Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: ft Clear Filter

Microsoft Fix Targets Attacks on SharePoint Zero-Day

On Sunday, July 20, Microsoft Corp. issued an emergency security update for a vulnerability in SharePoint Server that is actively being exploited to compromise vulnerable organizations. The patch comes amid reports that malicious hackers have used the Sharepoint flaw to breach U.S. federal and state agencies, universities, and energy companies. In an advisory about the SharePoint security hole, a.k.a. CVE-2025-53770, Microsoft said it is aware of active attacks targeting on-premises SharePoint

Microsoft fixes two SharePoint zero-days under attack, but it's not over - how to patch

sankai/Getty Microsoft has patched two critical zero-day SharePoint security flaws that have already been exploited by hackers to attack vulnerable organizations. Responding to the exploits, the software giant has issued fixes for SharePoint Server Subscription Edition and SharePoint Server 2019 but is still working on a patch for SharePoint Server 2016. Designated as CVE-2025-53771 and CVE-2025-53770, the two vulnerabilities apply only to on-premises versions of SharePoint, so organizations t

Installing apps on Linux? 4 ways it's different than any other OS - and mistakes to avoid

Elyse Betters Picaro / ZDNET When I first started using Linux in the late 90s, there was really only one way to install an application. You would download the app, unpack the archive, run the ./configure command, build the app with make, and then install it with make install. Inevitably, when you ran through that course, you would stumble because of dependencies and have to locate the dependency, run through the same process as you just did (only with the new software), and then find out the ne

Microsoft Sharepoint server vulnerability puts an estimated 10,000 organizations at risk

A major zero-day security vulnerability in Microsoft's widely used SharePoint server software has been exploited by hackers, causing chaos within businesses and government agencies, multiple outlets have reported. Microsoft announced that it had released a new security patch "to mitigate active attacks targeting on-premises [and not online] servers," but the breach has already effected universities, energy companies, federal and state agencies and telecommunications firms. The SharePoint flaw i

New zero-day bug in Microsoft SharePoint under widespread attack

The U.S. federal government and cybersecurity researchers say a newly discovered security bug found in Microsoft’s SharePoint is under attack. U.S. cybersecurity agency CISA sounded the alarm this weekend that hackers were actively exploiting the bug. Microsoft has not yet provided patches for all affected SharePoint versions, leaving customers across the world largely unable to defend against the ongoing intrusions. Microsoft said the bug, known officially as CVE-2025-53771, affects versions

Over 1,000 CrushFTP servers exposed to ongoing hijack attacks

Over 1,000 CrushFTP instances currently exposed online are vulnerable to hijack attacks that exploit a critical security bug, providing admin access to the web interface. The security vulnerability (CVE-2025-54309) is due to mishandled AS2 validation and impacts all CrushFTP versions below 10.8.5 and 11.3.4_23. The vendor tagged the flaw as actively exploited in the wild on July 19th, noting that attacks may have begun earlier, although it has yet to find evidence to confirm this. "July 18th,

Microsoft SharePoint servers are under attack because of a major security flaw

Hackers have exploited vulnerabilities in Microsoft’s SharePoint software, placing tens of thousands of on-premises servers used by global businesses and agencies at risk. Microsoft issued an alert on Saturday disclosing that it was aware of “active attacks,” and that it was working to patch the zero-day exploit. Researchers at Eye Security first identified the vulnerability on July 18th, which allows hackers to access certain on-premises versions of SharePoint and steal keys that can let them

Microsoft wants to fix ‘slow or sluggish’ performance in Windows 11

is a senior editor and author of Notepad , who has been covering all things Microsoft, PC, and tech for over 20 years. Ever since Windows 11 first debuted in October 2021, there have been complaints about its performance on certain types of hardware. Whether it was gaming on new hybrid performance CPUs showing no improvement on Windows 11, or claims that Windows 11 simply feels lethargic compared to Windows 10, Microsoft has tried to fix the problems with updates to the OS. Now, it wants direct

Microsoft releases emergency patches for SharePoint RCE flaws exploited in attacks

Microsoft has released emergency SharePoint security updates for two zero-day vulnerabilities tracked as CVE-2025-53770 and CVE-2025-53771 that have compromised services worldwide in "ToolShell" attacks. In May, during the Berlin Pwn2Own hacking contest, researchers exploited a zero-day vulnerability chain called "ToolShell," which enabled them to achieve remote code execution in Microsoft SharePoint. These flaws were fixed as part of the July Patch Tuesday updates; However, threat actors were

What my mother didn’t talk about (2020)

We did not visit Poland often. Only when someone died. I have not been able to bring part of my mother’s ashes to Poland yet because of the pandemic. They sit in my living room, waiting to join my other dead relatives in her village of Bedoń. I live in California, 3,000 miles away from where I grew up, and when my mother couldn’t sleep she’d call me. I always picked up. “I think I know how I got sick,” she said once. My mother had an aversion to being sick and to anyone knowing about it. Her

Java was not underhyped in 1997 (2021)

Java Criminally Underhyped? Not Back in 1997. Earlier today, a fun little moment of Twitter serendipity alerted me to an article by Jackson Roberts, a computer science student at the University of Colorado, entitled “Java is criminally underhyped”. It’s a really interesting article, and Jackson’s observations correlate with a lot of my own thinking about languages and platforms, although I am squarely in the .NET / CLR camp on that particular front. But Jackson ends his article: I am curious

What My Mother Didn't Talk About (2020)

We did not visit Poland often. Only when someone died. I have not been able to bring part of my mother’s ashes to Poland yet because of the pandemic. They sit in my living room, waiting to join my other dead relatives in her village of Bedoń. I live in California, 3,000 miles away from where I grew up, and when my mother couldn’t sleep she’d call me. I always picked up. “I think I know how I got sick,” she said once. My mother had an aversion to being sick and to anyone knowing about it. Her

Microsoft SharePoint zero-day exploited in RCE attacks, no patch available

A critical zero-day vulnerability in Microsoft SharePoint, tracked as CVE-2025-53770, has been actively exploited since at least July 18th, with no patch available and at least 85 servers already compromised worldwide. In May, Viettel Cyber Security researchers chained two Microsoft SharePoint flaws, CVE-2025-49706 and CVE-2025-49704, in a "ToolShell" attack demonstrated at Pwn2Own Berlin to achieve remote code execution. While Microsoft patched both ToolShell flaws as part of the July Patch T

How the 'Minecraft' Score Became Big Business for Its Composer

In 2009, in between full-time shifts at a local factory, then-19-year-old musician Daniel Rosenfeld composed a score for an independent video game. “It was just a side hustle, maybe not even that. It was a hobby, really,” explains Rosenfeld, who records under the name C418. The game, Minecraft, turned out to be successful beyond Rosenfeld’s wildest dreams. In 2014, Microsoft purchased Minecraft’s Swedish developer, Mojang Studios, for $2.5 billion, and through 2023, it had sold 300 million copi

Astronomers Detect Entirely New Type of Plasma Wave Above Jupiter’s North Pole

Since entering Jupiter’s orbit in 2016, NASA’s Juno spacecraft has been hard at work unveiling the many mysteries of our solar system’s largest planet. And its latest discovery may be one of the most intriguing yet: an entirely new type of plasma wave near Jupiter’s poles. In a paper published Wednesday in Physical Review Letters, astronomers describe an unusual pattern of plasma waves in Jupiter’s magnetosphere—a magnetic “bubble” shielding the planet from external radiation. Jupiter’s excepti

The curious case of the Unix workstation layout

Scroll through the blog: ‹ Newer | List All | Older › The Curious Case of the UNIX workstation layout Posted on 2025-07-19 Contents Background Cathode Ray Dude recently did an excellent video about the history of the PC case, particularly the early- and mid-1990s, and the various mainboard layouts that pre-date the ATX standard. You should watch it. Here it is. The rest of this blog will contain some spoilers for that video. UNIX workstations I have a bunch of 1990's RISC/UNIX workstatio

The Curious Case of the Unix workstation layout

Scroll through the blog: ‹ Newer | List All | Older › The Curious Case of the UNIX workstation layout Posted on 2025-07-19 Contents Background Cathode Ray Dude recently did an excellent video about the history of the PC case, particularly the early- and mid-1990s, and the various mainboard layouts that pre-date the ATX standard. You should watch it. Here it is. The rest of this blog will contain some spoilers for that video. UNIX workstations I have a bunch of 1990's RISC/UNIX workstatio

Microsoft says it will no longer use engineers in China for Department of Defense work

In Brief Following a Pro Publica report that Microsoft was using engineers in China to help maintain cloud computing systems for the U.S. Department of Defense, the company said it’s made changes to ensure this will no longer happen. The existing system reportedly relied on “digital escorts” to supervise the China-based engineers. But according to Pro Publica, those escorts — U.S. citizens with security clearances — sometimes lacked the technical expertise to properly monitor the engineers. I

Microsoft Will Erase Your Passwords in 2 Weeks: What to Do Now

Microsoft is axing passwords starting in August -- and if you use its Authenticator app, you'll want to be prepared. For years, Microsoft Authenticator has been a go-to for managing multifactor authentication and saved passwords. However, starting next month, it will no longer support passwords and will move to passkeys instead. That means your logins will soon rely more on things like PINs, fingerprint scans or facial recognition. Using a passkey can make your account safer, and it's a move I

New CrushFTP zero-day exploited in attacks to hijack servers

CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers. CrushFTP is an enterprise file transfer server used by organizations to securely share and manage files over FTP, SFTP, HTTP/S, and other protocols. According to CrushFTP, threat actors were first detected exploiting the vulnerability on July 18th at 9AM CST, though it may have begun

Debcraft – Easiest way to modify and build Debian packages

Debian packaging is notoriously hard. Far too many new contributors give up while trying, and many long-time contributors leave due to burnout from having to do too many thankless maintenance tasks. Some just skip testing their changes properly because it feels like too much toil. Debcraft is my attempt to solve this by automating all the boring stuff, and making it easier to learn the correct practices and helping new and old packagers better track changes in both source code and build artifac

CrushFTP zero-day exploited in attacks to gain admin access on servers

CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers. CrushFTP is an enterprise file transfer server used by organizations to securely share and manage files over FTP, SFTP, HTTP/S, and other protocols. According to CrushFTP, threat actors were first detected exploiting the vulnerability on July 18th at 9AM CST, though it may have begun

Joby Aviation Has a Bold Plan to Make Flying Cars Real—Fast

Flying cars were supposed to be a fantasy. A punchline. A cartoonish promise from a Jetsons-era past. But Joby Aviation is no longer promising anything. It’s building them. The Santa Cruz, California-based company just unveiled the expansion of its manufacturing facility in Marina, CA, where it now has the capacity to build up to 24 electric air taxis per year. That’s two flying cars a month. With additional capacity ramping up in Dayton, Ohio, and test flights already underway in Dubai, the fu

Microsoft stops relying on Chinese engineers for Pentagon cloud support

Microsoft Chairman and Chief Executive Officer Satya Nadella (L) returns to the stage after a pre-recorded interview during the Microsoft Build conference opening keynote in Seattle, Washington on May 19, 2025. Microsoft on Friday revised its practices to ensure that engineers in China no longer provide technical support to U.S. defense clients using the company's cloud services. The company implemented the changes in an effort to reduce national security and cybersecurity risks stemming from

What the hell is going on with Subnautica 2?

If I had to describe the status of Subnautica 2 in just three words, it would be these: messy, messy, messy. That’s not to say the game itself is in terrible shape — this is actually a pivotal claim in the whole situation — but the relationship between Subnautica series developer Unknown Worlds and its parent company, Krafton, is in shreds. This month alone, Krafton fired the founders and CEO of Unknown Worlds, Subnautica 2 was delayed until 2026 and the ousted leaders filed a lawsuit against Kr

Section 174 is reversed, mostly

Hi, this is Gergely with a bonus, free issue of the Pragmatic Engineer Newsletter. In every issue, I cover Big Tech and startups through the lens of senior engineers and engineering leaders. Today, we get into one out of four topics from last week’s The Pulse issue, which full subscribers received seven days ago. If you’ve been forwarded this email, you can subscribe here. Since early 2024, a tax change in the US named “Section 174” has been plaguing tech companies in the country. It was introd

Microsoft Quietly Pulls the Plug on Its Movies and TV Store

Microsoft abruptly shut down its online movie and TV store. On Friday, the tech giant quietly updated both its general and Xbox support pages to reflect the changes. Users will no longer be able to buy new content from Microsoft.com and the Microsoft Store on Windows and Xbox. Thankfully, Microsoft says if you already own movies or shows through the store you can still watch them via the Movies & TV app on Xbox and Windows devices. Microsoft says technical support will also continue for issues

Microsoft mistakenly tags Windows Firewall error log bug as fixed

Microsoft has mistakenly tagged an ongoing Windows Firewall error message bug as fixed in recent updates, stating that they are still working on a resolution. Earlier this month, Microsoft warned that, starting with the June 2025 Windows 11 preview update, users would see Windows Firewall errors in the Event Viewer. These events would be labeled as event ID 2042 for the Windows Firewall With Advanced Security, and would be generated every time you restart Windows. "The error is found in Event