/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Microsoft patches the Follina Windows zero-day, which let hackers execute malicious PowerShell commands and had been exploited by state-backed actors

Microsoft has released security updates with the June 2022 cumulative Windows Updates to address a critical Windows zero-day vulnerability known …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

The flaw had been reported to Microsoft in April and was described as critical while still unpatched in late May; the June update closes that exposed interval after an RCE exploit was reported active in the wild. It also follows a history in which a prior Windows zero-day patch did not fully resolve the vulnerability, making remediation quality as important as release speed.

First-order effects

  • Windows users and administrators can deploy the June cumulative updates to remove the Follina route used to launch malicious PowerShell commands.
  • State-backed actors exploiting Follina lose a known Windows execution path on systems that receive the update.

Second-order effects

  • Enterprise security teams must prioritize update deployment and verify coverage, since an earlier Microsoft zero-day fix required adjustments before the underlying issue was resolved.
  • Attackers relying on PowerShell-based execution must shift toward other unpatched access or execution techniques against updated Windows estates.

Third-order effects

  • Repeated Windows zero-day disclosures and incomplete-fix episodes push vulnerability response toward faster patch adoption paired with validation, rather than treating Patch Tuesday deployment as sufficient proof of remediation.

The trend: Windows security operations are becoming a continuous contest between actively exploited flaws, vendor patch cadence, and customers' ability to validate fixes quickly.

Discussion

  • @dangoodin001 Dan Goodin on x
    Microsoft has mishandled several recent vulnerability disclosures, and the missteps are putting the Internet at unnecessary risk. In 1 case, Microsoft took 5 months and 3 patches to fix the critical SynLapse vulnerability in Azure because failed to grasp the scope of the threat. …
  • @arstechnica @arstechnica on x
    Security professionals are calling out Microsoft over its lack of transparency and adequate speed when responding to reports of vulnerabilities threatening customers. https://arstechnica.com/...
  • @zackwhittaker Zack Whittaker on x
    It's 2022 and we're still having to talk about botched and silent security updates. @dangoodin001 https://arstechnica.com/...