Microsoft has addressed a local privilege escalation vulnerability in WalletService on Windows. This flaw could allow a standard user to gain full control over an affected machine, operating as text{NT AUTHORITYSYSTEM}.
The vulnerability specifically affects WalletService, a LocalSystem component used...
Windows 11 and Windows Server 2025 high-severity vulnerability in Microsoft’s Brokering File System (BFS), identified as CVE-2026-50458, which allows for local privilege escalation on impacted systems.
The flaw is located in bfs.sys. This minifilter driver manages file, pipe, and registry...
Public proof-of-concept (PoC) exploit code was released for CVE-2026-42980, a local privilege escalation vulnerability in the Windows NT OS Kernel. This vulnerability occurs due to an integer underflow in kernel-mode code.
CVE-2026-42980 is an elevation-of-privilege flaw in the Windows NT...
Microsoft will stop delivering OneDrive sync app updates to systems running Windows 10 version 21H2 and earlier on August 15, 2026, creating a new support concern for organizations still operating legacy Windows endpoints.
The change was announced in Microsoft 365...
LG monitor software may install advertising-related components on Windows systems without clearly informing users through its companion application, which manages monitor settings, display profiles, and other device features.
The software may silently install adware-like components in the background as part...
A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution.
LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for loading and unloading user...
Microsoft has confirmed a known issue in Teams on macOS that causes screen sharing to fail, freeze, or show a blank black screen during meetings.
The bug affects users running macOS versions older than macOS Tahoe 26.4, and Microsoft has...
Microsoft has formally expanded its use of artificial intelligence in vulnerability discovery, deploying a proprietary multi-model agentic scanning system across the Windows codebase to identify and patch security flaws before adversaries can exploit them a move that is already...
A recent user report has raised concerns about Windows Update silently installing third-party applications, after an LG monitor-related app allegedly appeared on systems and began displaying McAfee advertisements without user consent.
The issue surfaced in a discussion on Reddit’s r/pcmasterrace...
Microsoft has introduced Microsoft Execution Containers (MXC), a new security capability designed to protect AI agent workflows on Windows, marking a significant step toward making Windows more trustworthy for autonomous systems.
AI agents are rapidly evolving beyond simple assistants into...