Live

Security

Stay ahead with our essential Windows security news: Patch Tuesday updates, threat analyses, and expert guidance to safeguard your Microsoft environment.

13 stories in view AI assisted desk updated 5:52 PM
Latest Most Read Breaking
Sort
CISA · SBOM

CISA’s 2026 SBOM Refresh: The New Federal Baseline and What IT Teams Must Do Now

CISA, the NSA, the FBI, and international partners have released the 2026 Minimum Elements for a Software Bill of Materials, replacing the NTIA’s 2021 baseline. The update modernizes SBOM expectations to support real-time vulnerability management and expands transparency considerations for AI and SaaS. IT teams should audit current SBOM practices, integrate component data into security workflows, and prepare for upcoming federal acquisition requirements.

Security

Google Messages Kills QR Code Pairing for Web: Windows Users Must Now Sign In

Google has officially ended QR-code pairing for Google Messages on the web in the U.S., requiring a Google Account sign-in for new connections. The change, phased in over months, affects Windows users who relied on quick, anonymous browser access for texting. Users should prepare to sign in, enable security measures, and consider alternatives for shared devices.

Security Desk·2h ago ·5 min
Security

Microsoft Ships Urgent Fix for Defender on Linux Bug That Silently Disabled Endpoint Protection

Microsoft fixed a bug in Defender for Endpoint on Linux that could disable the security service after a reboot, affecting builds 101.26042.0000 through 101.26042.0009. The flaw, which Microsoft addressed in build 101.26042.0011 and the newer 101.26052.0011, is especially dangerous for cloud-managed servers that receive automatic updates. Administrators should immediately inventory their Linux devices, upgrade to a fixed release, and verify that real-time protection is active after any restart.

Security Desk·3h ago ·5 min
Security

Teams Vishing Campaign Drops GoGRPC Backdoor via Quick Assist—Here’s How to Block It

Since early 2026, attackers have been using Microsoft Teams calls to impersonate IT support and trick users into granting Quick Assist remote access, leading to deployment of the GoGRPC backdoor. The campaign, uncovered by Zscaler ThreatLabz, is growing more selective and now uses TLS-encrypted command-and-control. This article breaks down how the attack works, who is at risk, and provides concrete steps for Windows users and administrators to block or mitigate the threat.

Security Desk·4h ago ·5 min
Advertisement
Microsoft Teams · Meeting Security

Microsoft Teams Adds Numeric-Only Meeting Passcodes—But Only for Those Who Need Them

Microsoft Teams now allows admins to assign eight-digit numeric meeting passcodes to specific organizers instead of sticking with alphanumeric codes across the board. The feature, launched in April 2026, is intended for frontline, accessibility, and shared-device scenarios but comes with a firm security warning. A safe rollout means scoping the policy narrowly, hardening lobby and anonymous join controls, and never applying it to high-stakes meetings.

SE Security Desk·18h ago ·1 views
Microsoft Purview · Insider Risk Management

Microsoft Purview's New Panel Will Recommend Insider Risk Policies You're Missing

Microsoft is adding a Policy Recommendation Panel to Purview Insider Risk Management that will proactively identify missing protections and suggest high-value configurations. The feature, scheduled for preview in November 2026 and GA in December 2026, aims to move organizations from reactive policy checking to strategic coverage optimization. Admins should prepare by documenting existing policies, fixing health warnings, and establishing governance processes to evaluate future recommendations.

SE Security Desk·18h ago
Microsoft Purview · DLP

Microsoft Purview DLP SLA Dashboard Lands August 2026 Preview, Giving Orgs MTTA and MTTR Tracking

Microsoft is adding an SLA-based alert reporting dashboard to Purview DLP, with preview in August 2026 and GA in September 2026. The dashboard tracks MTTA, MTTR, and top sensitive info types, letting teams set custom severity-based targets. Organizations should prepare now by defining alert lifecycles and baselining performance to ensure the metrics drive real improvement.

SE Security Desk·18h ago ·1 views
Microsoft Purview · Data Loss Prevention

Microsoft Purview DLP Alerts Finally Explain the ‘Why’ Behind Exchange Policy Matches

Microsoft is rolling out enriched Exchange Online DLP alerts that now display every condition that triggered a policy match, not just the sensitive data type. Sender domains, recipients, subject keywords, attachment details, and message headers appear directly in alerts and Activity Explorer, speeding incident triage and making policy tuning more evidence-based.

SE Security Desk·18h ago
Microsoft Purview · Onedrive

Microsoft Purview Will Soon Let You Permanently Delete OneDrive and SharePoint Files—Here’s the Plan

Microsoft is adding a hard-delete option to Purview Priority cleanup for OneDrive and SharePoint, targeted for October 2026. The feature will let admins permanently remove files without sending them to the recycle bin, answering compliance and security needs but raising the stakes for governance. Administrators should begin planning formal approval workflows and audit processes now.

SE Security Desk·18h ago ·1 views
Data Loss Prevention · Microsoft Purview

Microsoft Purview DLP to Let Admins Auto-Close Low-Risk Alerts and Tag Workflows by September 2026

Microsoft will introduce rule-based auto-resolution and tagging for Purview DLP alerts in September 2026, allowing admins to automatically close low-risk, predictable alerts and label others for better routing. The feature aims to cut alert fatigue while maintaining audit trails and governance.

SE Security Desk·18h ago
Chrome 149 · CVE-2026-13030

Chrome 149 Patches Android GPU Flaw That Could Leak Browser Memory—Windows Update Included

Google’s Chrome 149 update fixes a high-severity GPU memory disclosure bug (CVE-2026-13030) that primarily threatens Android devices but also shipped as part of desktop security patches. Windows and Mac users aren’t explicitly identified as vulnerable, but the fix’s inclusion, combined with other bundled security updates, makes immediate patching essential for all platforms. We explain the real risks, the platform differences, and the simple steps users and admins must take.

SE Security Desk·19h ago
Android Security · Chrome Webview

Android Users Must Update Chrome Now: CVE-2026-13037 Exploits WebView for Sandboxed Code Execution

Google has patched a high-severity use-after-free bug in Android's WebView engine that could let attackers execute code within the browser sandbox via a crafted HTML page. The fix, version 149.0.7827.197, requires updates to both Chrome and Android System WebView, and it demands immediate attention from users, IT admins, and app developers because WebView is embedded in countless Android apps.

SE Security Desk·19h ago ·1 views
Chrome Security · Cve-2026-13028

Chrome 149 Patches Critical WebGL Sandbox Escape — Here’s What Windows Users Need to Do

Google’s June 2026 Chrome 149 update silently patches a critical WebGL use-after-free vulnerability tracked as CVE-2026-13028. Although the CVE entry only mentions Android, the fix applies to Windows, macOS, and Linux, closing a hole that could allow sandbox escape via a malicious webpage. Windows users should immediately update Chrome to the latest version and restart the browser to ensure protection.

SE Security Desk·19h ago