Live
CVE-2025-9288: Critical sha.js Vulnerability Threatens Node.js Supply Chain·MSFT +0.1%CVE-2025-12816: Critical Node-Forge ASN.1 Flaw Threatens JavaScript Supply Chain·NVDA +3.0%FlyOOBE Impersonation Threat: How to Safely Verify Windows 11 Bypass Tools·GOOGL +1.2%CVE-2025-59288: Playwright Signature Verification Vulnerability Explained·AMZN +2.9%250 Malicious Documents Can Backdoor LLMs, Evading Standard AI Safety Checks·MSFT +0.1%Microsoft's Wisconsin AI Factory: How 72-GPU Racks and Liquid Cooling Could Supercharge the Cloud·NVDA +3.0%When PC Optimizers Turn Hostile: The Case Against CCleaner, Advanced SystemCare, and Clean Master·GOOGL +1.2%How ENGIE Impact Achieved 13x Better Risk Detection with Azure AI and Databricks—and the Governance Lessons Along the Way·AMZN +2.9%CVE-2025-9288: Critical sha.js Vulnerability Threatens Node.js Supply Chain·MSFT +0.1%CVE-2025-12816: Critical Node-Forge ASN.1 Flaw Threatens JavaScript Supply Chain·NVDA +3.0%FlyOOBE Impersonation Threat: How to Safely Verify Windows 11 Bypass Tools·GOOGL +1.2%CVE-2025-59288: Playwright Signature Verification Vulnerability Explained·AMZN +2.9%250 Malicious Documents Can Backdoor LLMs, Evading Standard AI Safety Checks·MSFT +0.1%Microsoft's Wisconsin AI Factory: How 72-GPU Racks and Liquid Cooling Could Supercharge the Cloud·NVDA +3.0%When PC Optimizers Turn Hostile: The Case Against CCleaner, Advanced SystemCare, and Clean Master·GOOGL +1.2%How ENGIE Impact Achieved 13x Better Risk Detection with Azure AI and Databricks—and the Governance Lessons Along the Way·AMZN +2.9%

Supply Chain Risks

The latest Supply Chain Risks coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 7:28 AM
Latest Most Read Breaking
Sort
Hash Vulnerability · Nodejs Security

CVE-2025-9288: Critical sha.js Vulnerability Threatens Node.js Supply Chain

A critical vulnerability in the widely used sha.js npm package has sent shockwaves through the Node.js and JavaScript ecosystem, exposing thousands of applications to potential hash corruption and...

Advertisement
Ai Security · Data Poisoning

250 Malicious Documents Can Backdoor LLMs, Evading Standard AI Safety Checks

A groundbreaking study from Anthropic reveals that as few as 250 malicious documents can implant reliable backdoor behaviors in large language models, challenging fundamental assumptions about AI...

AI AI & Copilot Desk·40w ago
Ai Training · Ai Wan

Microsoft's Wisconsin AI Factory: How 72-GPU Racks and Liquid Cooling Could Supercharge the Cloud

On September 18, 2025, Microsoft revealed Fairwater—a 315-acre AI datacenter campus in Wisconsin that is more silicon foundry than server farm. Each rack inside holds 72 NVIDIA Blackwell GPUs...

AI AI & Copilot Desk·43w ago
Advanced System Care · Built-in Tools

When PC Optimizers Turn Hostile: The Case Against CCleaner, Advanced SystemCare, and Clean Master

In 2017, a signed update for CCleaner—one of the world’s most popular PC cleaning tools—secretly installed a backdoor on over two million Windows machines. The incident exposed a chilling...

SE Security Desk·44w ago
Adoption · Automation

How ENGIE Impact Achieved 13x Better Risk Detection with Azure AI and Databricks—and the Governance Lessons Along the Way

ENGIE Impact now says it can identify account risk 13 times more accurately than before, a leap the sustainability consultancy credits to a tightly integrated stack of Microsoft Azure AI services....

AI AI & Copilot Desk·44w ago
Ai Governance · Ai Security

Only 17% of Organizations Have Technical Controls for AI Data, Survey Finds, as Third-Party Risks Spiral

A staggering 83% of organizations lack the technical controls needed to stop employees from feeding sensitive data into public AI tools, according to a new survey from Kiteworks. The 2025 report,...

AI AI & Copilot Desk·44w ago
25h2 · Copilot

Tiny11’s Latest Builder Can Purge Copilot, Outlook, and Teams from Windows 11 — But There Are Risks

Tiny11’s builder, a community-favorite script for slimming down Windows 11 installs, just got a major update: it can now surgically remove Copilot, the new Outlook for Windows, and Microsoft Teams...

AI AI & Copilot Desk·45w ago
Adversarial Testing · Ai Security

Microsoft Copilot’s EchoLeak Flaw Proves GenAI Must Embrace Zero Trust — Or Risk Catastrophic Data Leaks

A zero-click prompt injection flaw in Microsoft 365 Copilot, discovered in January by security researchers at Aim Labs, allowed attackers to trick the AI assistant into silently exfiltrating...

AI AI & Copilot Desk·45w ago
Arbitrary Code · Cisa

Fuji Electric FRENIC-Loader 4 Flaw Opens Engineering Workstations to File-Based Code Execution Attacks

A critical deserialization vulnerability in Fuji Electric’s FRENIC-Loader 4 utility can give attackers full arbitrary code execution on industrial engineering workstations when a user opens a...

SE Security Desk·45w ago