< ciso
brief />
Tag Banner

All news with #microsoft tag

1056 articles · page 6 of 53

Windows 11 preview update KB5120998: 35 fixes

🛈 Microsoft released the KB5120998 preview cumulative update for Windows 11 25H2 and 24H2, bringing 35 non-security changes and improvements to the Start menu, taskbar, search, and system behaviors. This optional update lets administrators test bug fixes and new features before they're broadly deployed in the next Patch Tuesday release. It also begins rolling out an administrator protection feature that supplies just-in-time privileges and profile separation, disabled by default and configurable via Intune or Group Policy.
read more →

August 2026 Microsoft Security updates overview

🛡️ This update details new Microsoft Security capabilities for August 2026, focusing on AI agent visibility, broader threat coverage, and improved management across environments. Highlights include expanded Microsoft Defender Experts MDR coverage for third-party data sources, Microsoft Entra Tenant Governance for multi-tenant visibility, and Windows device management improvements. Other updates boost data protection with increased auto-labeling throughput in Microsoft Purview and introduce Secure Now guidance for agentic containment.
read more →

Microsoft issues fix for Windows 11 gaming crashes

🎮 Microsoft has begun rolling out a permanent fix for an issue that caused system crashes and games to fail with EXCEPTION_ACCESS_VIOLATION on Windows 11 devices. The problem was traced to the inpoutx64.sys driver used by peripherals or internal components with RGB lighting. The company is deploying a block that disables the driver on affected consumer and unmanaged business devices and has provided a registry workaround for enterprise administrators.
read more →

CISA Adds Six Actively Exploited Flaws to KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity issue in Citrix NetScaler ADC and NetScaler Gateway with evidence of active exploitation. The list includes flaws affecting Microsoft SQL Server, the Linux Kernel, Red Hat components, Ajax.NET Professional, and Citrix, with CISA issuing remediation deadlines for federal agencies. Security firms reported web shells and discovery activity tied to attempts exploiting the Citrix flaw, and telemetry has identified multiple attacker IPs worldwide. CISA also published a vulnerability review highlighting injection and memory-safety weaknesses as frequent root causes of exploitation.
read more →

Securing AI Gateways and Control Plane Targets

🔒 Microsoft describes attacks targeting AI infrastructure components such as gateways, retrieval platforms, orchestration services, and container runtimes that centralize credentials and execution privileges. Observed intrusions against LiteLLM, RAGFlow, and Kestra aimed to harvest secrets, persist on hosts, and monetize compute. The advisory emphasizes inventorying exposed AI surfaces, restricting administrative access, and monitoring gateway-originated execution and secret access to mitigate risk.
read more →

Reducing AI agent costs with runtime optimizations

🔍 This post explains how Microsoft Foundry helps reduce the cost per successful AI outcome by optimizing each model request at runtime. It outlines four levers—model routing and deployment choices, caching, prompt and agent optimization, and observability—that teams can apply, measure, and reverse if necessary. The guidance emphasizes matching model and deployment choices to task complexity, using caching and fine-tuning to lower repeated costs, and relying on observability and evaluation to validate savings without degrading quality.
read more →

Attackers Target SharePoint RCE Chain and PoC Exploits

🛡️ Defused warns attackers are chaining two Microsoft SharePoint flaws — CVE-2026-55040 and CVE-2026-63520 — to achieve remote code execution on unpatched servers. Public proof-of-concept exploits were published in August and were quickly weaponized, with probes observed against honeypots and large-scale internet-exposed SharePoint instances. CISA has issued directives to secure SharePoint servers while Microsoft monitors exploitation activity.
read more →

Microsoft tests per-app privacy controls in Windows 11

🔒 Microsoft is testing new privacy controls in Windows 11 Insider Experimental Preview Build 26340.9233 that let users manage camera, microphone, and location access per desktop app. Previously, these permissions were controlled by device-wide settings. Insiders can adjust access under Settings > Privacy & security using dedicated toggles. Microsoft cautions users to grant access only to trusted apps, noting some apps may appear unsigned or under different names.
read more →

Microsoft: Patch Window Is Collapsing, Adopt Network Controls

🛡️ Microsoft warns that the interval between vulnerability disclosure and exploitation is rapidly shrinking, outpacing many organizations' ability to safely deploy patches. Igor Sakhnov, Azure Networking GM, urges a shift to network-level controls as a temporary control plane to limit exposure while patches are tested and rolled out. Analysts note the model suits mature cloud environments but faces practical challenges such as poor asset visibility and risks that temporary measures become permanent liabilities.
read more →

PowerToys adds app-only window switching feature

🔧 Microsoft released PowerToys 0.101.2362.0, introducing a new utility called Window Hopper that lets users cycle through windows of the currently focused app using a configurable Alt + backtick shortcut. The update also brings a compact Command Palette mode, PowerDisplay linked control support for shortcuts, DemoMirror for ZoomIt, and a Mouse Highlighter ripple mode. PowerToys remains open source on GitHub with a detailed changelog.
read more →

Microsoft Teams adds admin controls to block external bots

🛡️ Microsoft is introducing a Teams meeting protection policy that lets administrators automatically block identified external bots from joining meetings. This builds on a June update that flagged detected bots for organizer approval; the new policy prevents such bots from joining without confirmation. Rolling out in targeted release through August and GA by late September, the setting is off by default and must be enabled and assigned via the Teams admin center.
read more →

August .NET updates break WPF printing and PDF export

🛠️ Microsoft confirmed that August 2026 .NET Framework cumulative updates are causing some Windows Presentation Foundation (WPF) applications to fail with a System.IO.FileFormatException when printing or generating PDF/XPS content using certain fonts such as Calibri. The issue affects multiple client and server Windows releases, and Microsoft provided a temporary AppContext switch workaround that must be added to the application config file. The company warns this workaround disables protections added in the update and should be used only temporarily while a permanent fix is developed.
read more →

Windows Defender driver can be repurposed for abuse

🛡️ Check Point Research found that Microsoft-signed Boot-Time Removal driver BTR.sys can be abused to perform kernel-level file and registry operations, potentially neutralizing security controls. The technique uses an undocumented encrypted transaction format rather than a conventional IOCTL interface and affects Windows versions from Windows 7 through Windows 11 25H2. CPR released a proof-of-concept tool, BTR_CLI, demonstrating extraction, transaction construction, and driver loading using the system's own copy of BTR.sys. Microsoft indicated the issue did not meet criteria for immediate servicing and noted the attack requires pre-existing privileges.
read more →

Microsoft issues temporary fix for Windows 11 gaming bug

🎮 Microsoft provided a temporary workaround for a gaming crash issue introduced with the August 11, 2026 Windows 11 updates (KB5121003). The bug caused crashes, freezes, EXCEPTION_ACCESS_VIOLATION errors, and restarts when launching certain games on 24H2 and 25H2 systems. Investigation linked the problem to RGB device drivers/components, specifically files like inpoutx64.sys. Microsoft’s interim fix disables the driver via a Registry change, with warnings to back up and potential loss of RGB functionality.
read more →

Microsoft Links Gaming Crashes to RGB Device Drivers

🎮 Microsoft says the August 2026 Windows update (KB5121003) has triggered game crashes, freezes, and EXCEPTION_ACCESS_VIOLATION errors on systems running Windows 11 24H2 and 25H2. The company is investigating and attributes the problem to drivers or components installed by peripherals with RGB lighting that include files named like inpoutx64. Affected titles include ARC Raiders, MARVEL Tōkon: Fighting Souls, and The Finals. Developers such as Embark Studios offered a temporary workaround involving removal of the inpoutx64 driver while Microsoft continues its investigation.
read more →

Microsoft introduces Classic Outlook theme rollout

📣 Microsoft is rolling out a Classic Outlook theme for Outlook on the web and New Outlook for Windows as part of a targeted release starting mid-August and completing by late September. The theme will become generally available worldwide between late September and late October. When enabled, it adjusts visual styling, layout, typography, icons, and selected interactions while respecting administrator settings and not migrating users automatically.
read more →

Microsoft patches critical Entra ID deserialization flaw

🔐 Microsoft patched a maximum-severity vulnerability in Entra ID that was exploited in attacks, tracked as CVE-2026-69836. Discovered by Microsoft engineer Robert Fitzpatrick, the flaw allowed unauthenticated actors to achieve code execution via deserialization of untrusted data. Microsoft states the issue is fully mitigated and no user action is required, and said exploit code is not publicly available. The company provided limited additional details on the incidents.
read more →

Microsoft August Windows Update Causing Game Crashes

🎮 Microsoft is investigating reports that August 2026 updates may prevent some games from launching or cause crashes on affected Windows 11 systems. Affected users report freezes, unexpected closures, EXCEPTION_ACCESS_VIOLATION errors, and random restarts after installing KB5121003. The company confirmed it is probing the issue and asked impacted gamers to submit Feedback Hub reports while it works to determine if Microsoft is the cause.
read more →

Microsoft named a Leader in Frost Radar 2026

🔒 Microsoft has been named a visionary leader in Frost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026. The report highlights a market shift from isolated scanning to a unified runtime security model that connects code, cloud resources, identities, and SOC workflows. Frost & Sullivan cites Microsoft Defender for Cloud’s scale, deep runtime telemetry, and integration with Defender XDR, Sentinel, GitHub, and Copilot as key strengths. This positioning reflects Microsoft’s estimated >22% share of the global CWPP market and emphasizes runtime depth, container and Kubernetes security, and AI workload protection.
read more →

Microsoft fixes Windows Defender crash bug

🛡️ Microsoft resolved a bug causing Windows Defender to crash with 0xc0000005 access violation errors after a recent signature update. Affected users on Windows 10 and Windows 11 reported scan failures and service stoppages that in some cases led to system reinstalls. Microsoft says the issue is fixed in Microsoft Defender Antivirus signature update version 1.457.236.0 or later and recommends applying updates or enabling automatic updates. Users should check Windows Update and their security intelligence version to ensure the fix is applied.
read more →