Topic: microsoft patch

  • Urgent: Actively Exploited WSUS Bug Now on CISA KEV List

    Urgent: Actively Exploited WSUS Bug Now on CISA KEV List

    A critical security flaw (CVE-2025-59287) in Windows Server Update Services (WSUS) allows unauthenticated attackers to execute remote code with system privileges by exploiting the GetCookie() endpoint. The vulnerability is under active exploitation, prompting urgent patching by Microsoft and incl...

    Read More »
  • Microsoft Patches Bloated Windows 11 Storage Folder

    Microsoft Patches Bloated Windows 11 Storage Folder

    Microsoft released a fix in the June 2026 optional update (KB5095093) for a Windows 11 bug that caused the CapabilityAccessManager.db-wal file to balloon in size, consuming gigabytes of storage. The file, which manages app permissions, has been reported to grow to massive sizes (e.g., 500GB, 12GB...

    Read More »
  • Entra ID Admin Role Could Let Hackers Hijack Service Principals

    Entra ID Admin Role Could Let Hackers Hijack Service Principals

    Microsoft patched a critical privilege escalation flaw in Entra ID's Agent Identity Platform in April 2026, where the Agent ID Administrator role could be exploited to hijack arbitrary service principals across a tenant. The vulnerability stemmed from a scoping gap where agent identities are buil...

    Read More »
  • Windows Task Host Bug Actively Exploited, CISA Warns

    Windows Task Host Bug Actively Exploited, CISA Warns

    A critical privilege escalation vulnerability (CVE-2025-60710) in the Windows Task Host process is under active attack, allowing attackers to gain full SYSTEM control of affected systems. CISA has mandated U.S. federal agencies to patch the flaw within two weeks and strongly urges all organizatio...

    Read More »
  • Urgent Windows SMB Flaw Actively Exploited, CISA Warns

    Urgent Windows SMB Flaw Actively Exploited, CISA Warns

    A critical Windows SMB vulnerability (CVE-2025-33073) is being actively exploited, allowing attackers to gain full SYSTEM-level control over unpatched systems. The flaw affects a wide range of Microsoft operating systems, including Windows Server, Windows 10, and Windows 11 up to version 24H2, an...

    Read More »
  • Urgent: Patch Windows SMB Flaw Being Actively Exploited

    Urgent: Patch Windows SMB Flaw Being Actively Exploited

    A critical Windows SMB Client vulnerability (CVE-2025-33073) is being actively exploited, allowing attackers to gain SYSTEM-level privileges through a malicious script that compromises SMB connections. Microsoft patched the flaw in June 2025, and CISA has added it to its Known Exploited Vulnerabi...

    Read More »
  • MiniPlasma Windows 0-Day Elevates Privileges to SYSTEM on Patched Systems

    MiniPlasma Windows 0-Day Elevates Privileges to SYSTEM on Patched Systems

    A security researcher has released a proof-of-concept exploit for the "MiniPlasma" zero-day vulnerability in the Windows Cloud Files Mini Filter Driver, which can elevate privileges to SYSTEM on fully patched systems. Originally reported to Microsoft in September 2020 and thought patched in Decem...

    Read More »