< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 16 of 48

Microsoft: April updates block vulnerable psmounterex.sys

🔒 Microsoft confirms the April 2026 security updates are blocking the kernel driver psmounterex.sys, causing mounting failures and VSS snapshot timeouts in third-party backup applications such as Macrium Reflect, Acronis Cyber Protect Cloud, UrBackup Server and NinjaOne Backup on Windows 10, Windows 11 and Windows Server. The update adds the driver to the Vulnerable Driver Blocklist to mitigate CVE-2023-43896. Microsoft advises installing updated application versions that include drivers with required protections and checking the Code Integrity log for Event ID 3077 rather than uninstalling or pausing the security updates.
read more →

Microsoft Defender False-Positives Flag DigiCert Roots

🛡️ Microsoft Defender began flagging legitimate DigiCert root certificates as Trojan:Win32/Cerdigent.A!dha after a signature update on April 30, producing widespread false positives and, in some cases, removing certificates from Windows trust stores. Microsoft issued Security Intelligence updates 1.449.430.0 and 1.449.431.0 to resolve the detections and reportedly restore removed certificates. Administrators can force an update via Windows Security > Virus and threat protection > Protection updates.
read more →

Microsoft tests modern Run dialog with faster performance

🖥️ Microsoft is testing a modernized Windows 11 Run dialog in preview Build 26300.8346 that adopts Fluent Design, enables dark mode, and shows icons in suggestion lists while preserving a minimalist interface. Microsoft reports a median time-to-show of 94 ms versus roughly 103 ms for the legacy dialog and expects further platform improvements. The rarely used Browse button was removed based on telemetry. The feature is optional and can be enabled via Settings > Advanced Settings while Microsoft collects feedback.
read more →

Windows Shell Spoofing Vulnerability Forces Rapid Patching

⚠️ Microsoft and CISA have warned that a Windows shell spoofing vulnerability (CVE-2026-32202) is being actively exploited and has prompted a CISA directive requiring federal agencies to patch by May 12. Microsoft says exploitation can expose sensitive data though it does not allow full system takeover. Security experts caution the situation was aggravated by an incomplete earlier fix for CVE-2026-21510, creating a patch gap between vendor updates and organizational deployment. CISOs face a difficult balance between rapid remediation and careful testing to avoid service disruption, and are urged to apply interim mitigations where possible.
read more →

Microsoft Agent 365 Now GA: Expanded Agent Controls

🔒 Microsoft announces Agent 365 is generally available, offering a unified control plane to observe, govern, and secure AI agents across endpoints, cloud, and SaaS. The release adds discovery of local and cloud agents (including OpenClaw, GitHub Copilot CLI, and Claude Code) and integrates with Intune and Defender for inventory, policy controls, runtime blocking, and alerting. Agent 365 also introduces Windows 365 for Agents, partner integrations, and licensing via Microsoft 365 E7 or standalone at USD 15 per user per month.
read more →

Microsoft fixes Remote Desktop warning display bug

🔧 Microsoft has issued a fix for a known issue that caused newly introduced Windows security warnings to render incorrectly when opening Remote Desktop (.rdp) files on multi-monitor systems with differing display scaling. The bug affected all supported Windows versions after the April 2026 cumulative updates and was addressed in the optional Windows 11 preview update KB5083631. The misrendering could hide or misalign dialog buttons and text, preventing users from interacting with the RDP security prompt designed to block risky resource redirections.
read more →

Microsoft lets admins pick preinstalled Store apps to remove

🛠️ Microsoft expanded its in-box app removal policy for Windows 11 to add a dynamic list that allows IT admins to specify which preinstalled Microsoft Store apps to uninstall by Package Family Name (PFN). The RemoveDefaultMicrosoftStorePackages policy can be applied via Group Policy or a custom OMA-URI for MDM and requires the April 2026 non-security update (Insiders can get it with the March 13, 2026 Dev/Beta builds). Intune support for the dynamic list will arrive in the coming months.
read more →

Windows 11 KB5083631 Preview: 34 Fixes, Security and Perf

🔔 Microsoft released the optional cumulative preview update KB5083631 for Windows 11, delivering 34 quality improvements and fixes. Highlights include a new Xbox mode that provides a full‑screen gaming interface, improved startup app launch performance, and enhanced batch file/CMD security that prevents scripts from changing during execution. The update is optional and can be installed via Settings → Windows Update or manually from the Microsoft Update Catalog.
read more →

Developer's Roblox cheat triggers $2M data breach

🔒 A developer at an AI startup downloaded a dubious Roblox script onto a work laptop, a single error that cascaded into a costly breach and caused roughly $2 million in remediation. The episode also highlights the long-standing SS7 telecom weakness that enables pervasive mobile tracking and interception. Host Graham Cluley and guest James Ball interview Rob Edmondson of CoreView about how to lock down Microsoft 365 before misconfigurations are exploited.
read more →

Eight Best Practices for CISOs Conducting Risk Reviews

📋 This blog by Rico Mariani outlines eight practical best practices for CISOs conducting risk reviews, focusing on identifying assets, applications, and access controls to shape review scope and priorities. It emphasizes good quality authentication (tokens and issuers like Microsoft Entra), robust authorization, network isolation, detection, and auditing to enable proactive security. The post also highlights commonly overlooked areas such as backups, support, and development systems to ensure comprehensive risk coverage.
read more →

Chinese State-Linked Hacker Extradited to the U.S.

🛡️ Xu Zewei, a 34-year-old accused of working for China's Ministry of State Security and linked to the state-backed hacking group Hafnium (also called Silk Typhoon), has been extradited from Italy to the United States and arrived in Houston. He pleaded not guilty at a federal hearing and is being held at the Federal Detention Center. U.S. prosecutors allege Xu targeted COVID-19 researchers in early 2020 and participated in the 2021 Microsoft Exchange zero-day campaign; if convicted on charges including wire fraud, conspiracy to damage protected computers, and aggravated identity theft, he faces decades in prison.
read more →

Microsoft backend change disrupts Teams Free chat and calls

⚠️ Microsoft is investigating a known issue that prevents some Teams Free users from chatting and calling others. A recently deployed backend change is skipping onboarding and privacy consent screens for affected users, leaving profiles incomplete and causing them to appear as 'Unknown users' to others. Microsoft has flagged the incident as an service degradation, says first reports emerged on April 8, and plans another status update later today.
read more →

Microsoft to Deprecate Legacy TLS for Exchange Online

🔒 Microsoft will block legacy TLS connections for POP and IMAP access to Exchange Online starting July 2026, deprecating TLS 1.0 and TLS 1.1. Connections that attempt to use those versions will fail, which may prevent older email clients, devices, or embedded systems from connecting. The company says most customers won't be affected because the majority of traffic already uses TLS 1.2 or later. Administrators are advised to verify client configurations, update custom or legacy systems, and avoid legacy endpoints to prevent disruption.
read more →

Microsoft: New Remote Desktop Warnings Display Issue

⚠ Microsoft confirmed a display bug causing newly introduced Windows security warnings to render incorrectly when opening Remote Desktop (RDP) files. The issue affects all supported Windows releases updated in April 2026 (including Windows 11 KB5083768 & KB5083769, Windows 10 KB5082200, and Windows Server KB5082063) and appears when multiple monitors use different scaling settings, producing overlapping text and misplaced buttons. These dialogs — deployed to warn users about unsigned or unverified RDP files and to show resource redirection settings — can become difficult or impossible to interact with until Microsoft provides a fix.
read more →

Microsoft asks iPhone users to re-enter Outlook creds

📧 Microsoft has asked iPhone users to manually re-enter credentials in the default Mail app to restore access to Outlook and Hotmail accounts after a global sign-in outage. The company reported intermittent sign-in failures and some users being signed out or seeing "too many requests" errors, attributing the disruption to a "recently introduced change." Service health was reported as restored around 7 PM UTC, but iOS users must follow a step-by-step procedure in Settings → Mail → Accounts to update passwords. Microsoft has not disclosed the outage's root cause, scale, or affected regions.
read more →

Microsoft: Active Exploitation of Windows Shell Bug

🛡️ Microsoft confirmed active exploitation of a patched Windows Shell vulnerability, CVE-2026-32202, after correcting its advisory metadata. The flaw is a spoofing/authentication-coercion issue (CVSS 4.3) that can disclose sensitive information and was addressed in April Patch Tuesday. Akamai researcher Maor Dahan links the defect to an incomplete February fix for CVE-2026-21510 and says an APT28 campaign weaponized LNK/CPL/UNC/SMB chains to harvest credentials.
read more →

Microsoft Fixes Agent ID Administrator Role Privilege Flaw

🔒 Researchers at Silverfort discovered that Microsoft’s Agent ID Administrator role could modify and take ownership of unrelated service principals, allowing role holders to create credentials and authenticate as compromised applications. The flaw stemmed from scope enforcement failing in the Agent Identity Platform, where agent identities share primitives with applications. Microsoft deployed a fix by April 9, 2026; organizations should audit role assignments and service principal ownership and monitor for unexpected changes.
read more →

Microsoft: Outlook.com outage causes sign‑in failures

📧 Microsoft is investigating an ongoing Outlook.com outage that is causing intermittent sign‑in failures and unexpected sign‑outs for some users. A high volume of reports on Downdetector indicate many customers are seeing connection problems and too many requests errors when attempting to access mailboxes. Microsoft says client sign‑in scenarios may be contributing and is validating interactions across service components. The company has flagged the incident as a service degradation but has not disclosed a root cause or affected regions.
read more →

Microsoft revamps Windows Insider Program channels

🛠️ Microsoft is rolling out a revamped Windows Insider Program to simplify channel structure and improve transparency around feature availability. The company is merging Dev and Canary into a new Experimental channel for high-risk or potentially non-shipping work, while maintaining an updated Beta channel where features in release notes will be broadly available without gradual rollouts. Experimental items may be gated behind Feature flags that users can toggle in Settings, and Microsoft is migrating Insiders in phases while shipping several preview builds and an updated Windows Update experience to give users more control over updates and reboots.
read more →

Windows Update adds controls to reduce forced restarts

🔧 Microsoft is rolling out Windows Update improvements to give users more control over update timing and reduce disruptive restarts. Insiders will see options to skip updates during OOBE, select specific pause dates via a calendar for up to 35 days, and separate standard power actions from update-triggering commands. Driver, .NET, and firmware updates will be consolidated with monthly quality updates to minimize reboots, while users can still opt to install specific updates earlier.
read more →