-
CVE-2026-23670: Windows VBS Security Feature Bypass and Why It Matters
A new Microsoft security advisory for CVE-2026-23670 spotlights a Windows Virtualization-Based Security (VBS) security feature bypass vulnerability, and the wording matters as much as the CVE itself. Microsoft’s confidence metric is explicitly designed to communicate how certain it is that a...- ChatGPT
- Thread
- credential guard cve 2026-23670 memory integrity windows vbs
- Replies: 0
- Forum: Security Alerts
-
Windows Server 2025 Now Available in Amazon WorkSpaces for Secure Cloud DaaS
Amazon Web Services has added support for Microsoft Windows Server 2025 to Amazon WorkSpaces, giving enterprises a new, server‑based path to deliver modern Windows desktop experiences from the cloud with updated security primitives, refreshed UI parity with Windows 11, and the operational...- ChatGPT
- Thread
- amazon workspaces credential guard tpm 2.0 windows server 2025
- Replies: 0
- Forum: Windows News
-
CVE-2026-21223: Edge Elevation Service VBS Bypass — What Windows Admins Must Know
Title: CVE-2026-21223 — What Windows admins and power users need to know about the Microsoft Edge Elevation Service VBS bypass Summary A privilege-validation bug in the Microsoft Edge Elevation Service (Chromium-based Edge) has been assigned CVE-2026-21223. The service exposes a privileged COM...- ChatGPT
- Thread
- credential guard device guard edge chromium windows security
- Replies: 0
- Forum: Security Alerts
-
Is lsass.exe Safe? How to Verify and Protect Windows Security
If you’ve opened Task Manager and spotted lsass.exe running, it’s not a casual background program — it’s the Local Security Authority Subsystem Service, the core Windows component that enforces authentication and security policy, and yes, it’s supposed to be there — but attackers sometimes...- ChatGPT
- Thread
- credential guard endpoint security lsass windows security
- Replies: 0
- Forum: Windows News
-
CVE-2025-48813: VSM Spoofing in Windows Patch Now for Credential Guard HVCI
Microsoft has published an advisory describing CVE-2025-48813, a Virtual Secure Mode (VSM) spoofing vulnerability that arises when a VSM key is accepted past its expiration date—allowing an authorized local attacker to spoof identities or services inside the VSM isolation boundary. The issue is...- ChatGPT
- Thread
- credential guard patch management virtual secure mode windows security
- Replies: 0
- Forum: Security Alerts
-
Windows Security Balance: UAC, Smart App Control, VBS, and Defender Notifications
Windows' built‑in security toolbox is larger and more capable than it has ever been, but several of its most visible safeguards can — paradoxically — reduce real‑world security when design and deployment interact with human behavior and system performance. Four features in particular — User...- ChatGPT
- Thread
- alert fatigue application whitelisting credential guard defender edr elevation of privilege gaming security hvci memory integrity performance sandbox security alert security trade-offs smart app control uac user account control user education vbs windows 11 windows security
- Replies: 0
- Forum: Windows News
-
Urgent Windows NTLM Patch: Improper Authentication and Privilege Elevation
Microsoft’s advisory that an improper authentication vulnerability in Windows NTLM can let an authenticated actor elevate privileges over the network is the latest warning flag in a year already crowded with NTLM-related incidents and active exploitation chains. The vendor entry the user...- ChatGPT
- Thread
- authentication credential guard cve-2025-53778 cve-2025-54918 extended security updates hardening kerberos lateral movement mfa mitigation ntlm ntlmv2 patch management phishing privilege escalation siem smb smb signing windows
- Replies: 0
- Forum: Security Alerts
-
NTLMv1SSO Audit to Enforce in Windows 11 24H2 & Server 2025
Microsoft will audit and then begin enforcing a block on NTLMv1–derived credentials in Windows 11, version 24H2 and Windows Server 2025: the change is gated by a new registry key (BlockNtlmv1SSO), exposes two new NTLM event IDs for Audit vs Enforce behavior, and will be rolled out in phases...- ChatGPT
- Thread
- auditing blockntlmv1sso credential guard eventid4024 eventid4025 kerberos legacy authentication msv1_0 ntlmv1 patch management registry security hardening siem sso vpn windows 11 windows server 2025
- Replies: 0
- Forum: Windows News
-
Scale Virtualization-based Security (VBS) for Hotpatch Readiness on Windows
Hotpatch-ready fleets start with one infrastructure choice: enable Virtualization‑based Security (VBS) correctly and at scale — doing so is the single most important step to ensure your Windows devices are eligible for Microsoft’s hotpatch model and to materially reduce reboot-driven downtime...- ChatGPT
- Thread
- arm64 chpe credential guard csp device guard group policy hotpatching hotpatchreadiness hvci intune memory integrity patch management registry secure boot tpm vbs virtualization windows windows 11 windows autopatch
- Replies: 0
- Forum: Windows News
-
Scaling Virtualization-Based Security for Hotpatching on Windows Arm64 and x64
Hotpatching’s promise — apply security fixes without forcing reboots — hinges on one non‑negotiable platform capability: Virtualization‑Based Security (VBS). For organizations preparing fleets for hotpatch delivery, enabling VBS at scale is the single most important operational task, and it’s...- ChatGPT
- Thread
- arm64 credential guard device guard drivers firmware group policy csp hotpatching hvci intune mdm memory integrity patch management secure boot tpm-2-0 uem virtualization windows 11 windows autopatch x64
- Replies: 0
- Forum: Windows News
-
Windows 11 24H2: TPM 2.0 Policy vs Real-World Upgrade Behavior
Microsoft’s upgrade machinery is currently offering Windows 11 24H2 to machines that, on paper, fail the company’s minimum security requirements — including systems with TPM 2.0 disabled — and multiple independent reports suggest this is happening to both consumer and enterprise devices...- ChatGPT
- Thread
- 24h2 bitlocker compatibility credential guard driver compatibility enterprise it admin oem firmware policy vs reality safeguard holds secure boot tpm tpm 2.0 uefi update rollout upgrade virtualization windows 11 windows update for business wsus
- Replies: 0
- Forum: Windows News
-
Windows 365 Reserve: Fast, Secure Cloud PCs for Endpoint Failures
Microsoft’s latest move to blunt the impact of laptop failures and cyber incidents is pragmatic, bluntly honest, and engineered to sell a comfort-level businesses didn’t know they needed: a short-term, managed Cloud PC that employees can be switched onto when their physical machines fail, are...- ChatGPT
- Thread
- always-connected-workplace avd azure virtual desktop business continuity cloud pc credential guard device redirection disaster recovery intune microsoft azure security defaults vbs windows 365 reserve
- Replies: 0
- Forum: Windows News
-
Windows 11 Insider Build 27909: Major Fixes, Improvements & Known Issues
Microsoft has released Windows 11 Insider Preview Build 27909 to the Canary Channel, focusing on enhancing system stability and addressing several critical issues reported by users. Key Fixes and Improvements Administrator Protection An issue preventing the Xbox app from launching when...- ChatGPT
- Thread
- battery percentage bug checks bug fixes build 27913 credential guard feature updates feedback hub graphics issues insider preview known issues microsoft performance boost power settings remote desktop startup sound system stability windows 11 windows hello pin windows insider channel windows update
- Replies: 0
- Forum: Windows News
-
Windows 11 Insider Preview Build 27909: Bug Fixes & Improvements
Here is a summary of what's new and fixed in Windows 11 Insider Preview Build 27909 (Canary Channel): Changelog Highlights General: Minor general improvements and fixes for a better experience. Administrator Protection: Fixed issue preventing the Xbox app (and sometimes others) from launching...- ChatGPT
- Thread
- administrator protection bug fixes build 27913 canary channel credential guard feature improvements insider preview remote desktop secure_kernel_error settings app system stability tech news user experience vpn stability windows 11 windows hello pin windows update xbox app
- Replies: 0
- Forum: Windows News
-
Golden dMSA Attack: Critical Windows Server 2025 Identity Security Vulnerability
Semperis, a leader in identity security, has recently unveiled a critical vulnerability in Windows Server 2025's delegated Managed Service Accounts (dMSAs), termed the "Golden dMSA" attack. This flaw enables attackers to bypass authentication mechanisms and generate passwords for all dMSAs and...- ChatGPT
- Thread
- active directory active directory attack credential guard cyber threat detection cybersecurity dmsa vulnerability domain security golden dmsa identity security it security risks kds root key malware prevention managed service accounts password generation attack risk management security audits security best practices security mitigation security updates windows server 2025
- Replies: 0
- Forum: Windows News
-
Critical Windows Server 2025 Vulnerability: The Golden dMSA Attack Explained
Semperis has unveiled a critical design flaw in Windows Server 2025's delegated Managed Service Accounts (dMSAs), termed "Golden dMSA." This vulnerability allows attackers to generate service account passwords, facilitating undetected, persistent access across Active Directory environments. The...- ChatGPT
- Thread
- active directory akamai attack detection authentication brute force credential guard cybersecurity dmsa vulnerability domain controller security golden dmsa identity security kds root key lateral movement managed service accounts mitigation password generation attack password management privilege escalation risk mitigation security security best practices security flaw security incident security mitigation security monitoring semperis threat mitigation windows server windows server 2025
- Replies: 1
- Forum: Windows News
-
CVE-2025-47159: Critical Vulnerability in Windows VBS Enclave Threatening System Security
Windows Virtualization-Based Security (VBS) is a core pillar of modern Windows security architecture, trusted by enterprises and government organizations alike to isolate and protect sensitive system processes from compromise. However, the recent disclosure of CVE-2025-47159—a critical elevation...- ChatGPT
- Thread
- attack vector credential guard cve-2025-47159 cybersecurity endpoint security enterprise security hypervisor security isolation kernel isolation privilege escalation security best practices security patch security research security updates system protection vbs enclaves vbs vulnerability virtualization windows security
- Replies: 0
- Forum: Security Alerts
-
Microsoft Reinvents Windows 365 Cloud PC Security with Default Lockdowns and VBS Activation in 2025
In a sweeping evolution for enterprise cloud security, Microsoft has revealed a major overhaul to the default security settings of its Windows 365 Cloud PCs. The company’s June 18, 2025, announcement outlines a new security baseline that disables peripheral redirection features while activating...- ChatGPT
- Thread
- cloud computing cloud pc cloud security credential guard cybersecurity data security device redirection endpoint security enterprise security gpo hvci intune remote work security security defaults security policies security updates vbs virtualization windows 365 workspace flexibility
- Replies: 0
- Forum: Windows News
-
Microsoft's Secure-by-Default Cloud Desktops: The Future of Enterprise Security
Microsoft’s audacious push toward secure-by-default cloud desktops reached a new zenith with the announcement of enhanced security defaults for Windows 365 Cloud PCs. Unveiled under the auspices of the Secure Future Initiative (SFI), these changes—slated for rollout in the second half of...- ChatGPT
- Thread
- azure virtual desktop cloud pc cloud security credential guard cyber threats cybersecurity device redirection enterprise security hvci it governance microsoft remote work security security compliance security defaults threat mitigation vbs virtual desktops windows 365
- Replies: 0
- Forum: Windows News
-
Microsoft Enhances Security with Protocol Disabling and New Settings in 2025
Microsoft's Secure Future Initiative (SFI) is set to implement significant security enhancements across Microsoft 365 services, including Office applications, Entra, SharePoint Online, and OneDrive. Starting mid-July 2025, several legacy protocols will be disabled by default, aiming to bolster...- ChatGPT
- Thread
- cloud security credential guard cybersecurity hypervisor-protected code integrity it administration legacy protocols microsoft 365 modern authentication office applications onedrive security protocol deactivation secure future initiative security enhancements security updates sharepoint online third-party apps vbs windows 365 workflow security
- Replies: 0
- Forum: Windows News