Live
FileCoAuth.exe Errors Could Be Malware in Disguise—Here’s How to Check·MSFT +2.1%FreePBX Zero-Day Exploited in Wild: CISA Orders Emergency Patching for CVSS 10 RCE·NVDA +0.2%Unpatchable ICS Vulnerabilities: Mitsubishi, Schneider, Delta Among Vendors in CISA's Nine-Alert Batch·GOOGL +1.7%CERT-In Urges Immediate Patching of Critical Microsoft Edge, Windows Server, and Azure Databricks Flaws to Avert Ransomware·AMZN +1.1%CISA Flags Zero-Day in INVT VT-Designer and HMITool: Remote Code Execution via Malicious Files·MSFT +2.1%CISA Flags Urgent Patches for Exploited Citrix Session Recording and Git Flaws·NVDA +0.2%Microsoft Fixes CVE-2025-55229 Certificate Spoofing Bug Threatening TLS, VPNs, and Code Signing·GOOGL +1.7%CISA Alerts Federal Agencies and Enterprises to Apple Image I/O Zero-Day Under Active Exploit·AMZN +1.1%FileCoAuth.exe Errors Could Be Malware in Disguise—Here’s How to Check·MSFT +2.1%FreePBX Zero-Day Exploited in Wild: CISA Orders Emergency Patching for CVSS 10 RCE·NVDA +0.2%Unpatchable ICS Vulnerabilities: Mitsubishi, Schneider, Delta Among Vendors in CISA's Nine-Alert Batch·GOOGL +1.7%CERT-In Urges Immediate Patching of Critical Microsoft Edge, Windows Server, and Azure Databricks Flaws to Avert Ransomware·AMZN +1.1%CISA Flags Zero-Day in INVT VT-Designer and HMITool: Remote Code Execution via Malicious Files·MSFT +2.1%CISA Flags Urgent Patches for Exploited Citrix Session Recording and Git Flaws·NVDA +0.2%Microsoft Fixes CVE-2025-55229 Certificate Spoofing Bug Threatening TLS, VPNs, and Code Signing·GOOGL +1.7%CISA Alerts Federal Agencies and Enterprises to Apple Image I/O Zero-Day Under Active Exploit·AMZN +1.1%

Vulnerability

The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 7:33 AM
Latest Most Read Breaking
Sort
Antivirus · Application Error

FileCoAuth.exe Errors Could Be Malware in Disguise—Here’s How to Check

A pop-up error from FileCoAuth.exe can abruptly halt collaborative editing in Microsoft Office, leaving users staring at a cryptic crash message. But before you rush to reinstall OneDrive or Office,...

Advertisement
Authentication · Cisa

CISA Flags Zero-Day in INVT VT-Designer and HMITool: Remote Code Execution via Malicious Files

A zero-day vulnerability in INVT's VT-Designer and HMITool engineering software lets attackers run arbitrary code on industrial control system (ICS) workstations simply by tricking a user into...

SE Security Desk·47w ago
Bod 22-01 · Cisa

CISA Flags Urgent Patches for Exploited Citrix Session Recording and Git Flaws

The Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on August 25, 2025, signaling active exploitation of flaws...

SE Security Desk·47w ago
802.1x · Authenticode

Microsoft Fixes CVE-2025-55229 Certificate Spoofing Bug Threatening TLS, VPNs, and Code Signing

Microsoft this week disclosed CVE-2025-55229, a high-impact spoofing vulnerability in Windows certificate handling that allows attackers to bypass signature verification over a network. The flaw,...

SE Security Desk·47w ago
Apple · Bod 22-01

CISA Alerts Federal Agencies and Enterprises to Apple Image I/O Zero-Day Under Active Exploit

The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-43300 to its Known Exploited Vulnerabilities (KEV) Catalog on August 21, 2025, triggering a mandatory patch sprint for...

SE Security Desk·47w ago
Air Conditioning Controllers · Cisa

CISA's Triple Threat: Mitsubishi HVAC 9.8, Unpatched MELSEC DoS, and Fujifilm Privilege Escalation

Mitsubishi Electric’s air conditioning controllers face a critical authentication bypass with a CVSS severity score of 9.8, leading a trio of industrial control system (ICS) and medical device...

SE Security Desk·47w ago
Advisory · Automation

Mitsubishi Electric Confirms Unpatched DoS Flaw in MELSEC iQ-F PLCs, Recommends Network Hardening

Mitsubishi Electric has disclosed a remotely exploitable denial-of-service vulnerability in the embedded web server of its MELSEC iQ-F series programmable logic controllers, tracked under an internal...

SE Security Desk·47w ago
Audit Logs · Auditing

Microsoft Quietly Patches Copilot Flaw That Let Insiders Access Files Without Audit Traces

A security researcher discovered that a simple prompt technique could make Microsoft 365 Copilot summarize sensitive corporate files without leaving the required Purview audit records. Microsoft...

AI AI & Copilot Desk·47w ago
Ai Governance · Audit Logs

Microsoft Quietly Patches Copilot Audit-Log Bypass, Keeps Customers in the Dark

Security researchers have uncovered a critical blind spot in Microsoft’s Purview audit logging for Copilot: certain prompts can retrieve sensitive file contents without leaving any trace in audit...

AI AI & Copilot Desk·47w ago