Risk Management
The latest Risk Management coverage — news, analysis, and updates from the WindowsNews.AI desk.
Chrome 139 Seals High-Severity V8 Out-of-Bounds Write CVE-2025-9132, Enterprises Scramble to Patch Edge
Google on August 19 shipped Chrome 139.0.7258.138 to patch a high-severity out-of-bounds write in its V8 JavaScript engine, tracked as CVE-2025-9132, that could let attackers execute arbitrary code...
Another Microsoft 365 Crash: How a Single Config Change Broke Office.com and Copilot
Microsoft's Office.com and Copilot services crashed for North American users on August 20, 2025, after a configuration change went sideways — a rollback reversed the damage after more than four...
Windows 10 Share Rebounds to 47% as Microsoft's ESU Offer Stalls Windows 11 Migration
Windows 11’s hard-won market share milestone has evaporated in just weeks, and the culprit is an olive branch Microsoft extended in the opposite direction. In July, Statcounter data showed Windows...
UK Government Bets on Agentic AI to Transform Public Services by 2027
The UK government has drawn up plans to trial agentic AI across public services, with a potential nationwide rollout by late 2027 if pilot programs prove safe and effective. The initiative, outlined...
Microsoft Activates 60-Day Countdown Warnings in Windows 10 Ahead of Support End
Microsoft has begun displaying a 60-day countdown inside Windows 10, triggered by a previously installed update, as the operating system’s free support clock ticks toward October 14, 2025. The...
Half an Hour Less Email, 12% Faster Docs: First Major M365 Copilot RCT Reveals Real Gains
A massive randomized controlled trial involving more than 6,000 workers at 56 companies has delivered the first rigorous, independent evidence on the productivity impact of Microsoft 365 Copilot. The...
45% of Employees Use Banned AI Tools: A Coordinated HR-IT Playbook to Reclaim Control
Forty-five percent. That’s the share of workers who, by their own admission, have used unapproved artificial intelligence tools on the job, according to multiple industry surveys. It’s a...
CVE-2025-40584: Siemens SIMOTION and SINAMICS Tools Vulnerable to XXE File Disclosure, Some Left Unpatched
Siemens has acknowledged a critical XML External Entity (XXE) vulnerability—tracked as CVE-2025-40584—affecting multiple versions of its SIMOTION SCOUT, SIMOTION SCOUT TIA, and SINAMICS STARTER...
CISA, NSA, FBI Release Guidance for OT Asset Inventories to Fortify Critical Infrastructure
On August 13, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) joined forces with the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), the Environmental...
Anthropic Class Action Certified: Billion-Dollar AI Copyright Threat Looms for Businesses
A federal judge in California has certified a class of authors accusing AI company Anthropic of downloading millions of pirated books to train its large language models, exposing the firm to...
Uninitialized Resource Bug in Windows RRAS Could Expose Corporate VPN Secrets, Microsoft Urges Patch
Microsoft has disclosed a new information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS), tracked as CVE-2025-53719, that could allow an authenticated attacker to...
Microsoft Patches Critical RRAS Heap Overflow CVE-2025-50160 That Exposes VPN Servers to Remote Takeover
Microsoft has released a patch for a critical heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) tracked as CVE-2025-50160, which allows attackers to remotely execute code...