Microsoft Fixed Eighteen Cloud Flaws Before Customers Could Touch Them
The fixes were real, but there was no update button for customers. The affected layer sat inside Microsoft's cloud control plane.
The fixes were real, but there was no update button for customers. The affected layer sat inside Microsoft's cloud control plane.

A million-plus email campaign combined fake executive approval, a forged ServiceNow invoice and an invented forwarded conversation to seek nearly $50,000 transfers.

Microsoft says September’s Windows security updates can destabilise Remote Desktop Services, break sign-ins and leave virtual machines reachable only through their management console.

Microsoft has confirmed exploitation of two Windows privilege-escalation vulnerabilities. One can break out of an AppContainer on older Windows systems; the other affects the Update Stack on current Windows releases. Together, they turn partial access into a race for SYSTEM.

Microsoft’s September security release is not a simple highest-score-first exercise. Two Windows flaws are already being exploited, several network services expose unauthenticated remote-code paths, Outlook can be attacked without a click, and even hotpatch-enrolled systems face a restart. Here is the order businesses should use.

CISA has added a seven-year-old Microsoft SQL Server vulnerability to its exploited list, turning forgotten database instances into an urgent incident-response problem.

Microsoft says a China-focused campaign is rebuilding malicious installers between downloads, making familiar names and file hashes unreliable clues.

KB5120998 may reset cursor styling, wallpaper and text rendering on some Windows 11 PCs. This Dutch and English guide explains when and how to remove the optional update safely.

Microsoft labels KB5120998 a non-security preview, but it changes administrator protection, AI process isolation, WMIC availability, post-quantum TLS and enterprise deployment behaviour.

BTR Reforged shows how Microsoft Defender’s own signed boot-time cleanup driver can be redirected to remove endpoint protection after administrative compromise.