Microsoft has published an advisory for CVE-2025-54105 — a local elevation-of-privilege vulnerability in the Microsoft Brokering File System (BFS) caused by a concurrency bug (race condition) that can be exploited by an authenticated local user to gain elevated rights on the host. Background
The...
Phison has publicly acknowledged and replicated a key finding first raised by the PCDIY community: a wave of disappearing and allegedly “bricked” NVMe SSDs linked in timing to Windows 11’s August cumulative update (KB5063878) appears to have been driven, in at least some test cases, by...
Pac‑Man’s 45th anniversary is getting a proper party: Bandai Namco’s year‑long “Make imPACt” campaign has been joined this weekend by an Xbox Free Play Days spotlight that lets Game Pass members jump into three Pac‑Man titles for free while limited‑time discounts make ownership tempting...
arcade
bandai namco
battle royale
chomp champs
cross platform play
crossplay
digital marketing
game pass
impact
modern remake
nostalgia
pac-man
pac-man 45th anniversary
pac-man mega tunnel battle
pac-man museum+
retro gaming
smart delivery
xbox free play days
xbox store
A major global outage affecting Microsoft’s services has sent shockwaves through industries spanning from aviation to healthcare. The incident, which disrupted access to Microsoft 365 apps and services, caused widespread delays and cancellations affecting airlines, border crossings, banks...
Hello.., I have seen many websites ask for accepting cookies. What is the purpose of the acceptance of the cookies what will be the impact if don't accept the cookies?
Thanks in advance.
Original release date: January 20, 2020<br/><h3>Summary</h3><p>On January 19, 2020, Citrix released firmware updates for Citrix Application Delivery Controller (ADC) and Citrix Gateway versions 11.1 and 12.0 to address CVE-2019-19781. Citrix expects to release updates for other vulnerable...
This week, we released the first Beta preview of the next version of Microsoft Edge. Alongside this, Microsoft is excited to announce the launch of the Microsoft Edge Insider Bounty Program. We welcome researchers to seek out and disclose any high impact vulnerabilities they may find in the next...
Original release date: May 21, 2018
Systems Affected
CPU hardware implementations
Overview
On May 21, 2018, new variants—known as 3A and 4—of the side-channel central processing unit (CPU) hardware vulnerability were Link Removed. These variants can allow an attacker to obtain access to...
If I remember correctly, XP's EOL had a HUGE reaction because of all the people's fond memories of it. So Win7's will be that, but bigger in my personal opinion.
anniversary
community
discussion
end of life
eol
feedback
history
impact
legacy
memories
operating system
reaction
sentiment
support
technology
upgrade
user experience
windows 7
windows xp
Security researchers play an essential role in Microsoft’s security strategy and are key to community-based defense. To show our appreciation for their hard work and partnership, each year at BlackHat North America, the Microsoft Security Response Center highlights contributions of these...
black hat
community
contributions
cybersecurity
defensive
impact
innovation
microsoft
msrc
participation
partnership
ranking
report
research
security
tech news
threats
top 100
vulnerabilities
Original release date: December 01, 2016 | Last revised: December 14, 2016
Systems Affected
Microsoft Windows
Overview
“Avalanche” refers to a large global network hosting infrastructure used by cyber criminals to conduct phishing and malware distribution campaigns and money mule schemes...
antivirus
avalanche
botnet
cybercrime
data theft
denial of service
dhs
fast flux
fbi
financial institutions
impact
malware
os upgrade
password change
personal data
phishing
ransomware
remediation
security
windows
The Link Removed has been in public preview since November 2016. This month marked our first release when security update information was published entirely in the new format. Over the last few months, customers and partners have provided a lot of feedback on the direction and implementation of...
advisories
api
bugs
cve
dashboard
data population
excel
feedback
identifier
impact
it professionals
machine-readable
msrc
powershell
public preview
security
severity rating
technet
transparency
update guide
Security is a critical component of our products at Microsoft. A strong emphasis on security is a persistent factor throughout our entire development process. Microsoft is committed to designing and developing secure software. Testing is performed both internally and by working closely with the...
asia
authentication
bounty program
bug bounty
china
cloud computing
cross-site scripting
impact
india
microsoft
microsoft azure
mitigation
nullcon
privilege escalation
research community
security
security software
vulnerabilities
windows 10
workshops
Massive Amazon cloud service outage disrupts sites
Affected server: Amazon's S3 service on the east coast, US-EAST-1. Operations were fully recovered by 4:49 pm ET, Amazon said.
AN FRANCISCO — Amazon didn't, quite, break the Internet Tuesday but a more than four-hour problem at one of the main...
Severity Rating: Critical
Revision Note: V1.0 (October 11, 2016): Bulletin published.
Summary: This security update resolves vulnerabilities in Microsoft Windows, Microsoft Office, Skype for Business, Silverlight and Microsoft Lync. The most serious of these vulnerabilities could allow remote...
Severity Rating: Critical
Revision Note: V1.0 (January 12, 2016): Bulletin published.
Summary: This security update resolves vulnerabilities in Microsoft Edge. The vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Microsoft Edge. An attacker who...
Original release date: December 03, 2015
Systems Affected
Microsoft Windows
Overview
Dorkbot is a botnet used to steal online payment, participate in distributed denial-of-service (DDoS) attacks, and deliver other types of malware to victims’ computers. According to Microsoft, the family of...
Original release date: October 13, 2015
Systems Affected
Microsoft Windows
Overview
Dridex, a peer-to-peer (P2P) bank credential-stealing malware, uses a decentralized network infrastructure of compromised personal computers and web servers to execute command-and-control (C2). The United...
The Skype Translator Preview was released December 2014 and has now been added to the Windows Store.. No need to sign up just download! :)
Ref:
http://blogs.skype.com/2015/05/12/skype-translator-preview-access-just-got-easier/
accessibility
application
communication
connection
download
feedback
globalization
impact
language
microsoft store
multilingual support
nonprofit
preview
services
skype
technology
translator
user experience
windows 10
windows 8.1