
Forbes: Update Windows Now — Microsoft Confirms System Takeover Danger
Forbes included a finding from NetSPI senior security consultant, Joshua Murrell, in a story that warned Microsoft Windows users about critical security vulnerabilities that require immediate updates. Murrell identified and reported on CVE-2025-26685, a vulnerability affecting Microsoft Defender for Identity, a vulnerability that shows the real-world risks that major companies such as Microsoft face.
+ + +
Microsoft users are starting to get all too familiar with being advised to act now, as confirmation of security threat after security threat is made. A Windows secure boot bypass, and attacks exploiting vulnerabilities against Windows 10 and 11 users both require users to update now. That advice is all too clearly warranted as Microsoft has confirmed yet another Windows vulnerability that demands urgent update attention, and this one can lead to a system takeover. Here’s what you need to know about CVE-2025-33073, and what you need to do. Hint: update Windows now!
CVE-2025-26685: A Microsoft Defender Attack Vulnerability For Windows Users
Joshua Murrell, a senior security consultant at NetSPI, has confirmed that CVE-2025-26685, a spoofing vulnerability impacting Microsoft Defender for Identity, can elevate privileges for a successful attacker. It’s important to note that CVE-2025-26685 alone is not enough to undertake an attack on Windows users, but when combined with other vulnerabilities in a chained attack, it becomes part of a potent exploit weaponisation that can lead to escalated privileges in Active Directory environments. In other words, the MDI sensor vulnerability, in conjunction with other vulnerabilities such as Active Directory Certificate Services vulnerabilities or Lightweight Directory Access Protocol relays, to create a domain machine account, according to Murrell. “This is not a part of the MDI sensor vulnerability,” Murrell said, “but an opportunity to demonstrate the impact it has on the environment.”
You can read the full story here.
Explore More News

Forbes: Silverfort’s Launch Signals The Start Of Agentic AI Security Arms Race
Enterprises face new security challenges as autonomous AI agents integrate into workflows, prompting specialized solutions to combat risks today.

NetSPI Named a Minnesota Top Workplace 2025 for Fifth Year in a Row
NetSPI earned a Top Workplaces 2025 award, the Star Tribune’s annual recognition of the best local companies, marking the fifth consecutive year NetSPI has received this prestigious honor.

The Minnesota Star Tribune: There aren’t enough people trained in cybersecurity, so NetSPI started its own program
CEO Aaron Shilts was featured in a Star Tribune article on NetSPI’s in-house training program tackling the cybersecurity talent gap.