Skip to content
tag — microsoft

grep -rl "microsoft" ./articles

#microsoft

23 articles

Microsoft's own figures put weaponisation under a day and remediation at up to sixty, and the most-detected flaw is from 2020

2026-10-03Security

The 2026 Digital Defense Report, covering July 2025 to June 2026, says attackers are collecting the benefits of AI first. Underneath that headline are three numbers that do not need AI to explain them: nearly 40,000 CVEs in six months, a weaponisation median well below 24 hours against 30 to 60 days to remediate, and a 2020 vulnerability still responsible for most detections among the top five.

974 flaws, and the two that matter are both privilege escalation

2026-09-09Security

Microsoft patched 974 vulnerabilities in September, a 70% jump over the previous record, with 723 of them in Windows and more than 110 rated critical. Two are being exploited. Both are CVSS 7.8 local privilege escalation, which means the attacker is already on the machine — and that is the whole triage.

The only thing they changed was telling you to open Terminal instead of Run

2026-08-31Security

TerminalFix is ClickFix with one substitution. A fake Cloudflare CAPTCHA asks you to paste a command, and instead of the Run dialog it sends you to Windows Terminal or PowerShell — where long multi-line scripts actually work. The end of the chain is a Python reverse tunnel that lets the operator reach anything your machine can see.