Live
CVE-2025-53741: Microsoft Issues Emergency Excel Patch to Stop Remote Code Execution via Heap Overflow·MSFT +2.1%Microsoft Fixes SQL Server Flaw That Allows Privilege Escalation via SQL Injection·NVDA +0.2%Microsoft Patches Azure File Sync EoP Vulnerability CVE-2025-29973—What IT Admins Must Do Now·GOOGL +1.7%Critical 8.4 CVSS Flaws in Ashlar-Vellum Cobalt/Xenon/Argon Allow Code Execution via Malicious CAD Files·AMZN +1.1%Zero-Click Data Leak in Microsoft 365 Copilot BizChat Exposes Enterprise Secrets·MSFT +2.1%Microsoft Confirms Critical Azure OpenAI Privilege Escalation Flaw, Urges Vigilance Until Patch·NVDA +0.2%CVE-2025-53792: Azure Portal Privilege Escalation Bug Could Lead to Full Cloud Control·GOOGL +1.7%CVE-2025-8579: Google Patches Critical Gemini Live Flaw—Edge Users Must Update Too·AMZN +1.1%CVE-2025-53741: Microsoft Issues Emergency Excel Patch to Stop Remote Code Execution via Heap Overflow·MSFT +2.1%Microsoft Fixes SQL Server Flaw That Allows Privilege Escalation via SQL Injection·NVDA +0.2%Microsoft Patches Azure File Sync EoP Vulnerability CVE-2025-29973—What IT Admins Must Do Now·GOOGL +1.7%Critical 8.4 CVSS Flaws in Ashlar-Vellum Cobalt/Xenon/Argon Allow Code Execution via Malicious CAD Files·AMZN +1.1%Zero-Click Data Leak in Microsoft 365 Copilot BizChat Exposes Enterprise Secrets·MSFT +2.1%Microsoft Confirms Critical Azure OpenAI Privilege Escalation Flaw, Urges Vigilance Until Patch·NVDA +0.2%CVE-2025-53792: Azure Portal Privilege Escalation Bug Could Lead to Full Cloud Control·GOOGL +1.7%CVE-2025-8579: Google Patches Critical Gemini Live Flaw—Edge Users Must Update Too·AMZN +1.1%

Vulnerability

The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 4:18 PM
Latest Most Read Breaking
Sort
Asr · Buffer Overflow

CVE-2025-53741: Microsoft Issues Emergency Excel Patch to Stop Remote Code Execution via Heap Overflow

Microsoft has disclosed a critical heap-based buffer overflow vulnerability in Excel, tracked as CVE-2025-53741, that can give attackers the ability to remotely execute code on a vulnerable machine...

Advertisement
Ai Chat Security · Ai Privacy

Zero-Click Data Leak in Microsoft 365 Copilot BizChat Exposes Enterprise Secrets

A newly disclosed vulnerability in Microsoft 365 Copilot BizChat can expose sensitive business information without any user interaction, Microsoft warned in a security advisory published this week....

AI AI & Copilot Desk·49w ago
Access Control · Ai Security

Microsoft Confirms Critical Azure OpenAI Privilege Escalation Flaw, Urges Vigilance Until Patch

{ "title": "Microsoft Confirms Critical Azure OpenAI Privilege Escalation Flaw, Urges Vigilance Until Patch", "content": "Microsoft has officially acknowledged a critical security vulnerability...

AI AI & Copilot Desk·49w ago
Azure Monitor · Azure Security

CVE-2025-53792: Azure Portal Privilege Escalation Bug Could Lead to Full Cloud Control

Microsoft has released a security update for CVE-2025-53792, a critical elevation-of-privilege vulnerability in the Azure Portal that allows authenticated attackers to bypass role-based access...

SE Security Desk·49w ago
Browser Issues · Browser Patch

CVE-2025-8579: Google Patches Critical Gemini Live Flaw—Edge Users Must Update Too

CVE-2025-8579, a critical security flaw in Google Chrome's Gemini Live feature, has been patched after four months of quiet danger. The vulnerability, reported by researcher Alesandro Ortiz on April...

AI AI & Copilot Desk·49w ago
Browser Security · Chrome

Chrome 139 Patches UI Spoofing Flaw That Tricks Users Into Giving Away Permissions—Edge Users Are Protected Too

Google has shipped a critical security fix for Chrome that plugs a user interface spoofing hole attackers could use to trick people into giving websites access to their camera, microphone, or...

SE Security Desk·49w ago
Browser Security · Chrome

CVE-2025-8581: The Low-Risk Chrome Extension Bug That Still Requires an Immediate Update on Edge and Chrome

Google has patched a security vulnerability in Chrome’s Extensions framework that could have allowed attackers to siphon sensitive cross-origin data from unsuspecting users. Tracked as...

SE Security Desk·49w ago
Browser Security · Chrome

CVE-2025-8578: Chrome Cast Vulnerability Sparks Urgent Updates for Chrome and Edge

A critical use-after-free vulnerability in Google Chrome’s Cast component, tracked as CVE-2025-8578, has been patched by both Google and Microsoft, after researchers confirmed that attackers could...

SE Security Desk·49w ago
Browser Security · Browser Updates

Critical CVE-2025-8582 DOM Vulnerability Patched in Chrome and Edge – Users Urged to Update

On August 5, 2025, Google shipped an urgent security update for Chrome that plugs a dangerous hole in the browser's Document Object Model (DOM) handling. Tracked as CVE-2025-8582, the vulnerability...

SE Security Desk·49w ago