Security Advisory
The latest Security Advisory coverage — news, analysis, and updates from the WindowsNews.AI desk.
Microsoft Patches Critical RCE Flaw in IIS Web Deploy – CVE-2025-53772 Threatens Exposed Servers
Microsoft has issued a high-priority security advisory for a deserialization vulnerability in its Web Deploy tool that could give authenticated attackers the ability to execute arbitrary code on...
Visio Under Fire: Microsoft Releases Patch for Use-After-Free Vulnerability CVE-2025-53730
Microsoft has disclosed a new use-after-free vulnerability in Visio, tracked as CVE-2025-53730, that allows an attacker to execute arbitrary code locally when a user opens a maliciously crafted...
Microsoft Patches Azure File Sync EoP Vulnerability CVE-2025-29973—What IT Admins Must Do Now
Microsoft has confirmed an elevation-of-privilege vulnerability in its Azure File Sync service that could allow an authenticated local attacker to gain full control of affected Windows servers....
Microsoft Patches Zero-Click LDAPNightmare Exploits That Crash Domain Controllers (CVE-2024-49112/49113)
SafeBreach Labs researchers dropped a bombshell at DEF CON with a zero-click exploit chain that weaponizes Windows LDAP protocol handling to crash Domain Controllers or, in the worst case, execute...
CISA Mandates Immediate Disconnect of EOL Exchange Servers After Black Hat Exploit Demo for CVE-2025-53786
A critical Microsoft Exchange Server vulnerability now carries a binding directive from the U.S. Cybersecurity and Infrastructure Security Agency, following a live demonstration of the exploit at the...
Zero-Click Data Leak in Microsoft 365 Copilot BizChat Exposes Enterprise Secrets
A newly disclosed vulnerability in Microsoft 365 Copilot BizChat can expose sensitive business information without any user interaction, Microsoft warned in a security advisory published this week....
CVE-2025-8579: Google Patches Critical Gemini Live Flaw—Edge Users Must Update Too
CVE-2025-8579, a critical security flaw in Google Chrome's Gemini Live feature, has been patched after four months of quiet danger. The vulnerability, reported by researcher Alesandro Ortiz on April...
Chrome 139 Patches UI Spoofing Flaw That Tricks Users Into Giving Away Permissions—Edge Users Are Protected Too
Google has shipped a critical security fix for Chrome that plugs a user interface spoofing hole attackers could use to trick people into giving websites access to their camera, microphone, or...
Critical CVE-2025-8582 DOM Vulnerability Patched in Chrome and Edge – Users Urged to Update
On August 5, 2025, Google shipped an urgent security update for Chrome that plugs a dangerous hole in the browser's Document Object Model (DOM) handling. Tracked as CVE-2025-8582, the vulnerability...
Rockwell Automation Patches Three High-Severity Arena Simulation Bugs Poised to Cripple Critical Manufacturing
Three newly disclosed vulnerabilities in Rockwell Automation’s Arena simulation software have shaken the industrial security landscape, exposing global manufacturers to file-based attacks that can...
CISA Orders Federal Agencies to Patch Critical Exchange Hybrid Flaw by August 11
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive on Friday mandating all federal agencies with Microsoft Exchange hybrid environments to patch a critical...
Critical Exchange Hybrid Flaw CVE-2025-53786 Allows Undetectable Privilege Escalation—Patch Now
A dangerous authentication bypass has surfaced in Microsoft Exchange hybrid deployments, prompting coordinated alerts from both Microsoft and the U.S. Cybersecurity and Infrastructure Security Agency...