Rabia Noureen profile picture

Follow Rabia

Rabia Noureen

News Editor

Rabia has a master's degree in Software Engineering and she has years of experience writing professionally about Microsoft products and other technologies. Rabia has also written for OnMSFT.com as well as Windows Report. She is always up to date on the latest trends in the IT Industry and has done extensive research in the data science industry.

LATEST

Windows 11 approved hero 1

Latest Windows 11 Security Update Triggers Unintended UAC Prompts

Microsoft has acknowledged that the August 2025 security update is causing pain for administrators across several versions of Windows 11 and Windows 10. This bug is triggering unexpected User Account Control (UAC) prompts and app installation issues for non-admin users. According to Microsoft, this issue is caused by a security update that addresses the CVE-2025-50173…

View Article
Microsoft Security image

China-Linked Hackers Exploit Windows Servers for Shady SEO Manipulation

A China-linked hacking group dubbed GhostRedirector has quietly breached dozens of Windows servers worldwide. Attackers leverage tools like Rungan and Gamshen to not only gain control but also hijack search engine rankings to promote shady gambling sites. According to ESET researchers, the threat actor has compromised at least 65 Windows servers since August 2024, with…

View Article
Datacenter networking servers

Microsoft Enables In-Place Trusted Launch Upgrades to Boost Azure VM Security

Microsoft has rolled out in-place upgrade support for Trusted Launch on existing Azure Virtual Machines (VMs) and Virtual Machine Scale Sets (VMSS). This capability lets organizations boost security with features like Secure Boot and vTPM, without downtime, redeployment, or complex migration steps. What is Trusted Launch in Azure? Trusted Launch is a security feature in…

View Article
Laptop-Windows-10

Windows 10 Extended Support Could Cost Enterprises Billions

New research warns that continuing to use Windows 10 after its end of support in October could cost businesses billions, with over 120 million PCs worldwide still expected to be running the aging operating system. According to new research from Nexthink, keeping custom versions of Windows 10 could cost enterprises over $7.3 billion globally. Microsoft…

View Article
PowerShell

Microsoft Retires Graph CLI and Toolkit in Push Toward PowerShell SDK

Microsoft has announced the retirement of its Microsoft Graph CLI and the Graph Toolkit. The move is part of the company’s broader effort to simplify and streamline its developer toolset. The Microsoft Graph CLI is a command-line tool designed to help developers and IT professionals interact with Microsoft Graph APIs directly from the terminal. This…

View Article
DevOps code

Leaked Azure AD (Entra ID) Credentials Expose Cloud Environments to Attack

Cybersecurity researchers have discovered a critical flaw where Azure Active Directory (Azure AD) application credentials were left exposed in a publicly accessible appsettings.json file. This misconfiguration could let attackers exploit Microsoft’s OAuth 2.0 endpoints to gain unauthorized access and infiltrate Azure cloud environments. The risk of exposed appsettings.json files appsettings.json is a configuration file commonly…

View Article
Microsoft Azure

Microsoft to Tighten Cloud Security with Mandatory MFA for Azure Resource Management

Microsoft will soon begin enforcing Multi-Factor Authentication (MFA) for all Azure resource management actions. The company has announced that this change will go into effect on October 1, 2025. In a support document, Microsoft detailed that the mandatory MFA enforcement will apply to Azure CLI, PowerShell, SDKs, REST APIs, Infrastructure as Code (IaC) tools, and…

View Article
Network Security

Russian Hackers Abuse Device Code Flow to Infiltrate Microsoft 365 Accounts

Cybersecurity researchers have discovered a new watering hole campaign orchestrated by a Russian state-sponsored hacking group. The operation exploits Microsoft’s device code authentication flow to trick users into authorizing attacker-controlled devices, granting them unauthorized access to Microsoft 365 accounts. How did Russian hackers exploit Microsoft authentication? According to Amazon’s threat intelligence team, the Russian threat…

View Article
Cloud Computing

Microsoft Intune Update Brings Smarter Controls and Multi-Admin Workflows

Microsoft has rolled out a range of new Intune capabilities for August 2025, including smarter app control, multi-admin approvals for sensitive actions, enhanced Apple update visibility, and more. These updates are designed to streamline IT management while strengthening security across organizations. App Control targeting Microsoft has made App Control for Business generally available to commercial…

View Article
Security

Storm-0501 Shifts to Cloud Ransomware in Sophisticated Hybrid Attack

Cybercriminal group Storm-0501 recently carried out a ransomware-style attack that breached both on-premises and cloud environments of an enterprise victim. The campaign highlights the group’s shift from traditional endpoint-focused tactics to more sophisticated cloud-based ransomware operations. Storm-0501 is a financially driven cybercriminal group that has been active since 2021. It’s known for launching ransomware attacks…

View Article
Laptop-Windows-10

Windows Backup for Organizations Now Available to All Commercial Customers

Windows Backup for Organizations, a new tool that launched in limited public preview, is now generally available for commercial customers. This new feature allows organizations to take a backup of their Windows PC settings and preferences and then restore them on a Microsoft Entra-joined device. Microsoft first announced Windows Backup for Organizations at its Ignite…

View Article
warning-cyber-attack

Massive Attack Campaign Hits Microsoft’s Remote Desktop Services

Security researchers have warned about a new attack campaign that targets Microsoft’s Remote Desktop Protocol (RDP) services. Nearly 2,000 malicious IPs have specifically hit RD Web Access and RDP Web Client authentication portals in recent days. Threat intelligence firm GreyNoise detected a significant increase in RDP scans from around 2,000 IP addresses on August 21….

View Article
Go to page