Security researcher takes over a subdomain that Windows 8 and Windows 10 use to deliver RSS-based news and updates to Live Tiles
Subdomain currently in the possession of a German security researcher, preventing any abuse. — Microsoft has lost control over a crucial subdomain …
Context & Ripple Effects
This is at least the second time a Microsoft authentication-or-delivery domain has slipped out of the company's hands: in 2018 a misconfigured domain opened a path into Office accounts, and Microsoft has itself used legal means to grab lookalike domains, including the livemicrosoft.net seizure that cut off Fancy Bear's malware servers. This time the lapsed asset is a subdomain feeding RSS-based news to Live Tiles on Windows 8 and Windows 10.
The difference is who got there first: a German researcher holds the subdomain and is preventing abuse rather than exploiting it, which turns an expired-infrastructure story into a live test of how much of Windows' tile-content pipeline still depends on unmanaged DNS.
First-order effects
- Live Tiles on Windows 8 and Windows 10 lose their intended news-and-updates feed, since the subdomain delivering that RSS content now answers to a third party instead of Microsoft.
- Microsoft must either reclaim the subdomain through registrar or legal channels or permanently retire the endpoint, because every remaining Live Tiles client still resolves to infrastructure it no longer controls.
Second-order effects
- Had a malicious actor registered the subdomain first, the same RSS pipe would have delivered attacker-chosen content straight onto users' Start screens — a reminder that Microsoft's own domain-seizure playbook against Fancy Bear applies equally to its abandoned assets.
- The lapse pressures Microsoft to audit other aging subdomains tied to legacy features, the same class of misconfiguration that produced the 2018 Office login exposure.
Third-order effects
- If the pattern holds, long-lived operating systems accumulate orphaned network endpoints faster than they retire them, making DNS hygiene over legacy features a standing part of platform security rather than a one-off cleanup.
- Domain control keeps proving to be a security boundary in both directions — Microsoft seizing adversaries' domains while its own expire into researchers' hands — pushing registrars and platform vendors toward tighter lifecycle management of feature-specific hostnames.
The trend: As Windows carries legacy features like Live Tiles far past their prime, forgotten subdomains keep resurfacing as a recurring takeover risk that sits between Microsoft's defensive domain seizures and its own lapses.