Microsoft

Winsage
September 24, 2026
Microsoft has released preview updates for Windows 11 versions 24H2, 25H2, and 26H1 as part of its Week D schedule. Users of versions 24H2 and 25H2 can install the preview cumulative update KB5124010, updating their systems to builds 26100.9550 and 26200.9550, respectively. Enhancements include refinements to File Explorer, support for Emoji 17.0, a new Tips widget, improved desktop backgrounds, enhanced Bluetooth functionality, upgrades to the Settings app, additional touchpad gesture controls, new key remapping options in Copilot, and Wi-Fi support in the Windows Recovery Environment. The final monthly update for Windows 11 version 24H2 will be shipped next month, with the version set to reach the end of its support lifecycle on October 13, 2026. Users of version 26H1 can install the preview cumulative update KB5124006 to upgrade to build 28000.3086. This update includes a resizable Taskbar, customizable Start menu, revamped Windows Search, improvements to File Explorer, enhanced progress indicators, and better app update support.
Winsage
September 24, 2026
Microsoft has introduced updates to its Surface lineup, including the Surface Pro 12-inch (2nd Edition), Surface Laptop 13-inch (2nd Edition), and a new Surface Mouse, all powered by Snapdragon X2 Plus processors. Additionally, Microsoft launched Microsoft Ink Canvas, a pen-first workspace that integrates handwriting, sketches, annotations, and AI functionalities. This follows an update to the Ink Workspace in Windows 11, which allows users to pin applications for easier access to inking experiences. The integration of AI with inking capabilities is part of a broader trend in the tech industry.
Winsage
September 24, 2026
A Chinese threat actor, codenamed UTA0565, has exploited newly disclosed vulnerabilities in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Windows (CVE-2026-85880) through deceptive websites, achieving remote code execution. The attacks were detected on September 3 and 4, 2026, and involved impersonating organizations to mislead victims, particularly targeting Asian government entities with phishing emails related to Hong Kong activist Chow Hang-tung. The phishing messages directed users to fraudulent sites that loaded an HTML element using the BlueMoon exploit kit, which delivered a payload named "chrome_cleanup.exe," associated with the CLEANGULP malware family. This malware allows for command execution, process listing, file uploads and downloads, and uses a hard-coded domain for command-and-control communications. The exploit's widespread use suggests a coordinated effort within the Chinese cyber espionage community, with indications that multiple groups are sharing and weaponizing the exploit.
Winsage
September 24, 2026
Microsoft has informed IT administrators about potential connection challenges with the Always On VPN after the September 2026 Windows 11 security updates. Users may face difficulties connecting to their organization's network, particularly if the VPN is set to automatically attempt an alternative connection method upon failure. Symptoms include connections remaining in a 'Connecting' state or displaying the error message: 'The specified port is already in use.' Affected versions include Windows 11, version 26H1 (KB5124012), version 25H2 (KB5124008), and version 24H2 (KB5124008). A temporary workaround involves adjusting the Always On VPN profile from automatic protocol selection to a single protocol (SSTP or IKEv2). Microsoft is also addressing various other issues related to Hyper-V, Remote Desktop Services, USB audio, and the File History backup feature.
Winsage
September 24, 2026
The Point-in-Time Restore feature in Windows 11 allows users to revert their system to a previous state, but it may result in the loss of recently created files. This feature captures the system's state, including Windows system files, installed applications, and local settings. Restore points are generated automatically every 24 hours, but users can create them manually. However, restoring can erase new documents, recently installed applications, and any settings changes made since the last restore point. Files stored in OneDrive remain unaffected. To verify Point-in-Time Restore settings, users must access the Settings application, select System, and then Recovery. Restore points are retained for up to 72 hours and may be deleted sooner if storage is limited. Windows 11 version 26H2 enables this feature by default for devices with an OS volume of at least 200 GB. Before restoring, users should back up recent work to an external drive. To initiate the restore, access the Windows Recovery Environment, select Troubleshoot, and then Point-in-Time Restore. If files are lost after a restore, 4DDiG Data Recovery Software can help recover deleted files. It scans local drives for files deleted during a rollback or accidental deletion. A robust recovery plan should include using Point-in-Time Restore, OneDrive for daily file protection, and separate backups before significant system changes.
Tech Optimizer
September 23, 2026
A new tool named BigDiskBuster has been released on GitHub, which disrupts Microsoft Defender Antivirus by preventing it from installing updates. It does this by consuming available disk space during the update process, causing Defender to remain on its current version and unable to receive new platform or signature updates. BigDiskBuster operates as a local denial-of-service technique and requires prior access to the target machine to execute. The tool was created by researcher Abdelhamid Naceri, known as Nightmare Eclipse, who has previously worked on similar projects. As of now, there is no CVE identifier, patch, or advisory from Microsoft regarding this issue.
Search