Thursday, April 16, 2026
HomeTagsWindows

Tag: windows

Critical Citrix VDA Vulnerability Allows Attackers to Gain SYSTEM-Level Access on Windows

A high-severity security vulnerability affecting Citrix Virtual Apps and Desktops and Citrix DaaS systems worldwide. The vulnerability, designated as CVE-2025-6759, enables local attackers with low-level privileges to escalate their access to SYSTEM-level privileges on affected Windows Virtual Delivery Agent installations. With a CVSS v4.0...

Zoom for Windows Vulnerabilities Leaves Users Open to DoS Attacks

A critical buffer overflow vulnerabilities in multiple Zoom clients for Windows that could enable authorized users to launch denial-of-service attacks through network access. The vulnerabilities, tracked as CVE-2025-49464 and CVE-2025-46789, both carry a medium severity rating with CVSS scores of 6.5, highlighting significant security...

Microsoft Removes PowerShell 2.0 from Windows 11 over Security & Architecture concerns

Microsoft has announced a significant change for Windows 11 Insiders, with the deprecation and removal of Windows PowerShell 2.0 in the latest Insider Preview Build 27891, released to the Canary Channel. The move aims to address longstanding architectural and security vulnerabilities associated with the...

Smarter Windows Updates: New Interface Empowers Users with Security Controls

Microsoft has rolled out a significant Windows Update enhancement that introduces intelligent notification capabilities designed to keep users better informed about their device's security status and update requirements. The new user interface functionality represents a proactive approach to addressing security vulnerabilities by alerting users...

FileFix – Leveraging Windows Browser Vulnerabilities to Circumvent Mark-of-the-Web Defense

A new blog post by a security researcher has introduced a troubling variant of the notorious FileFix attack, posing fresh challenges for defenders on the Windows platform. This new technique exploits subtle behaviors in Chromium-based browsers, Google Chrome and Microsoft Edge, to bypass the...

Windows Shutdowns Triggered by Invalid Inputs in Malicious passlib Python Package

Security researchers at Socket have uncovered a malicious Python package that exploits developer trust and system integration to compromise Windows environments. The malicious package, named psslib, is a typosquatting attack targeting the legitimate and widely used passlib library, resulting in immediate system shutdowns when users enter incorrect...