惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
T
Tailwind CSS Blog
月光博客
月光博客
爱范儿
爱范儿
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
GbyAI
GbyAI
腾讯CDC
The Cloudflare Blog
人人都是产品经理
人人都是产品经理
MongoDB | Blog
MongoDB | Blog
Microsoft Azure Blog
Microsoft Azure Blog
IT之家
IT之家
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
云风的 BLOG
云风的 BLOG
U
Unit 42
博客园 - 三生石上(FineUI控件)
A
About on SuperTechFans
N
Netflix TechBlog - Medium
Google DeepMind News
Google DeepMind News
雷峰网
雷峰网
L
LangChain Blog

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Microsoft Extends Windows 10 Security Updates for Users U...
Guru Baran · 2026-06-26 · via Cyber Security News

Microsoft has quietly expanded its Windows 10 Extended Security Updates (ESU) program, allowing consumers to receive critical security patches through October 12, 2027, an additional year beyond the program’s originally planned expiration date of October 12, 2026.

Windows 10 officially reached its end of support on October 14, 2025, leaving millions of users globally exposed to potential vulnerabilities without security patches. To ease the transition to Windows 11, Microsoft had initially launched the consumer ESU program to provide a one-year security bridge through October 2026.

However, recognizing that a large portion of the user base has not yet migrated, Microsoft has now silently updated its ESU program page to extend coverage by an additional full year. Users who are already enrolled need not take any action; their coverage automatically continues through the new end date.

What Is the Windows 10 ESU Program?

The Extended Security Updates program provides enrolled Windows 10 devices with critical and important security updates as classified by the Microsoft Security Response Center (MSRC). The program exclusively covers Windows 10, version 22H2, including Home, Professional, Pro Education, and Workstations editions.

Importantly, ESU enrollment does not include feature updates, product enhancements, or access to technical support. Its sole purpose is to reduce exposure to malware and cyberattacks during the transition period.

To qualify for the consumer ESU program, devices must meet the following requirements:

  • Must be running Windows 10, version 22H2 (Home, Pro, Pro Education, or Workstations edition).
  • Must have the latest Windows updates installed prior to enrollment.
  • The Microsoft account used to sign in must have administrator privileges.
  • The Microsoft account cannot be a child account.
  • Devices in kiosk mode, joined to an Active Directory domain, or enrolled in a Mobile Device Management (MDM) solution, are ineligible for the consumer ESU program.

Microsoft offers three enrollment tiers for the consumer ESU program:

  • Free — for users who have PC Settings Sync (Windows Backup) enabled.
  • 1,000 Microsoft Rewards points are redeemable for enrollment.
  • $30 USD (one-time purchase, plus applicable local taxes) for users without Rewards points or sync enabled.

A single ESU license can be applied to up to 10 devices under the same Microsoft account, making it a cost-effective option for households with multiple Windows 10 machines.

Enrolling is straightforward: navigate to Settings > Update & Security > Windows Update. If the device meets all prerequisites, an “Enroll now” option will appear under the end-of-support notification. Users signing in with a local account will be prompted to authenticate with their Microsoft account to complete enrollment.

Security professionals and IT administrators should treat this extension as a temporary risk-mitigation measure, not a permanent solution. Unenrolled devices running Windows 10 remain highly vulnerable to exploitation, ransomware, and zero-day attacks without active patch coverage.

Organizations managing enterprise deployments should evaluate the commercial ESU pathway or accelerate Windows 11 migration planning to avoid compounding technical debt and security exposure.

Windows Secure Boot Certificates to Expire – What IT Teams Should Do Before the Deadline.

Guru Baran

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.