Search
Articles · 45

Microsoft Halts July 2026 Windows 11 Update Rollout on Select Dell Machines
Microsoft has suspended the July 2026 Windows 11 Patch Tuesday update on certain Dell models after it triggered unexpected shutdowns, sluggish performance, higher heat and fast battery drain. The flaw traces to an Intel driver clashing with a new USB-C Connection Manager interface; exact affected machines remain undisclosed while a fix is prepared.

Microsoft to cut 605 jobs in Redmond
Microsoft has filed notice to permanently lay off 605 workers at its Redmond headquarters effective September 4, 2026. Axios notes 493 Redmond + other WA sites for the 605 total. The cuts are part of a sweeping Xbox gaming division restructure inside a global plan targeting approximately 3,200 roles in FY2027.

Critical RCE Flaw in Windows GDI+ Carries 9.6 CVSS Score
Microsoft disclosed CVE-2026-50380, a critical heap-based buffer overflow in Windows GDI+ that enables remote code execution over a network with a 9.6 CVSS score. The flaw affects numerous Windows 10 and 11 releases and is being patched as part of the July 2026 Patch Tuesday.

Microsoft Secure Boot bypassed for 13 years via unrevoked shims
ESET researchers found that 11 defective Microsoft-signed shims allowed trivial bypasses of UEFI Secure Boot for 13 years until revocation in the June 2026 Patch Tuesday update. The flaw affects Windows and Linux devices alike and enables persistent bootkit installation with minimal attacker effort.

Microsoft tells Windows 10 holdouts they can keep using their PCs until 2027
Microsoft is now emailing Windows 10 users about the consumer Extended Security Updates extension to October 2027 while making no reference to Windows 11. The outreach recognizes ongoing hardware cost barriers and stalled adoption rates that still leave millions on the older platform.

Microsoft to expand Patch Tuesday security releases with AI
Microsoft is expanding the number of fixes delivered in each Patch Tuesday release for Windows 11 by using AI to surface potential security issues earlier. The adjustment comes amid rising AI-assisted vulnerability hunting and exploitation by both attackers and security researchers.

Microsoft patches Nightmare Eclipse's RoguePlanet Defender zero-day
Microsoft has fixed the RoguePlanet zero-day in Defender via an update to the Malware Protection Engine. The patch closes the latest vulnerability publicly disclosed by researcher Nightmare Eclipse, who has sparred with the company over its handling of bug reports all year.

CVE-2026-58525 Reserved by Microsoft, Details Under Embargo
NIST lists CVE-2026-58525 as reserved by Microsoft with details withheld until the embargo ends. The placeholder NVD entry directs to an MSRC link while providing no severity, affected products, or technical description.

Microsoft accelerates Quantum Safe Program to 2029
Microsoft has moved its Quantum Safe Program target to 2029 because cryptographically relevant quantum computers could arrive sooner than previously expected. The update underscores the need for organizations to begin preparing now against harvest-now-decrypt-later attacks and future quantum decryption threats.

Microsoft cuts 4,800 jobs as new financial year starts
Microsoft eliminated approximately 4,800 roles on the first day of its new financial year, with the largest share coming from Xbox and commercial sales. The company cited industry-wide changes driven by AI, while noting that it has redeployed thousands of workers and used a voluntary retirement program to limit forced layoffs.

Microsoft assigns 6,000 workers and $2.5 billion to new AI client deployment subsidiary
Microsoft is committing $2.5 billion and reassigning 6,000 employees to its new Microsoft Frontier Co. subsidiary to help clients deploy artificial intelligence. The announcement follows similar forward deployed engineering initiatives launched this year by Amazon, Anthropic and OpenAI.

CISA Warns of Active Exploitation of SharePoint RCE Flaw
CISA warned Wednesday that attackers are exploiting CVE-2026-45659, a SharePoint RCE flaw patched by Microsoft in May, and added it to its KEV catalog on July 1 with a July 4 deadline for federal agencies. The deserialization vulnerability lets low-privileged authenticated users execute code remotely over the network, and more than 10,000 SharePoint servers remain exposed online.

Cloudflare to block mixed-purpose bots from ad-supported sites by default
Cloudflare will block mixed-use crawlers from ad-supported pages by default beginning September 15, 2026, aiming to protect publisher revenue from unpermitted AI training scrapes while still allowing search indexing. The policy affects bots from Apple, Google, and Microsoft that combine indexing with data harvesting and encourages clearer separation of those activities.

Microsoft pulls forward quantum-safe encryption deadline to 2029
Microsoft is accelerating its quantum-safe security roadmap to transition critical products and services to post-quantum cryptography by 2029. The move reflects advances in quantum computing that have shifted the risk horizon for "harvest now, decrypt later" attacks sooner than previously expected.

CISA Adds BlueHammer to KEV Catalog Over Ransomware Exploitation
CISA confirmed ransomware gangs are exploiting the BlueHammer Microsoft Defender privilege escalation vulnerability, CVE-2026-33825, previously abused in zero-day attacks. The KEV Catalog update highlights continued danger to federal networks and the urgency of patching.

Anthropic Claude Models Now Run on NVIDIA GB300 in Azure
Anthropic’s Claude models in Microsoft Foundry are now generally available on Microsoft Azure running on NVIDIA GB300 Blackwell Ultra GPUs. This gives Azure-native enterprises a new platform for building autonomous and domain-specific AI agents with enhanced performance and governed security.

Italy launches probe into Microsoft 365 price increases linked to AI
Italy's AGCM is investigating Microsoft over claims that fragmented notices left Microsoft 365 subscribers automatically moved to costlier plans once Copilot and Designer features were added without clear explanation of the changes.

Microsoft extends free Windows 10 security updates to 2027
Microsoft has extended free Windows 10 Extended Security Updates for personal devices by one year to October 12, 2027. The move gives users more time to transition amid hardware shortages and draws mixed reactions from consumer groups who say it comes too late.

Oracle's workforce shrinks by 21,000 amid AI-driven restructuring
Oracle reduced its global headcount by 21,000 to approximately 141,000 as of May 31, 2026, citing AI adoption among the factors. The job cuts freed resources for data-center construction serving clients including OpenAI and mirror similar workforce reductions at Microsoft and Meta.

Microsoft launches next Surface Pro and Laptop with Snapdragon X2
Microsoft has released the next Surface Pro and Surface Laptop powered by Snapdragon X2 processors, available immediately with business editions arriving July 14. The devices bring faster graphics performance, longer battery life and refined displays while continuing Surface's focus on hybrid AI workloads that span on-device and cloud processing.

Microsoft Edge shifts to two-week release cycle
Microsoft Edge is adopting a two-week release cycle for its Stable channel beginning with version 152 on August 27, while Extended Stable remains on an eight-week schedule. The shift delivers smaller, more frequent updates and faster security improvements to help organizations validate changes more easily.

Microsoft patches three Windows zero-days including BitLocker bypass
Microsoft patched GreenPlasma, MiniPlasma, and YellowKey zero-days in its June 2026 Patch Tuesday release, addressing SYSTEM privilege escalation and a BitLocker bypass. The flaws were disclosed by researcher Nightmare Eclipse in protest of Microsoft's vulnerability handling process.

Microsoft packages laced with credential stealer for second time
Microsoft open-source packages were compromised with a self-replicating credential stealer that activates inside AI coding agents, marking the second supply-chain attack on the company’s repositories in recent weeks. The campaign exploited legitimate OIDC tokens and SLSA provenance to bypass detection and target cloud identities.

Build 2026: Microsoft Places Its Biggest Bet Yet on AI Agents
Microsoft opens Build 2026 with a sweeping slate of agent-focused announcements, including an in-house reasoning model, agent hardware, and Windows-native AI capabilities. The moves signal Redmond’s intent to own the infrastructure where autonomous AI workers operate.

Microsoft Launches MAI-Thinking-1 Advanced Reasoning Model
Microsoft announced MAI-Thinking-1 as its new flagship model at Build 2026 among several proprietary systems developed in-house. The releases mark continued progress toward independent AI development following last year’s initial models and a recent renegotiation with OpenAI intended to loosen ties.

Microsoft Exchange Online Outage Hits Mail Flow in North America and Germany
Microsoft is investigating a widespread Exchange Online outage disrupting mail flow for customers in North America and Germany. Users face significant sending and receiving delays with some messages undelivered for over an hour while engineers seek the root cause.

Microsoft Optimizes Windows 11 for Developers with Deeper Linux Ties
Microsoft announced optimizations to Windows 11 for developers at Build, including native Linux command-line utilities, WSL containers, an Intelligent Terminal, and simplified setup configurations. The updates deepen Linux integration to improve performance, reliability, and workflow consistency across environments.

Microsoft Investigates Teams and Office Web File Access Outage
Microsoft is investigating an ongoing incident that prevents users from opening files in Teams and Office for the web, including Excel. Initial analysis indicates a potential cross-service issue and the outage has been tagged as a critical incident.

FTC Probe Targets Microsoft Azure Cloud Practices
The FTC is investigating Microsoft over potentially exclusionary practices in Azure cloud services and its AI role, sending detailed demands to competitors. This marks the first major antitrust scrutiny of the company in more than 25 years.

Microsoft Outage Blocks MFA Setup and My Sign-Ins Access
Microsoft confirmed an ongoing outage preventing some users from setting up MFA or reaching the My Sign-Ins platform with 504 Gateway Timeout errors reported. The company has failed over to alternate infrastructure and is evaluating further steps as elevated error rates continue.

Microsoft and NVIDIA Launch RTX Spark Windows PCs
Microsoft and NVIDIA announced the world’s most powerful and efficient thin-and-light Windows PCs accelerated by RTX Spark at NVIDIA GTC. The platform delivers 1 petaflop of AI performance and is purpose-built for local agents with deep Windows scheduler and power optimizations.

Microsoft Launches Surface Laptop Ultra with NVIDIA Blackwell GPU
Microsoft introduced Surface Laptop Ultra, its most powerful laptop yet featuring a NVIDIA Blackwell RTX GPU, up to 128GB unified memory and 1 petaflop of AI compute. The device is purpose-built for creators, developers and AI builders running demanding local workloads with quiet operation and all-day battery life.

Microsoft Phases Out SMS Authentication for All Accounts
Microsoft is phasing out SMS authentication and account recovery for all personal Microsoft accounts, including those used with Xbox, citing it as a leading source of fraud. The change promotes more secure passwordless options like passkeys to counter phishing and SIM-swap attacks while simplifying access.

Microsoft Settles Activision Suit for $250 Million
Microsoft will pay $250 million to end a lawsuit filed by Swedish pension fund AP7 that alleged its $69 billion Activision Blizzard purchase was undervalued and rushed to dodge scandal fallout. The resolution also ends Bobby Kotick’s countersuit and includes a prior statement denying any substantiated claims of systemic misconduct.

Microsoft Lets Office Users Disable Floating Copilot Button
Microsoft plans Office updates next week that let people shift the floating Copilot button to the ribbon. The change responds to complaints, especially from Excel users who said the button blocked cells and could not be fully disabled.

GitHub Battles Outages, Hacks, and Talent Drain at Microsoft
GitHub is battling multiple outages, a remote code execution vulnerability, an internal hack, and a wave of executive departures nearly eight years after its $7.5 billion acquisition by Microsoft. Leadership changes that began with the former CEO's resignation last summer have triggered a talent exodus to a direct competitor and heightened concerns over falling behind in AI coding tools.

Microsoft Patches Two Actively Exploited Defender Zero-Days
Microsoft began rolling out patches Wednesday for two zero-day vulnerabilities in Defender that attackers are actively exploiting to gain SYSTEM privileges or trigger denial-of-service conditions. CISA added the flaws, known as RedSun and UnDefend, to its Known Exploited Vulnerabilities catalog and gave federal agencies until June 3 to apply fixes.

Microsoft Launches Driver Quality Initiative for Windows
Microsoft launched the Driver Quality Initiative at WinHEC 2026 targeting improved driver quality, reliability and security. The program addresses an ecosystem of thousands of partners supporting tens of thousands of driver families that affect overall Windows stability and performance.

Microsoft Launches New Surface Pro, Laptop for Business with Intel Core Ultra
Microsoft announced new Surface Pro for Business and Surface Laptop for Business models powered by Intel Core Ultra Series 3 processors that are available today in select markets with significant graphics performance gains. The devices address IT challenges around AI workloads, security and investment decisions by integrating hardware, software and on-device AI capabilities.

Microsoft Lets Windows 11 Taskbar Sit on Any Edge
Microsoft announced it will let Windows 11 users position the taskbar on any screen edge while adding toggles and quality improvements to the Start menu. The updates restore capabilities removed at Windows 11 launch and focus on making the OS more personal.

Microsoft Phases Out SMS Authentication Over Fraud Concerns
Microsoft is phasing out SMS codes for login and recovery on personal accounts, citing the method as a leading source of fraud. The move accelerates the company's passwordless strategy centered on passkeys to counter threats and simplify access.

MiniPlasma Zero-Day Grants SYSTEM Access on Fully Patched Windows
A researcher known as Chaotic Eclipse has published a MiniPlasma PoC that reuses a 2020 Cloud Filter driver flaw to grant SYSTEM privileges on the latest patched Windows 11. The release forms part of an ongoing series of Windows zero-days whose author alleges poor treatment by Microsoft’s vulnerability handling program.

Windows 11 Taskbar Gains Full Edge Positioning for Insiders
Microsoft is rolling out taskbar positioning to any screen edge along with related personalization options to Windows Insiders in the Experimental channel. The changes address long-standing user requests for flexibility in one of the operating system's core interfaces while noting several features still under development.

Microsoft Exchange, Windows 11 Hacked on Pwn2Own Day Two
On the second day of Pwn2Own Berlin 2026, researchers earned $385,750 by exploiting 15 zero-day vulnerabilities including successful attacks on Microsoft Exchange and Windows 11. The demonstrations underscore risks in enterprise and AI products while giving vendors 90 days to issue patches after public disclosure.

Microsoft Adds Automatic Driver Rollback to Windows Update
Microsoft is launching Cloud-Initiated Driver Recovery to automatically replace faulty drivers installed via Windows Update with working versions. The change eliminates manual rollbacks for users and partners while introducing other tools to make the overall update process less disruptive.
From the feed · 46
Microsoft published manual mitigations for WSUS servers experiencing sync delays and timeouts during Windows Update scans. The steps address a known issue that causes scans to fail for affected administrators.
Protesters derailed a PNW Climate Week closing event by confronting Microsoft CSO Melanie Nakagawa over data center energy use tied to AI expansion. The fireside chat with a GeekWire reporter was halted as concerns about carbon goals were raised.
The Document Foundation says OOXML's ISO certification does not ensure consistent rendering outside Microsoft Office. Only the company's own apps can be trusted with the files.
Appointments set for 2050 are hiding commands for the HOLLOWGRAPH malware campaign inside Microsoft 365 calendars. The operators use Redmond's own cloud sync to retrieve instructions and exfiltrate data.
Microsoft is expanding Azure's AI and HPC infrastructure with additional AMD hardware. The update adds more AMD-based instances for large-scale training and simulation workloads.
AMD's first rack-scale AI system, Helios, now counts four hyperscale buyers. • Microsoft • Meta • OpenAI • Oracle
AMD and Microsoft expanded their partnership to deliver a full stack of AMD AI solutions for Azure, spanning GPUs, CPUs, networking, and software. Microsoft will deploy AMD Helios for frontier model inference.
Microsoft is addressing WSUS server sync delays and timeouts that have persisted for more than a week. The company confirmed it is working on a fix for the known issue.
Microsoft is overhauling File Explorer search in Windows 11 to fix its long-standing performance issues. The update targets the feature's slowest areas after years of user avoidance.
Microsoft shipped KB5121767 as an out-of-band fix after the July Windows 11 updates triggered shutdowns on some Dell systems. The patch targets the regression without requiring a full monthly cycle.
Microsoft is seeing a surge in ACR Stealer malware campaigns aimed at enterprise customers, harvesting browser passwords, auth tokens, and documents.
Microsoft ends OneDrive support for Windows 10 versions before 22H2 next month. Version 22H2 keeps access through 2028.
Microsoft Security will present supply chain research and AI trust sessions at Black Hat USA 2026, including hands-on labs and an evening reception.
8GB of RAM is now the base spec on Microsoft's $950 Surface Laptop 13-inch. Windows 11 still struggles with it.
Microsoft disclosed CVE-2026-58598, a high-severity race condition in the Windows Backup Engine. An authorized local attacker can exploit it to elevate privileges on multiple Windows 10 and Windows 11 releases. The flaw carries a CVSS score of 7.0. No patches appear in the July 16 NVD record.
From late April to mid-June 2026, Microsoft Defender Experts tracked increased ACR Stealer activity. Campaigns used ClickFix lures to pull browser credentials, authentication tokens, and enterprise documents.
Nadella told staff that Anthropic's Fable restrictions "doesn't make sense," even as Microsoft continues work on private-data model refinements.
Microsoft open sourced Comic Chat, the 1990s IRC client that rendered conversations as comic strips. The code is available on GitHub.
Microsoft's Secure Boot contained a flaw that left it open to bypass for roughly a decade. Affected systems need current firmware and OS updates.
Microsoft announced that Windows 11 24H2 Home and Pro editions will stop receiving updates in 90 days. Windows 10 Enterprise LTSB 2016 faces the same cutoff.
Microsoft deleted a 25-year-old account after it was hacked, removing the owner's OneDrive files, digital games, and his son's baby pictures rather than restoring access.
A Windows zero-day exploit called HiveLegacy reportedly dropped the same day Microsoft released a record number of patches. The flaw is described as a powerful primitive with potential for further abuse.
Microsoft 365 apps are affected by CVE-2026-55898, a high-severity vulnerability with a CVSS score of 7.1. An out-of-bounds read in Excel allows local information disclosure by an unauthorized attacker.
Microsoft canceled this month's Patch Tuesday for some Dell users after devices began shutting down unexpectedly and overheating. Affected models have not been named.
Microsoft Windows DNS carries CVE-2026-50465, a CVSS 7.1 flaw that lets an authorized local attacker tamper with data.
Microsoft fixed more security vulnerabilities in Windows 11 this month than in any previous month. The push comes as attackers increasingly use AI to find flaws.
Microsoft Excel contains a heap-based buffer overflow vulnerability, CVE-2026-50675, with a CVSS score of 7.8 that allows local code execution.
Microsoft's Universal Disk Format File System driver contains an elevation of privilege vulnerability, CVE-2026-49790, rated 7.3 on CVSS.
Microsoft's Windows App Store contains a use of uninitialized resource vulnerability, CVE-2026-49165, rated CVSS 7.1 and allowing local information disclosure.
Microsoft Office SharePoint contains a critical deserialization flaw, CVE-2026-58644, that lets an unauthenticated attacker run code over the network.
Microsoft Copilot has a critical command injection flaw, CVE-2026-48561, that lets an attacker execute code over the network.
Microsoft rolled out its July Patch Tuesday update for Windows 11, adding the option to pause updates for up to 35 days at a time with repeated extensions.
Microsoft Threat Intelligence tracked ShinyHunters-linked activity abusing OAuth in SaaS apps through vishing, supply-chain compromises, and misconfigured guest access.
Satya Nadella warned companies to lock down their IP against frontier AI labs. The Microsoft chief's comments highlight a sharper stance toward the labs Redmond once funded heavily.
Microsoft is updating the Windows Search Box for Insiders with less clutter and added controls for faster, more relevant results.
Microsoft is applying AI to spot Windows vulnerabilities for future security updates. Only the highest-confidence results reach engineers, with humans still handling decisions and fixes.
Microsoft AI is powering a lifelike avatar of Theodore Roosevelt at the new presidential library in Medora, North Dakota. Visitors can ask the avatar questions about his life, leadership and legacy.
Microsoft's Copilot now flags processes that might be slowing down a PC. The feature itself takes up a noticeable chunk of system RAM.
Microsoft Edge contains an untrusted pointer dereference vulnerability tracked as CVE-2026-58596 with a CVSS score of 8.3. The flaw lets an attacker elevate privileges over a network.
Microsoft Edge contains a high-severity deserialization flaw, CVE-2026-58281 with CVSS 8.3, that lets an attacker run code over the network.
Microsoft's climate-warming emissions surged 25 percent, driven by its AI infrastructure buildout.
Samsung Gallery will stop syncing with Microsoft OneDrive in September 2026. Users will need another backup option before then.
Microsoft identified GigaWiper, a Windows backdoor that bundles at least three malware families including wipers and ransomware into one modular package.
Microsoft released its July 2026 progress report on the Secure Future Initiative, detailing work on secure foundations, AI-powered defense, and future-ready cybersecurity.
Microsoft's emissions rose 25% in a year, driven by AI datacenter construction.
Microsoft Teams added a Workspace Check-in feature last month. It records employee locations when users sign into a workspace.