Microsoft has removed the legacy WMIC command-line tool from new Windows 11 installations, taking away a built-in utility that cybercriminals have repeatedly abused during attacks. The change affects Windows 11 versions 24H2 and 25H2, along with this week’s Windows 11 beta releases. While WMIC is disappearing, the underlying Windows Management Instrumentation platform remains available. Microsoft…
Microsoft has released security updates for the LegacyHive vulnerability, a Windows zero-day flaw that could allow a local attacker to gain administrator privileges. Tracked as CVE-2026-62832, the issue affects the Windows User Profile Service. Microsoft fixed it in the August 2026 Patch Tuesday updates after a public proof-of-concept exploit appeared shortly after July’s patches. LegacyHive…
A new Microsoft sign-in screen phishing campaign is using genuine Microsoft login pages to bypass traditional phishing checks. Instead of directing users to a fake website, attackers trick them into approving a malicious app after they sign in. Check Point researchers found that the campaign used convincing HR-themed Microsoft Teams lures. Once a victim grants…
Microsoft is preparing to require TPM attestation for servers that manage Windows Key Management Service activation, a move that could block many fake Windows KMS activators used for software piracy. The company says future KMS hosts will need to prove that they are running on verified and uncompromised hardware before they can activate Windows client…
Microsoft has released a security update to fix the RoguePlanet vulnerability, a Microsoft Defender zero-day disclosed shortly after the June 2026 Patch Tuesday. Security researcher Nightmare Eclipse publicly disclosed the flaw, tracked as CVE-2026-50656, during an ongoing dispute with Microsoft over its vulnerability disclosure and bug bounty practices. RoguePlanet Vulnerability Affected Fully Patched Systems According…
The FBI’s arrest of an alleged member of the Scattered Spider hacking group has triggered a wider debate over Microsoft GDID tracking and user privacy. Court documents show investigators identified 19-year-old Peter Stokes by linking activity to a persistent Windows Global Device Identifier (GDID). The case has left many Windows users questioning how much device…
A Microsoft Power BI data breach at the Avans University of Applied Sciences exposed sensitive personal information to unauthorized users for nearly a year before staff discovered the issue. The university has since fixed the vulnerability, notified affected individuals, and reported the incident to Dutch data protection authorities. Misconfiguration Exposed Personal Data for Nearly a…
Microsoft has accelerated its Microsoft quantum safe roadmap, warning that advances in quantum computing are bringing the transition to post-quantum cryptography closer than previously expected. The company now plans to migrate critical products and services to quantum-resistant encryption by 2029 while encouraging organizations to begin preparing immediately. The updated strategy reflects growing concerns that attackers…
Microsoft has introduced Microsoft Teams bot protection that prevents unauthorized third-party bots from joining meetings without organizer approval. The new policy gives organizations greater control over AI assistants and automated applications while reducing the risk of malicious bots quietly accessing sensitive conversations. The company released the feature as part of its broader effort to strengthen…
Microsoft has uncovered a sophisticated hotel phishing campaign targeting hospitality businesses across Europe and Asia. The attackers disguise malware as photo attachments and trick hotel employees into opening them. Once activated, the files install malware that gives cybercriminals long-term access to infected systems. Microsoft has not linked the activity to a known threat group, and…