Wednesday, September 16, 2026
Follow on LinkedIn

Windows

WalletService Privilege Escalation Flaw Allows Attackers Full Control of Windows Systems

Microsoft has addressed a local privilege escalation vulnerability in WalletService on Windows. This flaw could allow a standard user to gain full control over an affected machine, operating as text{NT AUTHORITYSYSTEM}. The vulnerability specifically affects WalletService, a LocalSystem component used...

Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability

Windows 11 and Windows Server 2025 high-severity vulnerability in Microsoft’s Brokering File System (BFS), identified as CVE-2026-50458, which allows for local privilege escalation on impacted systems. The flaw is located in bfs.sys. This minifilter driver manages file, pipe, and registry...

Public PoC Released for Windows NT OS Kernel Privilege Escalation Vulnerability

Public proof-of-concept (PoC) exploit code was released for CVE-2026-42980, a local privilege escalation vulnerability in the Windows NT OS Kernel. This vulnerability occurs due to an integer underflow in kernel-mode code. CVE-2026-42980 is an elevation-of-privilege flaw in the Windows NT...

Microsoft to End OneDrive Sync App Updates for Windows 10

Microsoft will stop delivering OneDrive sync app updates to systems running Windows 10 version 21H2 and earlier on August 15, 2026, creating a new support concern for organizations still operating legacy Windows endpoints. The change was announced in Microsoft 365...

Researchers Claim LG Monitors are Silently Installing Adware on Windows Using App

LG monitor software may install advertising-related components on Windows systems without clearly informing users through its companion application, which manages monitor settings, display profiles, and other device features. The software may silently install adware-like components in the background as part...

New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access

A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution. LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for loading and unloading user...

Microsoft Teams on macOS Screen Sharing Bug Causing Blank Screens

Microsoft has confirmed a known issue in Teams on macOS that causes screen sharing to fail, freeze, or show a blank black screen during meetings. The bug affects users running macOS versions older than macOS Tahoe 26.4, and Microsoft has...

Microsoft Adopts AI-Powered Scanning to Find Vulnerabilities Before Attackers

Microsoft has formally expanded its use of artificial intelligence in vulnerability discovery, deploying a proprietary multi-model agentic scanning system across the Windows codebase to identify and patch security flaws before adversaries can exploit them a move that is already...

Windows Update Silently Installs LG Monitor App That Pushes McAfee Ads

A recent user report has raised concerns about Windows Update silently installing third-party applications, after an LG monitor-related app allegedly appeared on systems and began displaying McAfee advertisements without user consent. The issue surfaced in a discussion on Reddit’s r/pcmasterrace...

Windows Adds Microsoft Execution Containers to Secure AI Agent Workflows

Microsoft has introduced Microsoft Execution Containers (MXC), a new security capability designed to protect AI agent workflows on Windows, marking a significant step toward making Windows more trustworthy for autonomous systems. AI agents are rapidly evolving beyond simple assistants into...

Latest News

Latest News