Supply Chain Risks
The latest Supply Chain Risks coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2025-9288: Critical sha.js Vulnerability Threatens Node.js Supply Chain
A critical vulnerability in the widely used sha.js npm package has sent shockwaves through the Node.js and JavaScript ecosystem, exposing thousands of applications to potential hash corruption and...
CVE-2025-12816: Critical Node-Forge ASN.1 Flaw Threatens JavaScript Supply Chain
A critical vulnerability in the widely-used JavaScript cryptography library node-forge has been disclosed, posing significant risks to thousands of applications and websites that depend on...
FlyOOBE Impersonation Threat: How to Safely Verify Windows 11 Bypass Tools
A dangerous impersonation campaign targeting the popular FlyOOBE Windows 11 upgrade and debloat tool has emerged, creating significant security risks for users seeking to bypass Windows 11...
CVE-2025-59288: Playwright Signature Verification Vulnerability Explained
Microsoft has officially acknowledged CVE-2025-59288, a critical security vulnerability in the Playwright testing framework that exposes developers to supply chain attacks through improper...
250 Malicious Documents Can Backdoor LLMs, Evading Standard AI Safety Checks
A groundbreaking study from Anthropic reveals that as few as 250 malicious documents can implant reliable backdoor behaviors in large language models, challenging fundamental assumptions about AI...
Microsoft's Wisconsin AI Factory: How 72-GPU Racks and Liquid Cooling Could Supercharge the Cloud
On September 18, 2025, Microsoft revealed Fairwater—a 315-acre AI datacenter campus in Wisconsin that is more silicon foundry than server farm. Each rack inside holds 72 NVIDIA Blackwell GPUs...
When PC Optimizers Turn Hostile: The Case Against CCleaner, Advanced SystemCare, and Clean Master
In 2017, a signed update for CCleaner—one of the world’s most popular PC cleaning tools—secretly installed a backdoor on over two million Windows machines. The incident exposed a chilling...
How ENGIE Impact Achieved 13x Better Risk Detection with Azure AI and Databricks—and the Governance Lessons Along the Way
ENGIE Impact now says it can identify account risk 13 times more accurately than before, a leap the sustainability consultancy credits to a tightly integrated stack of Microsoft Azure AI services....
Only 17% of Organizations Have Technical Controls for AI Data, Survey Finds, as Third-Party Risks Spiral
A staggering 83% of organizations lack the technical controls needed to stop employees from feeding sensitive data into public AI tools, according to a new survey from Kiteworks. The 2025 report,...
Tiny11’s Latest Builder Can Purge Copilot, Outlook, and Teams from Windows 11 — But There Are Risks
Tiny11’s builder, a community-favorite script for slimming down Windows 11 installs, just got a major update: it can now surgically remove Copilot, the new Outlook for Windows, and Microsoft Teams...
Microsoft Copilot’s EchoLeak Flaw Proves GenAI Must Embrace Zero Trust — Or Risk Catastrophic Data Leaks
A zero-click prompt injection flaw in Microsoft 365 Copilot, discovered in January by security researchers at Aim Labs, allowed attackers to trick the AI assistant into silently exfiltrating...
Fuji Electric FRENIC-Loader 4 Flaw Opens Engineering Workstations to File-Based Code Execution Attacks
A critical deserialization vulnerability in Fuji Electric’s FRENIC-Loader 4 utility can give attackers full arbitrary code execution on industrial engineering workstations when a user opens a...