Forbes: Update Windows Now — Microsoft Confirms System Takeover Danger
Forbes included a finding from NetSPI senior security consultant, Joshua Murrell, in a story that warned Microsoft Windows users about critical security vulnerabilities that require immediate updates. Murrell identified and reported on CVE-2025-26685, a vulnerability affecting Microsoft Defender for Identity, a vulnerability that shows the real-world risks that major companies such as Microsoft face.
+ + +
Microsoft users are starting to get all too familiar with being advised to act now, as confirmation of security threat after security threat is made. A Windows secure boot bypass, and attacks exploiting vulnerabilities against Windows 10 and 11 users both require users to update now. That advice is all too clearly warranted as Microsoft has confirmed yet another Windows vulnerability that demands urgent update attention, and this one can lead to a system takeover. Here’s what you need to know about CVE-2025-33073, and what you need to do. Hint: update Windows now!
CVE-2025-26685: A Microsoft Defender Attack Vulnerability For Windows Users
Joshua Murrell, a senior security consultant at NetSPI, has confirmed that CVE-2025-26685, a spoofing vulnerability impacting Microsoft Defender for Identity, can elevate privileges for a successful attacker. It’s important to note that CVE-2025-26685 alone is not enough to undertake an attack on Windows users, but when combined with other vulnerabilities in a chained attack, it becomes part of a potent exploit weaponisation that can lead to escalated privileges in Active Directory environments. In other words, the MDI sensor vulnerability, in conjunction with other vulnerabilities such as Active Directory Certificate Services vulnerabilities or Lightweight Directory Access Protocol relays, to create a domain machine account, according to Murrell. “This is not a part of the MDI sensor vulnerability,” Murrell said, “but an opportunity to demonstrate the impact it has on the environment.”
You can read the full story here.
Explore More News
VM Blog: Five Security Shifts that Will Define 2026
Joe Evangelisto outlines several critical shifts demanding executive attention. As organizations move from open AI experimentation to governed application, leaders must implement safeguards to manage data exposure and ensure system integrity.
DataCenter Knowledge: Defending at Scale – The Importance of People in Data Center Security
As the demand for AI, cloud computing, and digital infrastructure drives rapid data center expansion, the importance of robust security measures has never been greater. In a recent conversation, Dalin highlights why human factors remain central to effective data center security, even in an era of advanced technology.
Security Week: Exploring AI-Assisted Social Engineering Attacks to Help Prepare Leaders for What Lies Ahead in 2026
SecurityWeek interviewed NetSPI’s Director of Social Engineering, Patrick Sayler, for Cyber Insights 2026 exploring AI-assisted social engineering attacks to help prepare leaders for what lies ahead in 2026.