Security
Stay ahead with our essential Windows security news: Patch Tuesday updates, threat analyses, and expert guidance to safeguard your Microsoft environment.
Stop Chasing CVEs: Microsoft Defender's New Dashboard Tells You What to Fix First
Microsoft has released a public preview of a new Exposure Resolution dashboard in the Defender portal that prioritizes security fixes based on internet exposure and business criticality. The dashboard organizes remediation into 'Resolve Now' and 'Monitor Exposure' workflows, helping Windows and cloud admins focus on the most dangerous vulnerabilities first.
Veeam v13.1 Hands Windows Admins an Automated Lifeline for Active Directory Disasters
Veeam Data Platform v13.1, released July 29, automates Active Directory forest recovery by capturing metadata during backups, expands threat detection to Azure, and adds a new cloud archive tier. The update simplifies identity disaster recovery for Windows admins and extends support to 14 hypervisors, with practical implications for security, compliance, and storage strategy.
Your Alternate DNS Isn't a Backup: Why Windows 11 Ignores It When Your Primary Blocks a Site
Windows 11's DNS client treats a block response (NXDOMAIN) as a complete answer, so it never queries the alternate server if the primary blocks a site. That means mixing a security-focused resolver like Quad9 with an unfiltered backup can silently break your protections. Combined with many routers that ignore the primary/alternate order, this misconfiguration leads to inconsistent filtering and troubleshooting headaches. The fix is simple: always use the primary and secondary IPs from a single DNS provider.
Apple Closes 220+ Security Flaws: A Wake-Up Call for Mixed-Device Windows Shops
Apple’s July 27 updates patch over 220 vulnerabilities across macOS, iOS, and other platforms, including a critical Gatekeeper bypass. Windows IT teams managing mixed-device fleets must treat this with the same urgency as Patch Tuesday, ensuring all Apple endpoints are updated promptly to prevent local compromises and data exposure.
The YellowKey BitLocker Bypass Is Fixed—Here’s How to Make Sure Your PC Is Secure
Microsoft's June 2026 Patch Tuesday update finally closed the YellowKey BitLocker bypass (CVE-2026-45585), a physical-access attack that could expose encrypted files on Windows PCs with TPM-only protection. While the patch is essential, users must also update the Windows Recovery Environment and consider switching to TPM+PIN for stronger pre-boot security.
Microsoft’s AD FS DKM ACL Hardening: What You Need to Do Before October 13
Microsoft has begun auditing permissions on the AD FS Distributed Key Manager (DKM) container with its July 14, 2026 security update. Administrators have until October 13, 2026, when automatic enforcement begins, to review and remediate overly permissive access controls that could allow key theft. The article explains the event log warnings, opt-in remediation steps, and how to prepare for the coming change.
CISA Flags Actively Exploited Cisco Firewall Manager Flaw—Patch Immediately
CISA added a hardcoded password vulnerability in Cisco Secure Firewall Management Center (CVE-2026-20316) to its Known Exploited Vulnerabilities catalog, confirming active exploitation. This article explains the immediate risks to Windows-centric enterprises, outlines the containment and remediation steps, and details the regulatory obligations for federal agencies under BOD 26-04.
Kratos Phishing Kit: How Two Image Files Betray Microsoft 365 Attacks
Security researchers at ANY.RUN have discovered that the Kratos phishing kit targeting Microsoft 365 can be reliably detected by looking for two specific image files, barr.svg and lg.svg. This fingerprint enabled the identification of over 1,400 previously hidden attacks and gives defenders a practical way to spot the campaign regardless of domain changes. The article outlines detection methods, response steps, and guidance for both users and IT teams to protect against credential theft and session hijacking.
HP Reveals 30 Percent of Its PCs Remain on Windows 10: Your Upgrade and Security Action Plan
HP CFO Karen Parkhill revealed during the May 2026 earnings call that 30% of HP's PC installed base still runs Windows 10, months after official support ended. The slow migration is largely driven by Windows 11's strict hardware requirements, creating a long-tail security challenge for consumers and IT administrators.
CISA’s 2026 SBOM Refresh: The New Federal Baseline and What IT Teams Must Do Now
CISA, the NSA, the FBI, and international partners have released the 2026 Minimum Elements for a Software Bill of Materials, replacing the NTIA’s 2021 baseline. The update modernizes SBOM expectations to support real-time vulnerability management and expands transparency considerations for AI and SaaS. IT teams should audit current SBOM practices, integrate component data into security workflows, and prepare for upcoming federal acquisition requirements.
Google Messages Kills QR Code Pairing for Web: Windows Users Must Now Sign In
Google has officially ended QR-code pairing for Google Messages on the web in the U.S., requiring a Google Account sign-in for new connections. The change, phased in over months, affects Windows users who relied on quick, anonymous browser access for texting. Users should prepare to sign in, enable security measures, and consider alternatives for shared devices.
Microsoft Ships Urgent Fix for Defender on Linux Bug That Silently Disabled Endpoint Protection
Microsoft fixed a bug in Defender for Endpoint on Linux that could disable the security service after a reboot, affecting builds 101.26042.0000 through 101.26042.0009. The flaw, which Microsoft addressed in build 101.26042.0011 and the newer 101.26052.0011, is especially dangerous for cloud-managed servers that receive automatic updates. Administrators should immediately inventory their Linux devices, upgrade to a fixed release, and verify that real-time protection is active after any restart.
Teams Vishing Campaign Drops GoGRPC Backdoor via Quick Assist—Here’s How to Block It
Since early 2026, attackers have been using Microsoft Teams calls to impersonate IT support and trick users into granting Quick Assist remote access, leading to deployment of the GoGRPC backdoor. The campaign, uncovered by Zscaler ThreatLabz, is growing more selective and now uses TLS-encrypted command-and-control. This article breaks down how the attack works, who is at risk, and provides concrete steps for Windows users and administrators to block or mitigate the threat.