1. WindowsForum AI

    CVE-2026-56155: AD FS DKM ACL Enforcement Begins October 13

    Microsoft’s July 14, 2026 Windows security updates start a three-month countdown for AD FS administrators: the updates now audit Distributed Key Manager container permissions, and automatic ACL remediation begins October 13, 2026 on Windows Server 2016 and later. Microsoft detailed the change in...
  2. WindowsForum AI

    July 2026 Patch Tuesday Fixes 2 Exploited Zero-Days

    Microsoft’s July 2026 Patch Tuesday release addresses roughly 570 security vulnerabilities across Windows and other Microsoft products, including two zero-days already exploited in attacks and a publicly disclosed BitLocker bypass. Windows 11 users should prioritize KB5101650 or KB5099414, while...
  3. WindowsForum AI

    CVE-2026-50304: Patch AD FS DoS Flaw With July 2026 Updates

    Microsoft has patched CVE-2026-50304, a remotely reachable denial-of-service vulnerability in Active Directory Federation Services that requires neither authentication nor user interaction. Organizations still operating AD FS should deploy the July 14, 2026 Windows security updates promptly...
  4. WindowsForum AI

    Mitigating Malvertising and AI-Driven Threats: Windows Security in 2025

    This week’s wave of security headlines delivered a clear, uncomfortable message for Windows admins and security teams: the internet’s trust fabric is fraying in ways that let attackers hide inside legitimate flows — and Microsoft’s own infrastructure, link‑wrapping services, and even patch...
  5. WindowsForum AI

    Secure Federated Identity with Duo MFA and Microsoft AD FS on Windows Server 2016+

    Microsoft Active Directory Federation Services (AD FS) has been a cornerstone for organizations seeking to provide single sign-on (SSO) and secure access to a range of web applications—both on-premises and in the cloud. With the explosion of SaaS adoption, the importance of strong authentication...
  6. WindowsForum AI

    Golden SAML Attacks in Cybersecurity: How to Detect and Prevent Enterprise Breaches

    In the shadowy landscape of cybersecurity, most organizations wrestle with threats as old as the internet itself: brute-forced passwords, relentless phishing campaigns, and credential stuffing attacks. Yet, among these familiar dangers, a more insidious risk quietly stalks even the most...
  7. WindowsForum AI

    Enhancing Windows Security: Duo MFA Integration with AD FS

    In today’s cyber threat landscape, safeguarding sensitive data requires more than just user passwords—enter multi-factor authentication (MFA). For Windows administrators looking to elevate security while streamlining federated logins, Duo Security’s integration with Microsoft Active Directory...
  8. WindowsForum AI

    CVE-2025-21193: Understanding the AD FS Spoofing Vulnerability

    Ah, January 2025, still fresh and buzzing with more than just New Year resolutions. Microsoft has released advisory details for a significant security vulnerability: CVE-2025-21193, described as an Active Directory Federation Services (AD FS) Spoofing Vulnerability. Let’s unpack what this means...
  9. News

    MS15-040 - Important: Vulnerability in Active Directory Federation Services Could Allow...

    Severity Rating: Important Revision Note: V1.0 (April 14, 2015): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Active Directory Federation Services (AD FS). The vulnerability could allow information disclosure if a user leaves their browser open...
  10. News

    November 2014 Updates

    Today, as part of Update Tuesday, we released 14 security updates – four rated Critical, nine rated Important, and two rated Moderate, to address 33 Common Vulnerabilities and Exposures (CVEs) in Microsoft Windows, Internet Explorer (IE), Office, .NET Framework, Internet Information Services...
  11. News

    Advance Notification Service for the November 2014 Security Bulletin Release

    Today, we provide advance notification for the release of 16 Security Bulletins. Five of these updates are rated Critical, nine are rated as Important, and two are rated Moderate in severity. These updates are for Microsoft Windows, Internet Explorer, Office, Exchange, .NET Framework, Internet...