Cybersecurity News

Filters
Tag
Reset

Filtered by tag: microsoft × Clear

Fake Microsoft Security Scan Tells You to Remove Antivirus—Then Scammers Ask for Remote Access

Matched: health

Scammers are running fake Microsoft-branded security scan websites that display fabricated system warnings and artificially low security scores to frighten visitors. The sites instruct users to uninstall their antivirus software, then collect personal and banking details through a form before redirecting victims to await a callback. During that call, operators request remote access to complete a fake refund, giving criminals direct control of the device. Malwarebytes identified 11 related sites sharing one server.

Microsoft August 2026 Update Breaks When Generating PDF/XPS Content

Matched: health

Microsoft's August 2026 .NET Framework cumulative updates are causing printing failures and PDF/XPS generation errors in WPF applications. The bug triggers a System.IO.FileFormatException when using ClearType fonts like Calibri, Cambria, Constantia, and Corbel, affecting Windows 10, 11, and Server 2012–2025. The issue stems from stricter font validation in the TrueType subsetter introduced alongside fixes for six security vulnerabilities. A temporary workaround exists but disables the security protections the update introduced.

Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

A threat actor dubbed Doubloon Dredger used malicious PDFs to redirect victims to fake Microsoft login pages hosted via Notion. The campaign harvested Microsoft authentication tokens, exploiting Notion's legitimate infrastructure to evade detection. The abuse of trusted platforms helped the attackers bypass security filters while capturing credentials from targeted users.

Microsoft August 2026 Windows Updates Trigger Issues on Devices Using RGB Lighting Features

Matched: health

Microsoft is investigating a Windows 11 issue where August 2026 security update KB5121003 causes games to freeze, crash, or trigger PC restarts on devices with RGB lighting hardware. The problem involves the inpoutx64 driver used by RGB peripherals and components. Affected games include ARC Raiders, MARVEL Tōkon: Fighting Souls, and THE FINALS. As a workaround, Microsoft advises disabling the driver via Registry Editor. Windows Server is unaffected.

Experts manage to hack Microsoft Copilot by continually asking it questions about itself

Researchers discovered they could manipulate Microsoft Copilot by persistently questioning it about its own nature and system instructions. Through repeated probing, the AI revealed internal configurations it was meant to keep hidden. The findings highlight concerns that AI assistants can be socially engineered into bypassing safeguards, raising questions about whether current security measures are sufficient for enterprise deployment.

Microsoft smothers malware by tracking behavior instead of blocking domains

Microsoft has shifted its malware defense strategy from blocking malicious domains to tracking behavioral patterns. Because attackers can rapidly automate new domains to replace blocked ones, domain-blocking proves ineffective. By monitoring how malware behaves rather than where it connects, Microsoft aims to identify and neutralize threats more reliably, staying ahead of attackers who exploit the limitations of domain-based defenses.

'This one just needs a script': Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction

Researchers discovered a Windows vulnerability allowing attackers to disable antivirus software with minimal user interaction. Dubbed a near-universal "kill switch," the flaw could neutralize security tools across Windows systems. Microsoft addressed the issue in its April 2025 Patch Tuesday update. Additional fixes and mitigations are also available for users unable to apply the cumulative update immediately.

Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users

A researcher known as Nightmare Eclipse has disclosed a new zero-day vulnerability in Windows, the tenth such release from this individual. The flaw was revealed shortly after Microsoft's Patch Tuesday update cycle, a pattern the researcher has repeated previously. The timing leaves Windows users potentially exposed before Microsoft can issue a fix.

A Record-Breaking Patch Tuesday for June 2026

Microsoft's June 2026 Patch Tuesday addressed nearly 200 security vulnerabilities across Windows and related software, the largest monthly update in the company's history. Around 30 of the flaws were rated critical, and exploit code for at least three vulnerabilities is already publicly available, raising the urgency for users and administrators to apply the patches promptly.