vulnerabilities

Winsage
July 24, 2026
LG has decided to stop the McAfee pop-up notifications in its Monitor App Installer following intervention from Pavan Davuluri, head of Windows at Microsoft. Tim Sweeney, CEO of Epic Games, had previously highlighted the annoyance caused by these advertisements. The pop-ups appeared when certain LG devices, like the LG UltraGear, were connected to a Windows device for the first time. Windows allows hardware manufacturers to silently add software during external device installations, which can lead to advertising and mixed user experiences. LG is not exploiting vulnerabilities for software installation, and the automatic process is well-documented. This incident raises questions about review procedures and the implications of advertising within the Windows ecosystem.
AppWizard
July 23, 2026
GitHub will reject command-line support bundle uploads from outdated versions of GitHub Enterprise Server lacking security patches starting August 18, 2026. The npm package @copilot-mcp/apex has been identified as a post-install dropper that installs a macOS infostealer, phishing for sensitive information and maintaining a connection to an attacker's server. A rogue extension on the Microsoft Visual Studio Code marketplace, "Markdown All Pro," impersonates a legitimate tool and opens a backdoor after installation. A phishing campaign targeting Portuguese users delivers the Lampion banking malware, which has been active since 2019. DoubleVerify reports a rise in "AfterCall" apps that exploit user permissions for ad fraud. The GhostCommit attack method hides malicious instructions within PNG images in pull requests. The U.S. government has updated its advisory on Iranian-affiliated cyber activity targeting operational technology devices. An Android app posing as a civil defense alert system has been found to contain malware for data harvesting. An Iranian threat actor is distributing MarkiRAT malware through fake applications. An analysis of 28 AI-coded applications revealed 434 vulnerabilities, prompting Cisco to introduce Antares to identify vulnerabilities in codebases. A Russian-speaking threat actor is dismantling guardrails on AI models to create offensive tools.
Winsage
July 23, 2026
Windows 11 is installed on 78.8% of Windows computers, while 16.9% of users remain on Windows 10. Microsoft ended support for Windows 10 in October 2025, with an extension until 2027. Windows 10 has 1,903 active Common Vulnerabilities and Exposures (CVEs), 2.9 times more than Windows 11, which has 652 CVEs. Of the active CVEs on Windows 10, 66.6% are classified as high or critical risk, with 2.4% actively exploited. Small businesses show the most significant lag in upgrading, with 21.4% still using Windows 10, while two-thirds of large enterprises have moved to Windows 11. The cost of upgrading is a primary barrier for smaller companies.
Winsage
July 22, 2026
A study by Lansweeper found that Windows 10 PCs have an average of 1,903 active security vulnerabilities, while Windows 11 systems have only 652 vulnerabilities. As of June 2026, nearly 20% of Windows PCs in the U.S. are still using Windows 10, despite Microsoft ceasing regular updates for it. Users can enroll in the Extended Security Updates (ESU) program for continued security updates until October 12, 2027. Security experts have urged users to upgrade to Windows 11 due to increasing vulnerabilities in Windows 10, while some data privacy experts recommend staying with Windows 10 for as long as possible.
Winsage
July 22, 2026
Approximately 17% of all Windows client devices are still running Windows 10, equating to about one in six machines. Windows 11 accounts for 78% of Windows devices, with third-party trackers indicating it surpassed 70% of desktop share as of February 2026. Official support for Windows 10 ended in October 2025, but Microsoft’s Extended Security Updates (ESU) program will provide patches until October 2027 for eligible devices. A typical Windows 10 device has an average of 1,903 active security vulnerabilities, nearly three times the 652 CVE-tracked flaws found on a Windows 11 machine. 66% of Windows 10 vulnerabilities are classified as "high" or "critical." Small and medium enterprises have 21.4% of their Windows devices still on Windows 10, while larger enterprises have 16.6%. The healthcare and pharmaceuticals sectors have 23% of devices on Windows 10, followed by consumer and retail at 22%, and manufacturing at 18%. Lansweeper is urging organizations to enroll in the ESU program and address reasons for remaining on Windows 10 as 2026 approaches.
Winsage
July 21, 2026
Windows 10 officially reached its end of support in October 2025. Windows 11 has a 78.8% share of Windows devices, while Windows 10 maintains 16.9%. A typical Windows 10 device has an average of 1,903 active Common Vulnerabilities and Exposures (CVEs), compared to 652 on Windows 11, with 66.6% of Windows 10 vulnerabilities rated as high or critical. Microsoft's Extended Security Updates (ESU) program has been extended until October 12, 2027, providing critical security patches for eligible Windows 10 devices. The rise in memory and storage prices has made older Windows 10-compatible hardware more economically viable for some users.
Search