Cybersecurity and Infrastructure Security Agency has added a critical Citrix NetScaler vulnerability to its Known Exploited Vulnerabilities Catalog, signaling active exploitation in the wild....
Outlook Outage 2025: Authentication Failures Lock Users Out, Microsoft's Rapid Response Analyzed
Several thousand Microsoft Outlook users were locked out of their mailboxes on July 10, 2025, when authentication failures surged across Outlook's web, desktop, and mobile platforms. The service...
Microsoft Exchange Outage Disrupts Enterprise Email Access, Highlights Cloud Reliability Challenges
Microsoft Exchange experienced another widespread service disruption this week, leaving enterprise mailboxes intermittently inaccessible across multiple regions. The outage affected both Exchange...
Azure Front Door Outage 2025: Configuration Error Exposes Control Plane Fragility
Microsoft's Azure Front Door service experienced a significant outage in late 2024 that exposed critical vulnerabilities in cloud infrastructure design. The incident, triggered by a configuration...