56 Security Flaws Fixed by Microsoft, Including Actively Exploited Bug
Microsoft has rolled out its final set of security updates for 2025, fixing 56 vulnerabilities in Windows, including one that has already been exploited by hackers.
Of these issues, three are critical and the rest are considered important. The problems affect a wide range of Windows features and could allow attackers to take control of computers or access sensitive information if left unpatched.
One of the most serious flaws affects the Cloud Files feature, used by services like OneDrive and Google Drive. Hackers could exploit this flaw to gain full control of a computer, although they would need to first gain access to the system through other means. Because of its severity, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to install the patch by December 30, 2025.
Two other notable issues involve Windows PowerShell and GitHub Copilot for JetBrains, which could allow hackers to run harmful commands if a user is tricked into executing them.
In total, Microsoft has patched 1,275 security flaws this year, marking a record second year in a row of fixing over 1,000 vulnerabilities.
Other major tech companies, including Adobe, Google, Intel, Cisco, and Zoom, have also released updates to fix security problems in their products. Experts urge users and organizations to install the latest updates immediately to stay protected.
Source: https://thehackernews.com/2025/12/microsoft-issues-security-fixes-for-56.html