Microsoft Fabric Flips Item Recovery On By Default, and That Is a Good Thing
Microsoft is about to make a quiet change to Fabric that most tenants will never notice, but it will save a few of them from real pain. Starting August 23, 2026, Fabric will enable Item Recovery by default for any tenant that has not explicitly configured the setting. For supported item types, that means a […]
LegacyHive Zero-Day Bypasses July’s Record Patch Tuesday
Microsoft shipped its largest Patch Tuesday in history on July 14, 2026, fixing 622 CVEs. Within hours, a security researcher released a proof-of-concept for a Windows privilege escalation bug that the massive update did not fix. Named LegacyHive, the exploit targets the Windows User Profile Service and lets a standard user reach administrator privileges on […]
The decade-long hole in Microsoft Secure Boot and what to do about it
Security researchers at ESET have detailed a hole in Microsoft Secure Boot that was quietly exploitable for over a decade. The finding is uncomfortable because Secure Boot is one of the foundational trust mechanisms on modern PCs, and the bypass hinges on eleven old firmware shims that Microsoft still signed and that UEFI systems continued […]
Kremlin Hackers Exploit Max-Severity Exchange Flaw to Backdoor Unpatched Networks
Russian state hackers are actively exploiting a maximum-severity flaw in Microsoft Exchange Server to backdoor unpatched networks, according to Proofpoint researchers. The attacks are notable less for the vulnerability itself and more for what happens when it is triggered: opening an email is enough to get you compromised, and the resulting backdoor survives both credential […]
Forgotten UEFI shims broke Secure Boot for 13 years
Researchers at ESET discovered that Microsoft’s Secure Boot has been effectively broken for most of its existence. The culprit is a set of forgotten UEFI shim bootloaders that Microsoft signed years ago and never revoked. Eleven specific shims, all version 0.9 and below, can be used to bypass Secure Boot on virtually any system, and […]
Microsoft Secure Boot Bypassed by Decade-Old Unsigned Bootloaders
ESET researchers have found 11 old Microsoft-signed UEFI shim bootloaders that let attackers bypass Secure Boot entirely. The bootloaders date back to 2013, version 0.9 and earlier, and Microsoft never revoked their signatures. Secure Boot was introduced with Windows 8 in 2012 as a hardware-level protection. It checks that only trusted, signed bootloaders run during […]