Live
Windows Defender Exploit: RedSun 0day Uses Race Condition for System32 Privilege Escalation·MSFT +2.1%Chrome 145 Emergency Update Fixes 10 Critical CVEs: What Windows Users Need to Know·NVDA +0.2%Password Manager Zero-Knowledge Promise Broken: ETH Zurich Research Exposes Critical Flaws·GOOGL +1.7%Windows 11 Default Browser: How EU DMA Forced Microsoft's One-Click Switch·AMZN +1.1%8 Chrome, Edge extensions with 2M+ installs stole ChatGPT, Gemini chats·MSFT +2.1%XChat’s Encryption Promise Crumbles: GPS-Tagged Photos and Server Keys Put Users at Risk·NVDA +0.2%Critical Chromium Use-After-Free Flaw CVE-2025-8576 Triggers Urgent Edge, Chrome Updates·GOOGL +1.7%Black Hat Demo Exposes Windows Hello Biometric Flaw: Admin Rights Enable Face Injection Attack·AMZN +1.1%Windows Defender Exploit: RedSun 0day Uses Race Condition for System32 Privilege Escalation·MSFT +2.1%Chrome 145 Emergency Update Fixes 10 Critical CVEs: What Windows Users Need to Know·NVDA +0.2%Password Manager Zero-Knowledge Promise Broken: ETH Zurich Research Exposes Critical Flaws·GOOGL +1.7%Windows 11 Default Browser: How EU DMA Forced Microsoft's One-Click Switch·AMZN +1.1%8 Chrome, Edge extensions with 2M+ installs stole ChatGPT, Gemini chats·MSFT +2.1%XChat’s Encryption Promise Crumbles: GPS-Tagged Photos and Server Keys Put Users at Risk·NVDA +0.2%Critical Chromium Use-After-Free Flaw CVE-2025-8576 Triggers Urgent Edge, Chrome Updates·GOOGL +1.7%Black Hat Demo Exposes Windows Hello Biometric Flaw: Admin Rights Enable Face Injection Attack·AMZN +1.1%

Security Research

The latest Security Research coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 3:22 AM
Latest Most Read Breaking
Sort
Local Privilege Escalation · Security Research

Windows Defender Exploit: RedSun 0day Uses Race Condition for System32 Privilege Escalation

A newly disclosed Windows Defender vulnerability allows attackers to achieve local privilege escalation by exploiting a race condition in the antivirus engine's file handling. Dubbed "RedSun" by...

Advertisement
Browser Extensions · Data Exfiltration

8 Chrome, Edge extensions with 2M+ installs stole ChatGPT, Gemini chats

Security researchers have uncovered a startling privacy breach in plain sight: several widely used Google Chrome and Microsoft Edge extensions — marketed as privacy and security tools — were...

SE Security Desk·30w ago
Auditing · Data Retention

XChat’s Encryption Promise Crumbles: GPS-Tagged Photos and Server Keys Put Users at Risk

Images sent over X’s new encrypted chat service retain full EXIF metadata, including GPS coordinates, device information, and timestamps, Straight Arrow News (SAN) revealed this week. The finding,...

SE Security Desk·45w ago
Browser Ecosystem · Browser Extensions

Critical Chromium Use-After-Free Flaw CVE-2025-8576 Triggers Urgent Edge, Chrome Updates

A severe use-after-free vulnerability in the Chromium extensions engine, tracked as CVE-2025-8576, is driving urgent updates across the browser ecosystem. The flaw, which carries high severity,...

SE Security Desk·49w ago
Biometric Injection · Biometrics

Black Hat Demo Exposes Windows Hello Biometric Flaw: Admin Rights Enable Face Injection Attack

German security researchers at the Black Hat USA 2025 conference in Las Vegas have demonstrated a stark vulnerability in Microsoft’s Windows Hello biometric authentication system. The live demo...

SE Security Desk·49w ago
Agentflayer · Ai Autonomous Threats

Zenity Labs’ AgentFlayer Exposes Zero-Click Exploits: Microsoft Copilot, ChatGPT AI Agents Hijacked Without User Action

At Black Hat USA 2025, security researchers from Zenity Labs pulled back the curtain on a dangerously overlooked attack surface: enterprise AI agents that can be silently hijacked with zero user...

AI AI & Copilot Desk·49w ago
Ai Security · Aitm Attacks

Sophisticated Microsoft 365 Phishing Attacks: Exploiting Security Features from Within

The digital arms race between cyber defenders and adversaries has reached a new inflection point, one that rattles the very foundations of trust in modern email and identity security. For Microsoft...

AI AI & Copilot Desk·50w ago
Ai Sandbox Risks · Ai Security

EchoLeak: The Critical Microsoft Copilot Vulnerability Reshaping Enterprise AI Security

A storm has swept through the cybersecurity and Windows enterprise communities following the exposure of a critical vulnerability in Microsoft Copilot Enterprise, code-named “EchoLeak.” This...

AI AI & Copilot Desk·51w ago
Azure Active Directory · Cloud Security

Critical Microsoft Entra ID SAML Exploit Enables Global Administrator Privilege Escalation

Security researchers have sounded the alarm over a newly discovered exploit chain in Microsoft Entra ID, a service formerly known as Azure Active Directory, that enables attackers to seize Global...

SE Security Desk·52w ago