Rabia Noureen profile picture

Follow Rabia

Rabia Noureen

News Editor

Rabia has a master's degree in Software Engineering and she has years of experience writing professionally about Microsoft products and other technologies. Rabia has also written for OnMSFT.com as well as Windows Report. She is always up to date on the latest trends in the IT Industry and has done extensive research in the data science industry.

LATEST

Security

Tycoon 2FA Returns With OAuth-Based Phishing to Bypass Microsoft 365 Security

Cybercriminals are once again refining their tactics, as the Tycoon 2FA phishing kit evolves to target Microsoft 365 accounts. Instead of stealing passwords, attackers now manipulate users into granting access through device‑code techniques, which makes the attack harder to detect and block. Earlier this month, researchers reported that the Tycoon 2FA phishing kit had returned to full…

View Article
Cloud Computing

Microsoft Warns Exchange Server Flaw Lets Attackers Execute Code via OWA Emails

Microsoft has disclosed a critical vulnerability in on-premises Exchange Server that allows attackers to execute malicious code through specially crafted emails opened in Outlook Web Access. The company is urging administrators to apply emergency mitigations immediately while it works on a permanent security update for supported commercial customers. This security vulnerability (tracked as CVE‑2026‑42897) affects…

View Article
Windows-11-notebook-tablet

Microsoft Fixes Windows Autopatch Bug Installing Restricted Drivers on Windows 11

Microsoft has fixed a Windows Autopatch bug that was unintentionally deploying driver updates to certain managed Windows devices without proper approval controls. The issue impacted a limited number of systems running Windows 11 versions 25H2, 24H2, and 23H2, potentially causing unexpected restarts and stability problems. Windows Autopatch is a cloud-based service that automatically manages and…

View Article
Security

Internet‑Facing Systems Are Increasing Security Risk Faster Than Teams Can Fix It

Millions of organizations are unknowingly leaving doors open to cyberattacks by exposing sensitive systems to the Internet. This report finds that overlooked access points are driving real-world breaches and making security harder to control. According to Intruder’s 2026 Attack Surface Management Index, organizations face increasing risk because more systems and services are exposed to the…

View Article
Windows 11 2022 Update

Windows Update Gets Cloud‑Based Driver Recovery to Fix Faulty Updates

Microsoft is tackling one of Windows’ most frustrating issues, broken driver updates, with a new cloud‑powered solution that fixes problems before users even notice. This new Cloud‑Initiated Driver Recovery feature can automatically roll back faulty drivers, turning what used to be a manual headache into a seamless, behind‑the‑scenes repair. Microsoft mentioned that faulty or low‑quality…

View Article
Windows update hero image

Microsoft’s May 2026 Patch Tuesday Updates Fix 30 Critical Flaws

Microsoft has released the May 2026 Patch Tuesday updates for Windows 11. This month, Microsoft has fixed a total of 138 security flaws in Windows, Office, Microsoft Edge, Azure, .NET and Visual Studio, Copilot Chat, GitHub Copilot, and Microsoft 365 Copilot. On the quality and experience updates front, the KB5089548 update (26H1) brings enhancements to…

View Article
Security hero image

Dirty Frag Linux Flaw Allows Local Privilege Escalation to Root Access

A newly discovered Linux flaw dubbed “Dirty Frag” is raising alarms among security experts as it enables attackers to escalate minor breaches into full system takeovers quickly. This vulnerability highlights how even limited access can quickly spiral into complete control of critical systems. Last week, security researcher Hyunwoo Kim disclosed the vulnerability (dubbed “Dirty Frag”)…

View Article
Cloud Computing

Microsoft to Retire Exchange ActiveSync Certificate-Based Authentication

Microsoft is phasing out an old authentication method for mobile email, which signals another major step toward stricter, modern security in Exchange Online. Organizations relying on certificate-based access via ActiveSync must now prepare for a transition to Entra ID–based authentication ahead of the 2026 deadline. Direct Exchange ActiveSync certificate-based authentication is being phased out because…

View Article
Datacenter networking servers

Azure Arc-Enabled Kubernetes Adds Cert-Manager for TLS Certificate Automation

Microsoft has announced the public preview of cert-manager support for Azure Arc-enabled Kubernetes. This new feature simplifies security by streamlining certificate issuance, renewal, and trust management across distributed Kubernetes clusters, which reduces manual effort and improves reliability. According to Microsoft, managing TLS certificates in Kubernetes (especially across hybrid, multicloud, and edge environments) has become increasingly…

View Article
microsoft security hero approved image

Poor Employee Awareness and Skills Gap Drive Cybersecurity Breaches

A major driver of cybersecurity breaches continues to be insufficient employee training and awareness, a problem that has persisted across the industry for years. New findings from Fortinet highlight that despite advancing technologies, organizations still struggle to address this ongoing human-factor vulnerability. According to Fortinet’s 2026 Global Cybersecurity Skills Gap Report, more than half of…

View Article
Datacenter networking servers

Microsoft Azure Local Now Supports Thousands of Servers in Sovereign Deployments

Microsoft’s Azure Local can now support deployments of thousands of servers within a single sovereign environment. This allows organizations to run very large, complex workloads locally without redesigning their infrastructure. According to Microsoft, governments and regulated industries are increasingly prioritizing strict control over where their data is stored, how operations are managed, and how compliance…

View Article
Security – 4

Attackers Extract Microsoft Edge Passwords From Memory Using Legitimate Remote Access Tools

An attacker who has administrative-level access can retrieve Microsoft Edge users’ saved passwords from memory, even when those credentials are not actively being used. This is possible because the browser temporarily keeps them in an unencrypted form in its process memory as part of how it is designed. According to a new report from Securonix,…

View Article
Go to page