Live
Transform Your Windows 11 Workflow: ZDNET’s 45+ Shortcuts Guide Sparks Productivity Revolution·MSFT +2.1%Microsoft Overhauls Windows 11 Driver Stack: NuGet WDK, User-Mode Networking, and a Legacy Cleanup·NVDA +0.2%Microsoft Offers Free Copilot to Feds in $3B OneGov Deal—But Critics Cry Lock-In and Security Risks·GOOGL +1.7%Microsoft Inks $3 Billion AI Deal with U.S. Government: Free Copilot, Azure Discounts, and the Risks Agencies Can't Ignore·AMZN +1.1%Nadella's 5 GPT-5 Prompts Transform Copilot into an AI Chief-of-Staff for Executives·MSFT +2.1%How to Restore Classic Notepad in Windows 11 — and Run It Beside the AI-Enhanced Version·NVDA +0.2%Windows 11 Insider Preview Adds Native Clipboard Sync for Android Keyboards via Link to Windows·GOOGL +1.7%Windows 10’s October 2025 Deadline: Why Procrastinating on Windows 11 Migration Will Cost You·AMZN +1.1%Transform Your Windows 11 Workflow: ZDNET’s 45+ Shortcuts Guide Sparks Productivity Revolution·MSFT +2.1%Microsoft Overhauls Windows 11 Driver Stack: NuGet WDK, User-Mode Networking, and a Legacy Cleanup·NVDA +0.2%Microsoft Offers Free Copilot to Feds in $3B OneGov Deal—But Critics Cry Lock-In and Security Risks·GOOGL +1.7%Microsoft Inks $3 Billion AI Deal with U.S. Government: Free Copilot, Azure Discounts, and the Risks Agencies Can't Ignore·AMZN +1.1%Nadella's 5 GPT-5 Prompts Transform Copilot into an AI Chief-of-Staff for Executives·MSFT +2.1%How to Restore Classic Notepad in Windows 11 — and Run It Beside the AI-Enhanced Version·NVDA +0.2%Windows 11 Insider Preview Adds Native Clipboard Sync for Android Keyboards via Link to Windows·GOOGL +1.7%Windows 10’s October 2025 Deadline: Why Procrastinating on Windows 11 Migration Will Cost You·AMZN +1.1%

Security

Stay ahead with our essential Windows security news: Patch Tuesday updates, threat analyses, and expert guidance to safeguard your Microsoft environment.

13 stories in view AI assisted desk updated 9:34 AM
Latest Most Read Breaking
Sort
Software Supply Chain · Federal Cybersecurity

The White House just killed software attestation rules—here’s how to secure your development pipeline anyway

The Trump administration’s rollback of federal software attestation rules leaves agencies to secure their own development pipelines. This article explains how centrally managed Windows environments can close the gap and provides a step-by-step action plan for federal IT teams to achieve software sovereignty now.

Advertisement
Post-quantum Cryptography · Windows Security

Your 2030 Post-Quantum Deadline Has Arrived—and It Will Rewrite Windows Security

The White House's new quantum executive order sets a December 31, 2030 deadline for federal agencies to adopt post-quantum cryptography, with a knock-on effect for all vendors and enterprises. Windows admins must begin inventorying cryptographic assets, demanding PQC roadmaps from vendors, and planning for infrastructure-wide algorithm upgrades—years before the cutoff.

SE Security Desk·6h ago ·1 views
Windows Backup · Ransomware Protection

Beyond OneDrive: Why Every Windows User Needs a Layered Backup Strategy in 2026

Windows 11’s built‑in backup tools have improved, but they can’t recover from a dead drive, theft, or ransomware alone. We break down the 3‑2‑1‑1‑0 rule and show exactly how to combine OneDrive, File History, cloud services like Backblaze or Acronis, and offline drives into a layered defence that protects both everyday documents and entire system images. A practical checklist helps you lock down your data in an afternoon.

SE Security Desk·7h ago
CVE-2026-62835 · Microsoft Security

Microsoft’s CVE-2026-62835 Flags a Data Leak in an Online Service, but Won’t Say Which One

Microsoft published CVE-2026-62835, an information disclosure vulnerability in an unspecified online service, on July 23. The advisory lacks key details such as the affected service, severity, and remediation steps, leaving administrators to prepare their cloud environments for a potential data leak without knowing which service to focus on.

SE Security Desk·7h ago
Fleet Cybersecurity · Ransomware

Ransomware and Cargo Heists: The New Cyber Threats Paralyzing Fleet Operations

A July 2026 advisory from Upstream’s VP of Cyber Services warns that commercial fleets face escalating ransomware and cargo theft threats, fueled by connected vehicles, telematics, and cloud platforms. The report details how operational disruptions and digital heists are becoming routine, and it offers a practical defense checklist—from MFA and network segmentation to vendor scrutiny and incident playbooks—for fleet IT teams determined to keep their trucks rolling and freight secure.

SE Security Desk·8h ago ·1 views
Azure Dns · Azure Rbac

Azure DNS Vulnerability CVE-2026-58275: Steps to Secure Your Zones Immediately

Microsoft disclosed CVE-2026-58275, an elevation-of-privilege vulnerability in Azure DNS, on July 23, 2026. The flaw could allow unauthorized DNS modifications, threatening traffic routing and service integrity. This guide explains the practical impact and provides step-by-step actions to review RBAC, tighten identities, and monitor for changes.

SE Security Desk·9h ago
Azure Key Vault · Cve-2026-62825

New Azure Key Vault Flaw Puts Your Secrets at Risk—Here’s What to Do

Microsoft disclosed CVE-2026-62825, an elevation of privilege vulnerability in Azure Key Vault, on July 23, 2026. With limited technical details, organizations must proactively review their vault access, audit permissions, and prepare for targeted secret rotation. This article explains the immediate risks and provides a practical assessment and response plan for Windows and cloud administrators.

SE Security Desk·9h ago
CVE-2026-58630 · Azure Stack Hub

July 23 Advisory: CVE-2026-58630 Exposes Azure Stack Hub App Service to Elevation of Privilege Attacks

Microsoft's July 23, 2026 advisory for CVE-2026-58630 reveals a privilege escalation flaw in Azure App Service on Azure Stack Hub, posing a serious risk for hybrid cloud operators. This article breaks down what we know, who’s affected, and provides a step-by-step response plan to secure deployments. The key actions are to verify your inventory, apply official updates, and tighten access controls.

SE Security Desk·9h ago
Exchange Online · CVE-2026-56191

Microsoft Confirms Exchange Online Tampering Vulnerability CVE-2026-56191 — Here’s How to Respond

Microsoft disclosed CVE-2026-56191, a tampering vulnerability in Exchange Online, on July 23. With no patch or severity score yet, administrators must shift from patching to hardening tenant configurations, auditing privileged access, and monitoring for integrity anomalies. The advisory highlights the unique challenges of cloud-service vulnerabilities, where remediation is service-side and visibility is limited.

SE Security Desk·9h ago
Azure API Management · CVE-2026-35425

Microsoft Flags Remote Code Execution Bug in Azure API Management: Hands-On Steps for Early Defense

Microsoft published CVE-2026-35425, an RCE vulnerability in Azure API Management, with limited details. Here’s what cloud admins need to know and do to protect their API gateways before exploit specifics emerge.

SE Security Desk·9h ago ·1 views