Microsoft's July security update round addressed more than 600 vulnerabilities across Windows, Office, and Microsoft 365, including two flaws that were already being exploited by attackers before the fix was released.
- What it is: Microsoft's monthly security patch release fixed critical issues including a BitLocker encryption bypass and a flaw in Active Directory Federation Services, both already under active attack. It also fixed a critical privilege escalation bug in Microsoft 365 Copilot and an authorisation flaw in Exchange Online.
- Who is affected: Any business using Windows devices, on-premises Active Directory, Microsoft 365 Copilot, or Exchange Online.
- The risk: The BitLocker and AD FS flaws are already being used in real attacks, meaning unpatched systems are exposed now, not just theoretically vulnerable.
- What to do: Cloud services such as Exchange Online and Copilot are patched automatically by Microsoft. Windows devices and on-premises Active Directory servers need this month's updates installed as soon as possible.
If your systems are on managed patching through us, this update is already scheduled. If you manage your own Windows updates, we recommend applying this month's patches without delay.