/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Security researcher takes over a subdomain that Windows 8 and Windows 10 use to deliver RSS-based news and updates to Live Tiles

Subdomain currently in the possession of a German security researcher, preventing any abuse.  —  Microsoft has lost control over a crucial subdomain …

ZDNet Catalin Cimpanu

Context & Ripple Effects

This is at least the second time a Microsoft authentication-or-delivery domain has slipped out of the company's hands: in 2018 a misconfigured domain opened a path into Office accounts, and Microsoft has itself used legal means to grab lookalike domains, including the livemicrosoft.net seizure that cut off Fancy Bear's malware servers. This time the lapsed asset is a subdomain feeding RSS-based news to Live Tiles on Windows 8 and Windows 10.

The difference is who got there first: a German researcher holds the subdomain and is preventing abuse rather than exploiting it, which turns an expired-infrastructure story into a live test of how much of Windows' tile-content pipeline still depends on unmanaged DNS.

First-order effects

  • Live Tiles on Windows 8 and Windows 10 lose their intended news-and-updates feed, since the subdomain delivering that RSS content now answers to a third party instead of Microsoft.
  • Microsoft must either reclaim the subdomain through registrar or legal channels or permanently retire the endpoint, because every remaining Live Tiles client still resolves to infrastructure it no longer controls.

Second-order effects

  • Had a malicious actor registered the subdomain first, the same RSS pipe would have delivered attacker-chosen content straight onto users' Start screens — a reminder that Microsoft's own domain-seizure playbook against Fancy Bear applies equally to its abandoned assets.
  • The lapse pressures Microsoft to audit other aging subdomains tied to legacy features, the same class of misconfiguration that produced the 2018 Office login exposure.

Third-order effects

  • If the pattern holds, long-lived operating systems accumulate orphaned network endpoints faster than they retire them, making DNS hygiene over legacy features a standing part of platform security rather than a one-off cleanup.
  • Domain control keeps proving to be a security boundary in both directions — Microsoft seizing adversaries' domains while its own expire into researchers' hands — pushing registrars and platform vendors toward tighter lifecycle management of feature-specific hostnames.

The trend: As Windows carries legacy features like Live Tiles far past their prime, forgotten subdomains keep resurfacing as a recurring takeover risk that sits between Microsoft's defensive domain seizures and its own lapses.