Information Security
The latest Information Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Critical Microsoft SharePoint Vulnerability CVE-2025-30384 Exposes Enterprises to Remote Takeover
A newly disclosed critical vulnerability in Microsoft SharePoint, tracked as CVE-2025-30384, has sent shockwaves through enterprise security teams globally, exposing millions of business...
Critical Microsoft Excel Vulnerability CVE-2025-30375 Exposes Users to Remote Code Execution
A newly discovered critical vulnerability in Microsoft Excel, designated as CVE-2025-30375, has thrust enterprise security teams into high alert, exposing millions of users to potential remote code...
Microsoft Teams Enhances Security with Native Screen Capture Blocking for Virtual Meetings
In an era where virtual meetings have become the lifeblood of global business operations, Microsoft has escalated its security game with a groundbreaking addition to Teams. The collaboration platform...
Microsoft Teams Introduces Automatic Screen Capture Blocking to Enhance Meeting Security
Microsoft Teams Introduces Automatic Screen Capture Blocking to Enhance Meeting Security Introduction In a significant move to bolster data security, Microsoft Teams is set to roll out a new feature...
New Cloud Attack Steals Microsoft Entra Refresh Tokens to Bypass MFA
New Cloud Attack Technique Bypasses MFA by Stealing Microsoft Entra Refresh Tokens A sophisticated new cloud attack technique has emerged, leveraging a manipulation of Microsoft Entra (formerly Azure...
Microsoft Teams Blocks Screen Captures Starting July 2025
Introduction In an era where digital collaboration is paramount, safeguarding sensitive information during virtual meetings has become a critical concern for organizations worldwide. Recognizing this...
Microsoft Dataverse CVE-2025-47732 RCE flaw rated 8.7, requires immediate patch.
Overview On May 8, 2025, Microsoft disclosed a critical remote code execution (RCE) vulnerability identified as CVE-2025-47732, affecting Microsoft Dataverse. This vulnerability arises from the...
Microsoft 365 Security Challenges in Universities: Risks & Solutions
As universities increasingly embrace Microsoft 365 as their digital backbone, the explosive growth of third-party integrations within its ecosystem presents both unprecedented opportunities and...
Legacy Windows Telnet Zero-Click Flaw Grants Remote Admin Access via NTLM Bypass
Overview Microsoft’s Telnet Server, a legacy component rooted in the early days of Windows networking, is now the focus of serious cybersecurity concerns due to the discovery of a critical...
NLRB Cybersecurity Breach Exposes Systemic Federal Cloud Vulnerabilities
The National Labor Relations Board, the independent federal agency charged with safeguarding American workers' right to organize, became the epicenter of one of the most significant government...
Commvault Ensures Data Security Amid Azure Cyberattack Exploiting CVE-2025-3928
In early 2025, Commvault, a leading provider of data protection solutions, faced a significant cybersecurity incident when a nation-state actor exploited a zero-day vulnerability, CVE-2025-3928,...