<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Microsoft</title><description>Cybersecurity articles tagged #Microsoft on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Microsoft Removes WMIC Tool in Windows 11 to Curb Living-off-the-Land Tactics</title><link>https://runtimerebel.com/blog/microsoft-removes-wmic-tool-in-windows-11-to-curb-living-off-the-land-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-removes-wmic-tool-in-windows-11-to-curb-living-off-the-land-tactics</guid><description>Microsoft removes the legacy WMIC tool from Windows 11 builds to disrupt living-off-the-land techniques used by ransomware and malware.</description><pubDate>Tue, 18 Aug 2026 08:25:06 GMT</pubDate><category>Microsoft</category><category>Windows 11</category><category>Ransomware</category><category>Malware</category><category>Living-off-the-Land</category></item><item><title>CVE-2026-68820: Windows afd.sys Privilege Escalation Exploited</title><link>https://runtimerebel.com/blog/cve-2026-68820-windows-afd-sys-privilege-escalation-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-68820-windows-afd-sys-privilege-escalation-exploited</guid><description>Microsoft addresses 398 vulnerabilities, including an actively exploited privilege escalation flaw in Windows&apos; afd.sys component.</description><pubDate>Wed, 12 Aug 2026 01:06:41 GMT</pubDate><category>Microsoft</category><category>Windows</category><category>Privilege Escalation</category><category>Zero-Day</category><category>CVE-2026-68820</category></item><item><title>Microsoft &amp; Apple Patch Critical RCEs and Auth Bypass Flaws</title><link>https://runtimerebel.com/blog/microsoft-apple-patch-critical-rces-and-auth-bypass-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-apple-patch-critical-rces-and-auth-bypass-flaws</guid><description>Microsoft released patches for critical-severity RCE and EoP flaws across Active Directory, Azure, and Teams. Apple fixed a Screen Sharing authentication bypass.</description><pubDate>Sun, 09 Aug 2026 08:32:17 GMT</pubDate><category>Microsoft</category><category>Apple</category><category>Vulnerabilities</category><category>RCE</category><category>Authentication Bypass</category></item><item><title>Microsoft Secure Boot Bypass via Vulnerable Shims — Remediation Guide</title><link>https://runtimerebel.com/blog/microsoft-secure-boot-bypass-via-vulnerable-shims-remediation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-secure-boot-bypass-via-vulnerable-shims-remediation-guide</guid><description>An analysis of a decade-long vulnerability in Microsoft Secure Boot. Learn how vulnerable Linux shims allow attackers to bypass UEFI firmware protections.</description><pubDate>Wed, 29 Jul 2026 14:14:44 GMT</pubDate><category>Microsoft</category><category>Secure Boot</category><category>UEFI</category><category>Shim</category><category>ESET</category></item><item><title>CVE-2024-49019: Certighost AD CS Privilege Escalation Explained</title><link>https://runtimerebel.com/blog/cve-2024-49019-certighost-ad-cs-privilege-escalation-explained</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-49019-certighost-ad-cs-privilege-escalation-explained</guid><description>Analysis of CVE-2024-49019, the Certighost flaw in Microsoft AD CS. Learn how misconfigured certificate templates allow full Active Directory compromise.</description><pubDate>Tue, 28 Jul 2026 17:37:56 GMT</pubDate><category>CVE-2024-49019</category><category>Certighost</category><category>Active Directory Certificate Services</category><category>Privilege Escalation</category><category>Microsoft</category></item><item><title>Microsoft MAI-Cyber-1-Flash: Performance Analysis of Security LLM</title><link>https://runtimerebel.com/blog/microsoft-mai-cyber-1-flash-performance-analysis-of-security-llm</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-mai-cyber-1-flash-performance-analysis-of-security-llm</guid><description>Microsoft introduces MAI-Cyber-1-Flash, its first specialized cybersecurity AI model, outperforming competitors in CyberGym benchmark testing.</description><pubDate>Tue, 28 Jul 2026 14:11:15 GMT</pubDate><category>Microsoft</category><category>MAI Cyber 1 Flash</category><category>CyberGym</category><category>Artificial Intelligence</category><category>LLM</category></item><item><title>Microsoft MDASH Update: MAI-Cyber-1-Flash Achieves 95.95% Accuracy</title><link>https://runtimerebel.com/blog/microsoft-mdash-update-mai-cyber-1-flash-achieves-95-95-accuracy</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-mdash-update-mai-cyber-1-flash-achieves-95-95-accuracy</guid><description>Microsoft announces MAI-Cyber-1-Flash for its MDASH harness, delivering 95.95% vulnerability remediation accuracy at half the previous operational cost.</description><pubDate>Tue, 28 Jul 2026 06:28:35 GMT</pubDate><category>Microsoft</category><category>MDASH</category><category>MAI Cyber 1 Flash</category><category>Vulnerability Management</category><category>Artificial Intelligence</category></item><item><title>CVE-2026-50522: SharePoint RCE Exploitation to Steal Machine Keys</title><link>https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-exploitation-to-steal-machine-keys</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-50522-sharepoint-rce-exploitation-to-steal-machine-keys</guid><description>Critical CVE-2026-50522 in Microsoft SharePoint is actively exploited to steal machine keys, enabling persistent access. Understand the threat and mitigation.</description><pubDate>Tue, 21 Jul 2026 21:12:05 GMT</pubDate><category>CVE-2026-50522</category><category>SharePoint</category><category>RCE</category><category>Machine Keys</category><category>Persistence</category><category>Microsoft</category></item><item><title>WSUS Sync Delays &amp; Timeouts: Microsoft&apos;s Manual Fix Guidance</title><link>https://runtimerebel.com/blog/wsus-sync-delays-timeouts-microsoft-s-manual-fix-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/wsus-sync-delays-timeouts-microsoft-s-manual-fix-guidance</guid><description>Microsoft provides manual steps to resolve persistent sync delays and timeouts impacting Windows Server Update Services (WSUS) deployments, affecting Windows Update…</description><pubDate>Tue, 21 Jul 2026 10:40:42 GMT</pubDate><category>WSUS</category><category>Microsoft</category><category>Windows Server Update Services</category><category>Patch Management</category><category>System Management</category></item><item><title>Microsoft Investigates WSUS Server Synchronization Timeout Errors</title><link>https://runtimerebel.com/blog/microsoft-investigates-wsus-server-synchronization-timeout-errors</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-investigates-wsus-server-synchronization-timeout-errors</guid><description>Microsoft confirms technical issues causing WSUS synchronization delays and timeouts. Learn how this affects enterprise patch management and security.</description><pubDate>Mon, 20 Jul 2026 10:56:29 GMT</pubDate><category>WSUS</category><category>Windows Server Update Services</category><category>Microsoft</category><category>Patch Management</category><category>IT Operations</category></item><item><title>ACR Stealer Campaign Targets Microsoft Enterprise Credentials</title><link>https://runtimerebel.com/blog/acr-stealer-campaign-targets-microsoft-enterprise-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/acr-stealer-campaign-targets-microsoft-enterprise-credentials</guid><description>Microsoft warns of a surge in ACR Stealer attacks targeting browser credentials and session tokens to bypass multi-factor authentication in enterprise environments.</description><pubDate>Sat, 18 Jul 2026 16:59:16 GMT</pubDate><category>ACR Stealer</category><category>Infostealer</category><category>Microsoft</category><category>Credential Theft</category></item><item><title>CVE-2026-58644: SharePoint RCE Zero-Day Exploited in the Wild</title><link>https://runtimerebel.com/blog/cve-2026-58644-sharepoint-rce-zero-day-exploited-in-the-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-58644-sharepoint-rce-zero-day-exploited-in-the-wild</guid><description>CISA adds CVE-2026-58644, a critical Microsoft SharePoint Server deserialization RCE vulnerability with a CVSS 9.8, to its Known Exploited Vulnerabilities catalog.</description><pubDate>Fri, 17 Jul 2026 09:58:24 GMT</pubDate><category>CVE-2026-58644</category><category>SharePoint</category><category>Microsoft</category><category>CISA KEV</category><category>RCE</category></item><item><title>Microsoft April 2024 Patch Tuesday Analysis: Three Zero-Days Patched</title><link>https://runtimerebel.com/blog/microsoft-april-2024-patch-tuesday-analysis-three-zero-days-patched</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-april-2024-patch-tuesday-analysis-three-zero-days-patched</guid><description>Analysis of Microsoft&apos;s April 2024 Patch Tuesday featuring 147 CVEs, including critical zero-days CVE-2024-26234 and CVE-2024-29988. Mitigation guide for SOCs.</description><pubDate>Wed, 15 Jul 2026 10:09:10 GMT</pubDate><category>CVE-2024-26234</category><category>CVE-2024-29988</category><category>Microsoft</category><category>Patch Tuesday</category><category>Zero-Day</category></item><item><title>Windows 11 Compatibility Hold for Dell Devices: Mitigation Guide</title><link>https://runtimerebel.com/blog/windows-11-compatibility-hold-for-dell-devices-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-11-compatibility-hold-for-dell-devices-mitigation-guide</guid><description>Microsoft blocks October 2024 Windows 11 updates for specific Dell hardware due to kernel-level conflicts causing spontaneous shutdowns and performance loss.</description><pubDate>Wed, 15 Jul 2026 10:06:06 GMT</pubDate><category>Microsoft</category><category>Dell</category><category>Windows 11</category><category>Stability</category><category>Patch Management</category></item><item><title>Microsoft Patch Tuesday: Addressing 570 Security Flaws</title><link>https://runtimerebel.com/blog/microsoft-patch-tuesday-addressing-570-security-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-patch-tuesday-addressing-570-security-flaws</guid><description>Microsoft released updates for a record 570 security flaws in Windows and other software, with AI aiding discovery. Learn the impact and mitigation.</description><pubDate>Wed, 15 Jul 2026 06:16:23 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Vulnerability Management</category><category>Software Updates</category><category>AI</category><category>Windows Security</category></item><item><title>Microsoft Zero-Days: Active Directory &amp; SharePoint Exploited</title><link>https://runtimerebel.com/blog/microsoft-zero-days-active-directory-sharepoint-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-zero-days-active-directory-sharepoint-exploited</guid><description>Microsoft addresses 622 vulnerabilities, including two actively exploited zero-days in Active Directory and SharePoint Server.</description><pubDate>Wed, 15 Jul 2026 02:35:14 GMT</pubDate><category>Microsoft</category><category>Active Directory</category><category>SharePoint Server</category><category>Zero-Day</category><category>Patch Tuesday</category><category>Vulnerability</category></item><item><title>Microsoft Patches Record 622 Flaws and Two Zero-Days — Patch Now</title><link>https://runtimerebel.com/blog/microsoft-patches-record-622-flaws-and-two-zero-days-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-patches-record-622-flaws-and-two-zero-days-patch-now</guid><description>Microsoft releases its largest Patch Tuesday ever, addressing 622 vulnerabilities and two zero-days under active attack. Analyze the security impact here.</description><pubDate>Tue, 14 Jul 2026 21:01:48 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Zero-Day</category><category>Windows Security</category><category>RCE</category><category>Privilege Escalation</category></item><item><title>Windows Defender RoguePlanet Zero-Day Threat: Patch Now</title><link>https://runtimerebel.com/blog/windows-defender-rogueplanet-zero-day-threat-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-defender-rogueplanet-zero-day-threat-patch-now</guid><description>Microsoft addresses the &apos;RoguePlanet&apos; Windows Defender zero-day, with a PoC released by researcher Nightmare-Eclipse. Patching is critical.</description><pubDate>Thu, 09 Jul 2026 21:32:54 GMT</pubDate><category>Windows Defender</category><category>Zero-Day</category><category>RoguePlanet</category><category>Nightmare Eclipse</category><category>PoC</category><category>Microsoft</category></item><item><title>GigaWiper Windows Backdoor Analysis: Disk Wiping &amp; Fake Ransomware</title><link>https://runtimerebel.com/blog/gigawiper-windows-backdoor-analysis-disk-wiping-fake-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/gigawiper-windows-backdoor-analysis-disk-wiping-fake-ransomware</guid><description>Runtime Rebel analyzes GigaWiper, a destructive Windows backdoor identified by Microsoft, bundling disk wiping, fake ransomware, and spyware capabilities.</description><pubDate>Thu, 09 Jul 2026 21:32:34 GMT</pubDate><category>GigaWiper</category><category>Windows Backdoor</category><category>Disk Wiper</category><category>Fake Ransomware</category><category>Data Destruction</category><category>Microsoft</category></item><item><title>Microsoft Introduces Windows 11 Cloud Rebuild Recovery Feature</title><link>https://runtimerebel.com/blog/microsoft-introduces-windows-11-cloud-rebuild-recovery-feature</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-introduces-windows-11-cloud-rebuild-recovery-feature</guid><description>Microsoft is testing the new Cloud Rebuild recovery feature for Windows 11 Insider Preview, offering a streamlined, cloud-based OS reinstallation option.</description><pubDate>Tue, 07 Jul 2026 07:47:07 GMT</pubDate><category>Windows 11</category><category>Cloud Rebuild</category><category>System Recovery</category><category>Microsoft</category><category>Insider Preview</category></item><item><title>Windows 11 Emoji Panel GIF Fix Highlights Supply Chain Dependency</title><link>https://runtimerebel.com/blog/windows-11-emoji-panel-gif-fix-highlights-supply-chain-dependency</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-11-emoji-panel-gif-fix-highlights-supply-chain-dependency</guid><description>Microsoft resolves Windows 11 Emoji Panel GIF functionality after provider shutdown, underscoring third-party service dependencies in OS features.</description><pubDate>Wed, 01 Jul 2026 13:05:33 GMT</pubDate><category>Windows 11</category><category>Emoji Panel</category><category>GIF</category><category>Microsoft</category><category>Service Disruption</category><category>Supply Chain Dependency</category></item><item><title>Microsoft&apos;s Post-Quantum Cryptography Acceleration: A 2029 Shift</title><link>https://runtimerebel.com/blog/microsoft-s-post-quantum-cryptography-acceleration-a-2029-shift</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-s-post-quantum-cryptography-acceleration-a-2029-shift</guid><description>Microsoft accelerates its post-quantum cryptography (PQC) timeline to 2029, urging security professionals to assess current encryption standards and prepare for…</description><pubDate>Wed, 01 Jul 2026 13:04:40 GMT</pubDate><category>Post Quantum Cryptography</category><category>PQC</category><category>Quantum Computing</category><category>Microsoft</category><category>Encryption</category><category>Cryptography Roadmap</category><category>Quantum Safe</category></item><item><title>AI Agents Vulnerable to Data Leak via Poisoned MCP Tools</title><link>https://runtimerebel.com/blog/ai-agents-vulnerable-to-data-leak-via-poisoned-mcp-tools</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agents-vulnerable-to-data-leak-via-poisoned-mcp-tools</guid><description>Microsoft warns that malicious tool descriptions for AI agents can lead to stealthy data exfiltration, bypassing security controls by mimicking routine actions.</description><pubDate>Wed, 01 Jul 2026 01:02:51 GMT</pubDate><category>AI Agents</category><category>Data Exfiltration</category><category>Supply Chain Attack</category><category>Microsoft</category><category>Prompt Injection</category></item><item><title>Windows 10 ESU Extended to 2027: Security Implications</title><link>https://runtimerebel.com/blog/windows-10-esu-extended-to-2027-security-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-10-esu-extended-to-2027-security-implications</guid><description>Microsoft extends free Windows 10 Extended Security Updates (ESU) for consumers until October 2027. Understand the security implications and planning for end-of-life.</description><pubDate>Thu, 25 Jun 2026 20:47:57 GMT</pubDate><category>Windows 10</category><category>ESU</category><category>Microsoft</category><category>End of Life</category><category>Security Updates</category></item><item><title>Amadey &amp; StealC Malware C2 Infrastructure Disrupted</title><link>https://runtimerebel.com/blog/amadey-stealc-malware-c2-infrastructure-disrupted</link><guid isPermaLink="true">https://runtimerebel.com/blog/amadey-stealc-malware-c2-infrastructure-disrupted</guid><description>Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.</description><pubDate>Wed, 24 Jun 2026 16:52:14 GMT</pubDate><category>Amadey</category><category>StealC</category><category>Malware</category><category>Botnet</category><category>Infostealer</category><category>Cybercrime</category><category>C2 Takedown</category><category>Microsoft</category></item><item><title>Microsoft AutoGen Studio RCE via AutoJack Flaw — Patch Now</title><link>https://runtimerebel.com/blog/microsoft-autogen-studio-rce-via-autojack-flaw-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-autogen-studio-rce-via-autojack-flaw-patch-now</guid><description>Microsoft patched the AutoJack vulnerability chain in AutoGen Studio, enabling remote code execution through malicious AI agent manipulation.</description><pubDate>Mon, 22 Jun 2026 17:37:07 GMT</pubDate><category>AutoGen Studio</category><category>AutoJack</category><category>Microsoft</category><category>RCE</category><category>AI Security</category></item><item><title>Microsoft Resolves Windows Update Failures with WUSA via Network Share</title><link>https://runtimerebel.com/blog/microsoft-resolves-windows-update-failures-with-wusa-via-network-share</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-resolves-windows-update-failures-with-wusa-via-network-share</guid><description>Microsoft has fixed an issue causing Windows updates released since May 2024 to fail when installed via the WUSA installer from a network share.</description><pubDate>Fri, 12 Jun 2026 13:19:59 GMT</pubDate><category>Windows Update</category><category>WUSA</category><category>Microsoft</category><category>Patch Management</category><category>Network Share</category></item><item><title>June 2026 Patch Tuesday: Microsoft Fixes 200 Flaws — Patch Now</title><link>https://runtimerebel.com/blog/june-2026-patch-tuesday-microsoft-fixes-200-flaws-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/june-2026-patch-tuesday-microsoft-fixes-200-flaws-patch-now</guid><description>Microsoft’s June 2026 Patch Tuesday addresses a record-breaking 200 vulnerabilities, including 36 critical flaws and several with public exploit code.</description><pubDate>Thu, 11 Jun 2026 09:40:38 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Windows Security</category><category>RCE</category><category>Exploit Code</category></item><item><title>Windows Server 2025 BitLocker Recovery Bug: Mitigation Guide</title><link>https://runtimerebel.com/blog/windows-server-2025-bitlocker-recovery-bug-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-server-2025-bitlocker-recovery-bug-mitigation-guide</guid><description>Microsoft resolves a Windows Server 2025 bug causing systems to boot into BitLocker recovery modes following recent security updates. Patching guidance inside.</description><pubDate>Thu, 11 Jun 2026 09:37:45 GMT</pubDate><category>Windows Server 2025</category><category>BitLocker</category><category>Microsoft</category><category>Boot Loop</category><category>KB5041160</category></item><item><title>GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware</title><link>https://runtimerebel.com/blog/github-supply-chain-disruption-microsoft-repos-abused-to-host-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-supply-chain-disruption-microsoft-repos-abused-to-host-malware</guid><description>GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.</description><pubDate>Tue, 09 Jun 2026 17:00:46 GMT</pubDate><category>GitHub</category><category>Microsoft</category><category>Supply Chain Attack</category><category>Infostealer</category><category>DevSecOps</category></item><item><title>Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis</title><link>https://runtimerebel.com/blog/miasma-compromises-73-microsoft-github-repos-incident-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/miasma-compromises-73-microsoft-github-repos-incident-analysis</guid><description>Microsoft restores some GitHub repositories after 73 projects were hit by Miasma&apos;s supply chain attack to inject information stealers. Learn detection steps.</description><pubDate>Tue, 09 Jun 2026 17:00:07 GMT</pubDate><category>GitHub</category><category>Miasma</category><category>Microsoft</category><category>Supply Chain Attack</category><category>Information Stealer</category><category>Open Source Security</category></item><item><title>VS Code Extension Auto-Update Delay: Mitigating Supply Chain Attacks</title><link>https://runtimerebel.com/blog/vs-code-extension-auto-update-delay-mitigating-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/vs-code-extension-auto-update-delay-mitigating-supply-chain-attacks</guid><description>Microsoft introduces a two-hour delay for VS Code extension auto-updates to prevent rapid compromise during software supply chain attacks.</description><pubDate>Mon, 08 Jun 2026 09:44:07 GMT</pubDate><category>Visual Studio Code</category><category>Microsoft</category><category>Supply Chain Security</category><category>IDE Extensions</category></item><item><title>Microsoft Intelligent Terminal: AI Integration and Security Risks</title><link>https://runtimerebel.com/blog/microsoft-intelligent-terminal-ai-integration-and-security-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-intelligent-terminal-ai-integration-and-security-risks</guid><description>An analysis of Microsoft&apos;s Intelligent Terminal fork. Explore technical architecture, LLM data privacy risks, and securing AI-integrated terminal environments.</description><pubDate>Mon, 08 Jun 2026 01:03:44 GMT</pubDate><category>Microsoft</category><category>Windows Terminal</category><category>Artificial Intelligence</category><category>LLM Security</category><category>Intelligent Terminal</category></item><item><title>Microsoft Rust-Based Coreutils for Windows: Security Analysis</title><link>https://runtimerebel.com/blog/microsoft-rust-based-coreutils-for-windows-security-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-rust-based-coreutils-for-windows-security-analysis</guid><description>Microsoft is adopting Rust-based Coreutils for Windows, offering a memory-safe alternative to legacy GnuWin32 tools. Learn about the security implications.</description><pubDate>Thu, 04 Jun 2026 09:27:24 GMT</pubDate><category>Microsoft</category><category>Rust</category><category>Coreutils</category><category>Memory Safety</category><category>Windows Security</category></item><item><title>Microsoft Coreutils for Windows: Security and Memory Safety Analysis</title><link>https://runtimerebel.com/blog/microsoft-coreutils-for-windows-security-and-memory-safety-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-coreutils-for-windows-security-and-memory-safety-analysis</guid><description>Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.</description><pubDate>Wed, 03 Jun 2026 01:09:39 GMT</pubDate><category>Microsoft</category><category>Coreutils</category><category>Rust</category><category>Windows Security</category><category>Living-off-the-Land</category></item><item><title>Misconfigured MSAL for Android Exposes Microsoft Account Tokens</title><link>https://runtimerebel.com/blog/misconfigured-msal-for-android-exposes-microsoft-account-tokens</link><guid isPermaLink="true">https://runtimerebel.com/blog/misconfigured-msal-for-android-exposes-microsoft-account-tokens</guid><description>A vulnerability in the Microsoft Authentication Library for Android allowed unauthorized apps to intercept OAuth tokens, impacting billions of users.</description><pubDate>Tue, 02 Jun 2026 17:39:32 GMT</pubDate><category>Microsoft</category><category>Android Security</category><category>Msal</category><category>Token Theft</category><category>Identity Management</category></item><item><title>Microsoft&apos;s Zero-Day Disclosure Stance Sparks Industry Debate</title><link>https://runtimerebel.com/blog/microsoft-s-zero-day-disclosure-stance-sparks-industry-debate</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-s-zero-day-disclosure-stance-sparks-industry-debate</guid><description>Microsoft&apos;s legal threats against a researcher for Zero-Day exploit disclosure spark industry backlash, prompting scrutiny of responsible disclosure practices.</description><pubDate>Tue, 02 Jun 2026 05:41:09 GMT</pubDate><category>Microsoft</category><category>Zero-Day</category><category>Vulnerability Disclosure</category><category>Legal Threats</category><category>Security Research</category><category>Responsible Disclosure</category></item><item><title>CVE-2020-1472: How Attackers Exploit Windows Netlogon RCE — Patch Now</title><link>https://runtimerebel.com/blog/cve-2020-1472-how-attackers-exploit-windows-netlogon-rce-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2020-1472-how-attackers-exploit-windows-netlogon-rce-patch-now</guid><description>Threat actors are actively exploiting Zerologon (CVE-2020-1472), a critical Windows Netlogon RCE vulnerability that allows for full domain takeover.</description><pubDate>Mon, 01 Jun 2026 14:14:13 GMT</pubDate><category>CVE-2020-1472</category><category>Zerologon</category><category>Microsoft</category><category>Active Directory</category><category>Domain Controller</category></item><item><title>Microsoft Condemns Public Zero-Day Disclosures, Advocates CVD</title><link>https://runtimerebel.com/blog/microsoft-condemns-public-zero-day-disclosures-advocates-cvd</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-condemns-public-zero-day-disclosures-advocates-cvd</guid><description>Microsoft reiterates strong support for Coordinated Vulnerability Disclosure, criticizing immediate public zero-day disclosures after a researcher&apos;s account removal.</description><pubDate>Thu, 28 May 2026 17:22:04 GMT</pubDate><category>Zero-Day</category><category>Coordinated Vulnerability Disclosure</category><category>Microsoft</category><category>Security Research</category><category>Responsible Disclosure</category></item><item><title>Windows 11 KB5089573: Performance and Reliability Fixes for 24H2/25H2</title><link>https://runtimerebel.com/blog/windows-11-kb5089573-performance-and-reliability-fixes-for-24h2-25h2</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-11-kb5089573-performance-and-reliability-fixes-for-24h2-25h2</guid><description>Microsoft releases KB5089573 preview for Windows 11 24H2 and 25H2, addressing Task Manager bugs, ReFS performance issues, and Sandbox stability errors.</description><pubDate>Wed, 27 May 2026 09:17:12 GMT</pubDate><category>Windows 11</category><category>KB5089573</category><category>24H2</category><category>ReFS</category><category>Microsoft</category></item><item><title>CVE-2026-45659: SharePoint RCE via Deserialization - Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-via-deserialization-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-45659-sharepoint-rce-via-deserialization-patch-now</guid><description>Microsoft addresses CVE-2026-45659, a high-severity RCE flaw in SharePoint Server caused by untrusted data deserialization. Learn how to mitigate this risk.</description><pubDate>Tue, 26 May 2026 13:10:28 GMT</pubDate><category>CVE-2026-45659</category><category>SharePoint</category><category>RCE</category><category>Microsoft</category><category>Deserialization</category></item><item><title>YellowKey BitLocker Bypass: Microsoft Mitigates Data Access</title><link>https://runtimerebel.com/blog/yellowkey-bitlocker-bypass-microsoft-mitigates-data-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/yellowkey-bitlocker-bypass-microsoft-mitigates-data-access</guid><description>Microsoft addresses the &apos;YellowKey&apos; BitLocker bypass, preventing unauthorized data access via the FsTx Auto Recovery Utility in WinRE. Understand the threat.</description><pubDate>Wed, 20 May 2026 17:13:27 GMT</pubDate><category>YellowKey</category><category>BitLocker</category><category>WinRE</category><category>Microsoft</category><category>Data Encryption Bypass</category></item><item><title>YellowKey Zero-Day: Mitigating BitLocker Encryption Bypasses in Windows</title><link>https://runtimerebel.com/blog/yellowkey-zero-day-mitigating-bitlocker-encryption-bypasses-in-windows</link><guid isPermaLink="true">https://runtimerebel.com/blog/yellowkey-zero-day-mitigating-bitlocker-encryption-bypasses-in-windows</guid><description>Microsoft releases mitigation guidance for the YellowKey zero-day, a Windows BitLocker vulnerability allowing unauthorized access to encrypted data volumes.</description><pubDate>Wed, 20 May 2026 09:16:25 GMT</pubDate><category>Windows</category><category>BitLocker</category><category>YellowKey</category><category>Zero-Day</category><category>Encryption</category><category>Microsoft</category></item><item><title>Microsoft Disrupts MSaaS Operation Abusing Artifact Signing Service</title><link>https://runtimerebel.com/blog/microsoft-disrupts-msaas-operation-abusing-artifact-signing-service</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-disrupts-msaas-operation-abusing-artifact-signing-service</guid><description>Microsoft shuts down a malware-signing-as-a-service provider that leveraged fraudulent certificates to bypass security controls for ransomware groups.</description><pubDate>Wed, 20 May 2026 00:58:59 GMT</pubDate><category>Microsoft</category><category>Storm 0324</category><category>Code Signing</category><category>Ransomware</category><category>Malware as a Service</category></item><item><title>Microsoft&apos;s 2026 Plan: Enhancing Windows 11 Driver Quality and Security</title><link>https://runtimerebel.com/blog/microsoft-s-2026-plan-enhancing-windows-11-driver-quality-and-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-s-2026-plan-enhancing-windows-11-driver-quality-and-security</guid><description>Microsoft outlines plans for 2026 to significantly enhance Windows 11 driver quality, aiming to bolster system stability and security from the core up.</description><pubDate>Tue, 19 May 2026 17:03:59 GMT</pubDate><category>Windows 11</category><category>Driver Quality</category><category>Microsoft</category><category>Operating System Security</category><category>Hardware Security</category></item><item><title>Windows Update Failures in Restricted Networks via January 2025 Patch</title><link>https://runtimerebel.com/blog/windows-update-failures-in-restricted-networks-via-january-2025-patch</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-update-failures-in-restricted-networks-via-january-2025-patch</guid><description>Microsoft confirms January 2025 non-security updates cause Windows Update failures in restricted networks. Learn how to resolve metadata service connection errors.</description><pubDate>Tue, 19 May 2026 13:18:44 GMT</pubDate><category>Windows Update</category><category>Microsoft</category><category>Windows Server 2022</category><category>Restricted Networks</category><category>Enterprise Security</category></item><item><title>Azure Backup for AKS Vulnerability: Risks of Silent Patches</title><link>https://runtimerebel.com/blog/azure-backup-for-aks-vulnerability-risks-of-silent-patches</link><guid isPermaLink="true">https://runtimerebel.com/blog/azure-backup-for-aks-vulnerability-risks-of-silent-patches</guid><description>A reported Azure Backup for AKS vulnerability allowed potential cluster compromise. Learn why Microsoft rejected the report and the impact of silent fixes.</description><pubDate>Sun, 17 May 2026 00:54:57 GMT</pubDate><category>Azure</category><category>AKS</category><category>Kubernetes</category><category>Microsoft</category><category>Cloud Security</category></item><item><title>Microsoft Introduces Remote Rollback for Faulty Windows Drivers</title><link>https://runtimerebel.com/blog/microsoft-introduces-remote-rollback-for-faulty-windows-drivers</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-introduces-remote-rollback-for-faulty-windows-drivers</guid><description>Microsoft expands its Known Issue Rollback capability to Windows drivers, allowing remote remediation of faulty updates that cause boot loops or crashes.</description><pubDate>Fri, 15 May 2026 12:46:02 GMT</pubDate><category>Microsoft</category><category>Windows Update</category><category>Driver Security</category><category>Patch Management</category></item><item><title>Microsoft and Palo Alto Networks Use AI to Identify Dozens of Vulnerabilities</title><link>https://runtimerebel.com/blog/microsoft-and-palo-alto-networks-use-ai-to-identify-dozens-of-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-and-palo-alto-networks-use-ai-to-identify-dozens-of-vulnerabilities</guid><description>Microsoft and Palo Alto Networks leverage AI-powered tools MDASH and Mythos to identify dozens of critical software vulnerabilities before exploitation.</description><pubDate>Wed, 13 May 2026 16:53:28 GMT</pubDate><category>Microsoft</category><category>Palo Alto Networks</category><category>AI</category><category>Vulnerability Discovery</category><category>MDASH</category><category>Mythos</category></item><item><title>Microsoft MDASH AI Discovers 16 Windows Vulnerabilities</title><link>https://runtimerebel.com/blog/microsoft-mdash-ai-discovers-16-windows-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-mdash-ai-discovers-16-windows-vulnerabilities</guid><description>Microsoft reveals MDASH, a new AI-driven agentic scanning harness that discovered 16 vulnerabilities in Windows, now fixed in recent Patch Tuesday updates.</description><pubDate>Wed, 13 May 2026 16:52:01 GMT</pubDate><category>Microsoft</category><category>MDASH</category><category>Windows Security</category><category>AI Security</category><category>Patch Tuesday</category></item></channel></rss>