Tag: microsoft


  • Microsoft Removes WMIC From New Windows 11 Builds

    Microsoft has removed the legacy WMIC command-line tool from new Windows 11 installations, taking away a built-in utility that cybercriminals have repeatedly abused during attacks. The change affects Windows 11 versions 24H2 and 25H2, along with this week’s Windows 11 beta releases. While WMIC is disappearing, the underlying Windows Management Instrumentation platform remains available. Microsoft…

  • Microsoft patches LegacyHive Windows zero-day vulnerability

    Microsoft has released security updates for the LegacyHive vulnerability, a Windows zero-day flaw that could allow a local attacker to gain administrator privileges. Tracked as CVE-2026-62832, the issue affects the Windows User Profile Service. Microsoft fixed it in the August 2026 Patch Tuesday updates after a public proof-of-concept exploit appeared shortly after July’s patches. LegacyHive…

  • Attackers Use Real Microsoft Sign-In Screens in Phishing Campaign

    A new Microsoft sign-in screen phishing campaign is using genuine Microsoft login pages to bypass traditional phishing checks. Instead of directing users to a fake website, attackers trick them into approving a malicious app after they sign in. Check Point researchers found that the campaign used convincing HR-themed Microsoft Teams lures. Once a victim grants…

  • Microsoft TPM Attestation Will Block Many Windows KMS Activators

    Microsoft is preparing to require TPM attestation for servers that manage Windows Key Management Service activation, a move that could block many fake Windows KMS activators used for software piracy. The company says future KMS hosts will need to prove that they are running on verified and uncompromised hardware before they can activate Windows client…

  • Microsoft Fixes RoguePlanet Defender Zero-Day Vulnerability

    Microsoft has released a security update to fix the RoguePlanet vulnerability, a Microsoft Defender zero-day disclosed shortly after the June 2026 Patch Tuesday. Security researcher Nightmare Eclipse publicly disclosed the flaw, tracked as CVE-2026-50656, during an ongoing dispute with Microsoft over its vulnerability disclosure and bug bounty practices. RoguePlanet Vulnerability Affected Fully Patched Systems According…

  • Microsoft GDID Tracking Sparks Privacy Backlash After Hacker’s Arrest

    The FBI’s arrest of an alleged member of the Scattered Spider hacking group has triggered a wider debate over Microsoft GDID tracking and user privacy. Court documents show investigators identified 19-year-old Peter Stokes by linking activity to a persistent Windows Global Device Identifier (GDID). The case has left many Windows users questioning how much device…

  • Avans University Reports Year-Long Microsoft Power BI Data Breach

    A Microsoft Power BI data breach at the Avans University of Applied Sciences exposed sensitive personal information to unauthorized users for nearly a year before staff discovered the issue. The university has since fixed the vulnerability, notified affected individuals, and reported the incident to Dutch data protection authorities. Misconfiguration Exposed Personal Data for Nearly a…

  • Microsoft Quantum Safe Roadmap Targets Post-Quantum Security by 2029

    Microsoft has accelerated its Microsoft quantum safe roadmap, warning that advances in quantum computing are bringing the transition to post-quantum cryptography closer than previously expected. The company now plans to migrate critical products and services to quantum-resistant encryption by 2029 while encouraging organizations to begin preparing immediately. The updated strategy reflects growing concerns that attackers…

  • Microsoft Teams Bot Protection Blocks Unapproved Meeting Bots

    Microsoft has introduced Microsoft Teams bot protection that prevents unauthorized third-party bots from joining meetings without organizer approval. The new policy gives organizations greater control over AI assistants and automated applications while reducing the risk of malicious bots quietly accessing sensitive conversations. The company released the feature as part of its broader effort to strengthen…

  • Microsoft Warns of Hotel Phishing Campaign Targeting Europe and Asia

    Microsoft has uncovered a sophisticated hotel phishing campaign targeting hospitality businesses across Europe and Asia. The attackers disguise malware as photo attachments and trick hotel employees into opening them. Once activated, the files install malware that gives cybercriminals long-term access to infected systems. Microsoft has not linked the activity to a known threat group, and…