Security Best Practices
The latest Security Best Practices coverage — news, analysis, and updates from the WindowsNews.AI desk.
Safeguarding Service Principals: Lessons from the Commvault Azure Security Breach
Overview In early 2025, Commvault, a leading data protection and information management company, experienced a significant security incident within its Azure environment. This breach, attributed to a...
Active Directory dMSA Flaw Lets Attackers Escalate Privileges Domain-Wide
Overview A recently discovered vulnerability in Microsoft's Active Directory delegated Managed Service Accounts (dMSA) feature has raised significant security concerns. This flaw allows attackers to...
Cyberattacks on SaaS Providers: Safeguarding Data and Enhancing Cloud Security
Introduction In recent months, Commvault, a leading data management and security firm, has been targeted by sophisticated cyberattacks attributed to nation-state actors. These incidents have raised...
BadSuccessor Vulnerability in Windows Server 2025 dMSA: Protecting Your Active Directory from Critical Threats
Introduction The launch of Windows Server 2025 brought promising new capabilities for enterprise IT, notably the addition of delegated Managed Service Accounts (dMSA), designed to simplify service...
Windows Attachment Manager: Enhancing Email and Download Security
The Windows Attachment Manager is a security feature integrated into Microsoft Windows to safeguard users from potentially harmful files received via email or downloaded from the internet. By...
Commvault Azure Breach and CISA Advisory Highlight SaaS Cloud Security Risks
Overview Recent developments have cast a spotlight on the security vulnerabilities inherent in Software as a Service (SaaS) solutions, particularly within cloud environments. A notable incident...
Critical Security Flaw in Microsoft Edge CVE-2025-47181 and How to Mitigate It
Here are the key details about the Critical Security Flaw in Microsoft Edge (CVE-2025-47181): What is CVE-2025-47181? It is a critical security vulnerability found in Microsoft Edge, related to...
Lantronix XML attack, Rockwell bypass: CISA flags May 2025 ICS flaws
The Cybersecurity and Infrastructure Security Agency (CISA) issued two critical advisories on May 22, 2025, highlighting significant vulnerabilities in Industrial Control Systems (ICS) that...
Critical CVE-2025-4338 Vulnerability Discovered in Lantronix Device Installer Threatening Legacy Devices
Lantronix Device Installer, a utility long relied upon by IT administrators for device discovery, configuration, and upgrade management across Lantronix networking hardware, now finds itself at the...