Vulnerability
The latest Vulnerability coverage — news, analysis, and updates from the WindowsNews.AI desk.
Critical Chromium Use-After-Free Flaw CVE-2025-8576 Triggers Urgent Edge, Chrome Updates
A severe use-after-free vulnerability in the Chromium extensions engine, tracked as CVE-2025-8576, is driving urgent updates across the browser ecosystem. The flaw, which carries high severity,...
Akira Ransomware Exploits Intel ThrottleStop Driver to Disable Windows Defender in Stealthy BYOVD Campaign
A potent ransomware campaign has turned a trusted Intel CPU tuning driver into a weapon, allowing attackers to evade Windows 11's built-in defenses by disabling Microsoft Defender with surgical...
Black Hat Demo Exposes Windows Hello Biometric Flaw: Admin Rights Enable Face Injection Attack
German security researchers at the Black Hat USA 2025 conference in Las Vegas have demonstrated a stark vulnerability in Microsoft’s Windows Hello biometric authentication system. The live demo...
Exchange Hybrid Bug Lets Attackers Quietly Escalate to Cloud Admin — Patch Now
A single compromise on a dusty, overlooked Exchange Server can now silently hand an attacker the keys to your entire Microsoft 365 kingdom — with no alarm raised and no audit trail left behind....
Four Yealink IP Phone Vulnerabilities Expose Enterprise VoIP to Brute-Force and Certificate Attacks
Four newly disclosed security vulnerabilities in Yealink’s widely deployed IP phones and cloud-based Redirect and Provisioning Service (RPS) have thrust business communications security into urgent...
Critical 8.4 CVSS Flaw in Johnson Controls FX Controllers Threatens Building Automation Systems Worldwide
Critical infrastructure operators worldwide are scrambling to apply emergency patches after a dangerous new vulnerability was disclosed in Johnson Controls’ FX80, FX90, and FX Server platforms....
Patch Now: 9.3-Rated Path Traversal in Delta DIAView ICS Puts Critical Sectors at Risk
A severe path traversal vulnerability in Delta Electronics’ DIAView industrial automation platform has sent shockwaves through the operational technology community, after federal cybersecurity...
CVE-2025-53786: How a Hybrid Exchange Flaw Turns On-Prem Access into Cloud Catastrophe
Attackers who manage to breach an on-premises Microsoft Exchange server can now pivot to the cloud with a set of unrevocable credentials—and for 24 hours, defenders are all but helpless. That is...
CVE-2025-53786: The Silent Hybrid Exchange Exploit That Bypasses All Cloud Defenses
Microsoft has issued an urgent warning about a high-severity vulnerability in hybrid Exchange deployments that could let attackers who breach an on-premises server silently escalate their privileges...
KB5060999: Microsoft’s June 2025 Windows 11 Update Breaks CJK Font Clarity, Delays IT Rollouts
Microsoft shipped its June 2025 security update for Windows 11 on June 10, and while it plugs a fresh set of operating system vulnerabilities, the patch lands with two conspicuous side effects:...
Microsoft Issues Emergency Patch for Critical WSL Vulnerability CVE-2025-53788
A quiet urgency has swept across both the Windows and Linux communities with Microsoft’s recent emergency patch for a critical security vulnerability in the Windows Subsystem for Linux (WSL). This...
Critical Security Update for Microsoft Exchange Server Hybrid Environments: Addressing CVE-2025-53786 Vulnerability
A new critical security update targeting Microsoft Exchange Server environments—specifically those deployed in hybrid cloud configurations—has rapidly gained attention among IT administrators and...