Rabia has a master's degree in Software Engineering and she has years of experience writing professionally about Microsoft products and other technologies. Rabia has also written for OnMSFT.com as well as Windows Report. She is always up to date on the latest trends in the IT Industry and has done extensive research in the data science industry.
Microsoft has acknowledged that the August 2025 security update is causing pain for administrators across several versions of Windows 11 and Windows 10. This bug is triggering unexpected User Account Control (UAC) prompts and app installation issues for non-admin users. According to Microsoft, this issue is caused by a security update that addresses the CVE-2025-50173…
A China-linked hacking group dubbed GhostRedirector has quietly breached dozens of Windows servers worldwide. Attackers leverage tools like Rungan and Gamshen to not only gain control but also hijack search engine rankings to promote shady gambling sites. According to ESET researchers, the threat actor has compromised at least 65 Windows servers since August 2024, with…
Microsoft has rolled out in-place upgrade support for Trusted Launch on existing Azure Virtual Machines (VMs) and Virtual Machine Scale Sets (VMSS). This capability lets organizations boost security with features like Secure Boot and vTPM, without downtime, redeployment, or complex migration steps. What is Trusted Launch in Azure? Trusted Launch is a security feature in…
New research warns that continuing to use Windows 10 after its end of support in October could cost businesses billions, with over 120 million PCs worldwide still expected to be running the aging operating system. According to new research from Nexthink, keeping custom versions of Windows 10 could cost enterprises over $7.3 billion globally. Microsoft…
Microsoft has announced the retirement of its Microsoft Graph CLI and the Graph Toolkit. The move is part of the company’s broader effort to simplify and streamline its developer toolset. The Microsoft Graph CLI is a command-line tool designed to help developers and IT professionals interact with Microsoft Graph APIs directly from the terminal. This…
Cybersecurity researchers have discovered a critical flaw where Azure Active Directory (Azure AD) application credentials were left exposed in a publicly accessible appsettings.json file. This misconfiguration could let attackers exploit Microsoft’s OAuth 2.0 endpoints to gain unauthorized access and infiltrate Azure cloud environments. The risk of exposed appsettings.json files appsettings.json is a configuration file commonly…
Microsoft will soon begin enforcing Multi-Factor Authentication (MFA) for all Azure resource management actions. The company has announced that this change will go into effect on October 1, 2025. In a support document, Microsoft detailed that the mandatory MFA enforcement will apply to Azure CLI, PowerShell, SDKs, REST APIs, Infrastructure as Code (IaC) tools, and…
Cybersecurity researchers have discovered a new watering hole campaign orchestrated by a Russian state-sponsored hacking group. The operation exploits Microsoft’s device code authentication flow to trick users into authorizing attacker-controlled devices, granting them unauthorized access to Microsoft 365 accounts. How did Russian hackers exploit Microsoft authentication? According to Amazon’s threat intelligence team, the Russian threat…
Microsoft has rolled out a range of new Intune capabilities for August 2025, including smarter app control, multi-admin approvals for sensitive actions, enhanced Apple update visibility, and more. These updates are designed to streamline IT management while strengthening security across organizations. App Control targeting Microsoft has made App Control for Business generally available to commercial…
Cybercriminal group Storm-0501 recently carried out a ransomware-style attack that breached both on-premises and cloud environments of an enterprise victim. The campaign highlights the group’s shift from traditional endpoint-focused tactics to more sophisticated cloud-based ransomware operations. Storm-0501 is a financially driven cybercriminal group that has been active since 2021. It’s known for launching ransomware attacks…
Windows Backup for Organizations, a new tool that launched in limited public preview, is now generally available for commercial customers. This new feature allows organizations to take a backup of their Windows PC settings and preferences and then restore them on a Microsoft Entra-joined device. Microsoft first announced Windows Backup for Organizations at its Ignite…
Security researchers have warned about a new attack campaign that targets Microsoft’s Remote Desktop Protocol (RDP) services. Nearly 2,000 malicious IPs have specifically hit RD Web Access and RDP Web Client authentication portals in recent days. Threat intelligence firm GreyNoise detected a significant increase in RDP scans from around 2,000 IP addresses on August 21….