Zero Day Threats
The latest Zero Day Threats coverage — news, analysis, and updates from the WindowsNews.AI desk.
Chrome and Edge Users Alerted to Critical PiP Flaw CVE-2025-8577 as Patches Roll Out
A serious security vulnerability in the Chromium engine’s Picture-in-Picture (PiP) feature is being urgently patched by Google and Microsoft, affecting millions of users of Chrome, Edge, and other...
The Evolution of Windows Administrator Protection: Balancing Security and Usability
The evolution of Windows security has been a story of continual adaptation, responding to the ever-changing threat landscape while striving to preserve the accessibility and productivity that users...
July 2025 Patch Tuesday breaks 22-month zero-day streak with 78 fixes, six critical.
For the first time in recent memory, Microsoft’s Patch Tuesday has arrived with a touch of optimism: July 2025’s security update package dropped without a single known exploited vulnerability in...
Windows 11’s Smart App Control Blocks Untrusted Apps Proactively — Here’s What You Need to Know
When Microsoft rolled out the Windows 11 2022 Update (version 22H2), it quietly shipped one of the most aggressive consumer security features in years: Smart App Control. Unlike traditional antivirus...
Windows 11's Smart App Control: How It Blocks Unknown Threats—and Why a Reinstall May Be the Price You Pay
Windows 11 draws a hard line with Smart App Control: unknown executables are guilty until proven innocent. This cloud‑powered, machine‑learning‑driven feature stops untrusted code before it...
Smart App Control in Windows 11 blocks untrusted apps by default, but requires clean install.
Introduction In the ever-evolving landscape of cybersecurity, Microsoft has introduced Smart App Control (SAC) in Windows 11, aiming to provide users with a proactive defense mechanism against...
AI-Driven Defense Blocks Advanced Microsoft 365 Device Code Phishing Attacks
Advanced Microsoft 365 Phishing Attacks and How AI-Driven Defense Shields Your Organization Phishing attacks targeting Microsoft 365 users have escalated to alarming levels of sophistication. A newly...
Critical Windows RRAS Vulnerability (CVE-2025-29959) Exposes VPN Systems to Memory Leak Exploits
A newly disclosed critical vulnerability in Windows Routing and Remote Access Service (RRAS) is sending shockwaves through enterprise security teams, exposing millions of VPN and network routing...
Chromium bug CVE-2025-4372 lets hackers hijack Chrome and Edge via WebAudio.
Overview A critical security vulnerability, identified as CVE-2025-4372, has been discovered in the WebAudio component of the Chromium browser engine. This flaw affects both Google Chrome and...