< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 30 of 48

Microsoft Releases Windows 10 KB5073724 ESU Update

🔒 Microsoft released the KB5073724 Extended Security Update for Windows 10, available to Windows 10 Enterprise LTSC and systems enrolled in the ESU program. Install via Settings → Windows Update by performing a manual “Check for Updates”; installs update and raises builds to 19045.6809 (Windows 10) and 19044.6809 (Enterprise LTSC 2021). The update contains only security and bug fixes — including patches for three zero-days, an actively exploited elevation-of-privilege fix in Agere modem drivers, an updated WinSqlite3.dll, and targeted handling for expiring Secure Boot certificates.
read more →

Windows 11 KB5074109 & KB5073455 January 2026 Updates

🛡️ Microsoft released Windows 11 cumulative updates KB5074109 and KB5073455 as the January 2026 Patch Tuesday rollups for 25H2/24H2 and 23H2. The updates are mandatory and advance affected systems to new builds (25H2: 26200.7623 / 24H2: 26100.7462 / 23H2: 226x1.6050), addressing security vulnerabilities, stability fixes, and feature changes. Key fixes include removal of specific legacy modem drivers that will disable dependent hardware, networking repairs for WSL and Azure Virtual Desktop RemoteApp, an NPU idle power fix, an update to WinSqlite3.dll, and a new phased Secure Boot certificate targeting mechanism; Microsoft notes only a minor bug that can hide the password visibility button.
read more →

Microsoft January 2026 Patch Tuesday: 114 Flaws Fixed

🔒Microsoft released its January 2026 Patch Tuesday updates addressing 114 vulnerabilities, including three zero-day flaws and one actively exploited issue. The bulletin patches an actively exploited Desktop Window Manager information disclosure (CVE-2026-20805), renews expiring Secure Boot certificates, and removes legacy Agere modem drivers (agrsm64.sys, agrsm.sys). Eight vulnerabilities are rated Critical, including six remote code execution flaws. Administrators should prioritize these cumulative updates and apply them promptly to reduce exposure.
read more →

Microsoft Patch Tuesday Jan 2026: 112 Fixes and Snort rules

🔒 Microsoft released its January 2026 security updates addressing 112 vulnerabilities across Windows and Office, including eight marked critical. One important issue, CVE-2026-20805, was observed exploited in the wild. Critical flaws include RCEs in LSASS, Word, Excel and Office, plus EoP in the Windows Graphics component and VBS Enclave. Cisco Talos published Snort rules to detect exploitation attempts (Snort 2: 65498, 65499, 65663–65676; Snort 3: 301344, 301368–301374).
read more →

How Microsoft Integrates Privacy and Security by Design

🔐 In a Deputy CISO post, Terrell Cox explains how Microsoft aligns privacy and security as complementary priorities, treating privacy as a human right across products from Microsoft 365 to Azure. The company enforces rigorous internal compliance—audits, cross‑functional reviews, and executive oversight—and limits data access through controls like Customer Lockbox and zero‑trust access. Microsoft highlights solutions such as Microsoft Entra, Entra ID, and Microsoft Purview to support data residency, classification, protection, and regulatory compliance.
read more →

CISA Adds Microsoft Windows CVE to KEV Catalog - Jan 2026

🔔 CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog: CVE-2026-20805, a Microsoft Windows information disclosure issue identified as being actively exploited. This vulnerability type is a common attack vector and presents significant risks to the federal enterprise. Under BOD 22-01, Federal Civilian Executive Branch agencies are required to remediate KEV entries by prescribed due dates, and CISA strongly urges all organizations to prioritize timely remediation. CISA will continue to update the KEV Catalog as new exploited CVEs meet its criteria.
read more →

CISOs Name Top 10 Vendors for AI-Enabled Security in 2025

🔒 The CSO 2025 Security Priorities Study asked more than 640 senior security executives to rank leaders in AI-enabled security, and established, name-brand vendors dominated the results. CISOs prioritized product innovation but heavily weighed reputation, breach history, business value, cost, time to integrate, and peer adoption. The top-ranked providers included Cisco, Microsoft, and Google, while MSSPs and cloud-native service providers also gained visibility as teams seek managed incident response.
read more →

January 2026 Patch Tuesday: 114 CVEs Including Zero-Days

🔔 Microsoft released its January 2026 Patch Tuesday addressing 114 vulnerabilities, including three zero-days and several Critical flaws. Notable fixes include an actively exploited information-disclosure issue in Windows Desktop Window Manager (CVE-2026-20805) and publicly disclosed zero-days in Agere Soft Modem and Secure Boot. The release also remediates multiple Critical RCE and elevation-of-privilege issues across Windows and Microsoft Office. Organizations should prioritize testing and deployment and apply compensating controls where immediate patching is impractical.
read more →

Microsoft to Retire Lens Scanner App on iOS, Android

📢 Microsoft has begun retiring the Microsoft Lens PDF scanner app for iOS and Android, with removal from app stores set for February 9, 2026 and scanning functionality scheduled to stop on March 9, 2026. Microsoft updated its Microsoft 365 Message Center guidance and recommends users switch to OneDrive's built-in scan feature. Existing scans remain accessible via MyScans while the app stays installed and the user is signed into their last active account, though Microsoft will no longer support the app after the cutoff. No administrative action is required; administrators should notify users of the change.
read more →

Prevent Cloud Data Leaks with Microsoft 365 Access Reviews

🔒 Microsoft 365 sharing is convenient but can quickly lead to uncontrolled access and data exposure. This sponsored article explains how tenfold provides centralized visibility across Teams, OneDrive and SharePoint and introduces targeted access reviews for shared content. Personalized review dashboards let owners confirm or revoke links, and automated enforcement removes permissions that fail review.
read more →

Microsoft Brings Claude to Foundry for Healthcare AI

🏥 Microsoft announced Claude for Healthcare and Life Sciences is now available in Microsoft Foundry, bringing Anthropic’s Claude models into an Azure-backed, enterprise-grade platform for regulated health and research environments. The release emphasizes domain-tuned agents, model context protocols (MCPs), connectors, and skill libraries designed to support multi-step clinical and R&D workflows. Microsoft highlights specific applications such as prior authorization automation, claims appeal processing, care coordination triage, and life-sciences tasks from protocol design to bioinformatics. The offering underscores governance, safety investments, and flexible deployment options across regulated settings.
read more →

Microsoft to Remove 'Send to Kindle' Option in Word

📚 Microsoft will retire the Send Documents to Kindle option in Microsoft Word, with the change rolling out after February 2026. The feature, formerly accessible from Word's Export menu, allowed .doc and .docx files to be transferred to a user's Kindle library while preserving page layout and most formatting. Microsoft notes that comments and tracked changes were not preserved when files were sent. After the retirement, users should use the Send to Kindle website to transfer documents.
read more →

Microsoft to Let IT Admins Uninstall Copilot on Devices

🔧 Microsoft is testing a new Group Policy, RemoveMicrosoftCopilotApp, that enables IT administrators to uninstall the AI-powered Copilot app on managed Windows devices. The policy began rolling out in the Dev and Beta Insider channels with Windows 11 Insider Preview Build 26220.7535 (KB5072046) and applies to endpoints managed via Microsoft Intune or SCCM. It targets systems where both Microsoft 365 Copilot and Microsoft Copilot are installed, the app was not user-installed, and it hasn't been launched in the last 28 days. Admins can enable the setting at User Configuration -> Administrative Templates -> Windows AI -> Remove Microsoft Copilot App; users may still reinstall if they choose.
read more →

CrowdStrike to Buy SGNL for $740M to Add Real-Time Identity

🔐 CrowdStrike will acquire identity security startup SGNL for $740 million to add real-time, risk-aware authorization that grants or revokes access based on current signals rather than static permissions. The deal, expected to close in CrowdStrike’s fiscal Q1 ending April 30, will be paid mostly in cash with some stock subject to vesting. SGNL’s technology layers with existing identity systems from Okta, Microsoft, and AWS, evaluating contextual signals — user behavior, device posture, and threat intelligence — to enforce continuous authorization and address rising machine-identity and AI-agent risks.
read more →

Microsoft Exchange Online outage affects IMAP4 access

⚠ Microsoft is investigating an Exchange Online outage (EX1215307) that intermittently prevents users from accessing mailboxes via IMAP4. Microsoft attributes the disruption to a recent IMAP deployment that introduced a code conflict and authentication misconfiguration, and says a configuration fix has been deployed and is being rolled out. Other connection methods are not affected, and Microsoft advises retries may restore access while the update completes.
read more →

Microsoft Enforces MFA for Microsoft 365 Admin Center Access

🔐 Microsoft will require MFA for all users signing into the Microsoft 365 admin center and will block accounts that do not have MFA enabled starting February 9, 2026. The enforcement covers portal.office.com/adminportal/home, admin.cloud.microsoft, and admin.microsoft.com and follows an initial rollout that began in February 2025. Administrators are urged to enable MFA using Microsoft's setup wizard or official documentation to avoid service interruptions; Microsoft notes that MFA significantly reduces the risk of account compromise.
read more →

CISA Flags Microsoft Office and HPE OneView KEV Flaws

⚠️ CISA added two vulnerabilities — in Microsoft Office PowerPoint (CVE-2009-0556, CVSS 8.8) and HPE OneView (CVE-2025-37164, CVSS 10.0) — to its Known Exploited Vulnerabilities catalog after observing evidence of active exploitation. The HPE flaw permits unauthenticated remote code execution and affects versions prior to 11.00; HPE has released hotfixes for OneView 5.20 through 10. A proof-of-concept exploit for CVE-2025-37164 was disclosed publicly on December 23, 2025, prompting eSentire to urge immediate patching. Federal agencies subject to BOD 22-01 are instructed to remediate by January 28, 2026.
read more →

Microsoft Incident Response: New Proactive Services

🔒 Microsoft Incident Response expands its proactive offerings to help organizations build cyber resilience and reduce disruption. New services include incident response plan development, major event support, an immersive cyber range, advisory engagements, and compromise assessments for M&A activity. These capabilities build on existing services such as compromise assessments, identity assessment and hardening, and tabletop exercises. The focus is on preparation, gap detection, defense hardening, and tailored threat insights to accelerate recovery and strengthen security posture.
read more →

Classic Outlook bug prevents opening encrypted emails

🔒 Microsoft is investigating a bug in the classic Outlook client introduced by Current Channel Version 2511 (Build 19426.20218) that prevents recipients from opening messages encrypted with Encrypt Only permissions. Impacted users may see a reading pane error asking them to verify credentials or encounter a message_v2.rpmsg attachment instead of readable content. The Outlook Team is working on a fix but has not provided an ETA. Microsoft recommends two temporary workarounds: have senders save encrypted messages before sending, or roll back to build 16.0.19426.20186.
read more →

Microsoft Alerts: Phishing Uses Email Routing and DMARC Gaps

📧 Microsoft’s Threat Intelligence team warns that attackers are increasingly exploiting complex email routing and misconfigured DMARC and SPF policies to make phishing messages appear to come from inside targeted organizations. These campaigns often rely on MX records that route mail through on‑premises servers or third‑party relays before Microsoft 365, which can prevent correct spoof checks. Threat actors deliver lures ranging from password resets to shared documents and use PhaaS platforms such as Tycoon 2FA. Microsoft advises enforcing strict DMARC reject and SPF hard-fail policies, verifying connectors, and adopting phishing-resistant MFA like FIDO2 keys.
read more →