Recent Posts

Pages: [1] 2 3 ... 10
1

Windows 11's biggest update this month is a dozen of small fixes

Microsoft has started rolling out the August 2026 Patch Tuesday update for Windows 11, and after going through the full changelog and testing everything, I feel there is no headline feature this time. It is a quality-of-life update with dozens of small fixes and refinements.

The update ships as Windows 11 KB5121003 (OS build 26200.9165 and 26100.9165) for Windows 11 version 25H2 and 24H2, and takes everything from the July 28 optional preview, KB5101684, and adds it into the mandatory August security release.



Voice Access gets its biggest upgrade in a while, File Explorer finally shows file sizes properly, Windows Hello adds support for external fingerprint readers, and there is a long list of smaller reliability work across the taskbar, Start menu, networking, and power settings.

Like every recent release, and I feel like a broken record here, this update also arrives in two phases. A gradual rollout hands features to devices over time through Microsoft’s Controlled Feature Rollout system, so some of what is listed below may take extra days to show up after you install. A normal rollout goes to every eligible device at once and covers the security-critical pieces, including Secure Boot.

Speaking of which, Microsoft confirms that Secure Boot certificates from 2011 keep expiring in stages through 2026, and that PCs still waiting on the newer 2023 certificates will keep booting and updating normally in the meantime. If you have not checked your Secure Boot status recently, it is worth a look.



Windows 11 version 24H2 Home and Pro reach end of updates on October 13, 2026, with Enterprise and Education supported until October 2027. 24H2 is already on the list of 15 products Microsoft is retiring in 2026, and Microsoft is force-installing 25H2 on eligible Home devices to keep them up-to-date.

What’s new in the Windows 11 August 2026 Patch Tuesday update

Here is a quick list of everything coming to your PC with the mandatory August update:

   • Voice Access adds Voice Isolation, Korean language support, and more reliable startup.

   • File Explorer shows file sizes in KB, MB, or GB instead of everything in KB.

   • Middle-click now opens a folder in a new tab from the address bar and Home page.

   • Windows Hello Enhanced Sign-in Security works with external, plug-in fingerprint readers.

   • Touchpad gestures add adjustable scroll and zoom speed, plus accelerated scrolling.

   • Taskbar notification badges switch from red to your Windows accent color.

   • You can now remove the Image Generation AI component from supported Copilot+ PCs.

   • Windows Search gets better at handling typos and partial app names.

   • Power and battery settings apply more consistently across sleep, hibernate, and lid-close.

   • Secure Boot certificate rollout keeps expanding to more eligible devices.

Voice Access gets its biggest upgrade in a while with Voice Isolation

The only “big” new change this month is on Voice Access, and it is part of Microsoft’s focus on voice as a priority area for 2026. Voice Access now has three speech recognition modes under Voice Access settings > Improve speech recognition:

1. Voice Isolation filters out other speakers and background noise, though it needs a one-time voice setup first by going to Voice Access settings > Improve speech recognition and selecting Voice Isolation.



2. Remove background noise only cuts out non-speech sounds like typing or a door closing, with no setup required.

3. No filtering keeps the default microphone input untouched.

I tried Voice Isolation with a podcast playing in the background, and the difference over the default mode was noticeable. Voice Access didn’t pick up any unwanted words from the audio, which had been a real problem before this update.

Voice Access also adds Korean language support, and Microsoft also improved the reliability of starting Voice Access. Interestingly, Windows chief Pavan Davuluri wrote in his July update on Windows quality that voice was one of the areas the team has been focused on since March.

File Explorer finally shows file sizes in the right units

File Explorer’s Details view has shown every file size in kilobytes for years, regardless of whether the file was 10KB or 10GB, and all of us have gotten used to it by now.

Anyway, with the August Patch Tuesday update, file sizes display using appropriate units, KB, MB, or GB, based on the size of the file, so a 10MB file no longer shows as 10,000KB.


File Explorer details view size now show appropriate file size

I have always found this oddly frustrating given how basic a fix it is, since converting kilobytes to gigabytes in your head while browsing a drive is not something we want to waste our brain tokens on!

The feature is rolling out gradually, so it may not be immediately visible.

Address bar navigation is also improved. Middle-click now opens a folder in a new tab from both the address bar and the File Explorer Home page, matching how tabbed browsing works elsewhere in Windows.

Microsoft also fixed a grey flash on load and unexpected scrolling to the top of the Home page in certain cases, and file thumbnails in the Recommended section are now crisper.

Windows Search gets better at handling typos for apps

The August update brings forward Search improvements Microsoft has been testing for months. App search now better handles typos, dropped letters, extra characters, and partial names, so a misspelled app name is more likely to show the app you meant to search for.



Searching Windows Settings also improves here, meaning more useful settings should appear higher in the results list.

We first saw the typo-tolerant search behavior in an Insider Experimental build back in June, where searching “pwerp” correctly returned PowerPoint. It is good to see that work reach all PCs now.



Windows Hello Enhanced Sign-in Security now works with external fingerprint readers

Windows Hello Enhanced Sign-in Security, or ESS, previously required a built-in fingerprint sensor. The August update extends ESS to peripheral fingerprint sensors, so desktops and other Windows 11 PCs without a built-in reader, including Copilot+ PCs, can use this more secure sign-in method too.

To set it up, plug in a supported ESS fingerprint reader, go to Settings > Accounts > Sign in options, and follow the enrollment prompts.



Microsoft first disclosed this feature back in January 2026 through KB5074105, and it is only now beginning to roll out to all PCs.

Touchpad gestures add adjustable scroll speed and accelerated scrolling

New gesture controls for precision touchpads come under Settings > Bluetooth & devices > Touchpad. You can adjust the baseline speed for scroll and zoom gestures, and there is a new accelerated scrolling option that speeds up scrolling the more you repeat the gesture, so long documents move faster the longer you keep scrolling.



I did not expect to care about this one, but after using accelerated scrolling on a lengthy PDF I had downloaded, it turned out to be one of the more surprisingly useful small additions in this update. It is the kind of change you only appreciate once you have used it.

You can now remove the Image Generation AI component from Copilot+ PCs

Supported Copilot+ PCs can now uninstall the Image Generation AI component where it is installed, giving users who do not use the feature a way to reclaim the space it takes up. Microsoft has slowly made AI components optional after pushback over disk space and unwanted defaults.

Widgets and Start menu pick up smaller refinements

Taskbar notification badges switch from red to match your Windows accent color, which is a smaller version of the badge changes Microsoft already rolled out for Insiders earlier this year when they turned off the MSN feed and ads in Widgets by default.



New users also see a simpler Lock screen, with Weather as the only widget shown by default instead of a cluttered set of cards.

Start menu view preferences are now retained more reliably, so your chosen layout won’t get reset spontaneously. Keyboard navigation also improves when focus is set to the apps list within the Start menu.



Also, the Start menu’s account control flyout gets a design refresh and now shows a badge for your subscription status, which you can view by selecting your account picture in the lower-left corner. It is limited to users signed in with a Microsoft account, and availability varies by device and market.

Accessibility, input, and windowing improvements

Magnifier on touch-enabled devices gets a fix for the horizontal and vertical touch bars used to pan the magnified view. These are now off by default so they no longer obstruct magnified content, though you can turn them back on in Settings > Accessibility > Magnifier if you use touch panning.



Fluid dictation for Voice Typing is now off by default for new users, with a teaching tip shown the first time the feature is used. Mouse cursor size now persists more reliably between sessions, and system dialogs open at the appropriate size on small tablets.

Power, Windows Update, and networking reliability improvements

With the latest Windows 11 update, Power and battery settings apply more consistently now. Changes you make in Settings, covering display, sleep, hibernate, the power button, the sleep button, and lid-close behavior, now apply across all power plans instead of just the active one.

Microsoft also restored the ability to set a threshold for when Energy Saver turns on, under Settings > System > Power & Battery.



Windows Update gets two minor fixes. Update progress calculation in Windows Update Settings is more accurate now, and update clean-up logic has changed to improve system performance right after an update finishes installing.

On networking, DHCP renewal reliability improves in a few scenarios, particularly when a device receives a NACK from the DHCP server, and on devices using Modern Standby.

Print performance also improves for IPPS printers, so pages should print faster on secure Internet Printing Protocol connections.

Clipboard reliability improves in some Remote Desktop and Azure Virtual Desktop scenarios too.

General reliability improvements across explorer.exe and sign-in

Microsoft continues chasing explorer.exe stability. The August update improves reliability when opening Jump Lists and recent files, when sharing files and folders, and when using Task View and multiple desktops. It also improves the reliability of the Windows sign-in and lock screens, especially when system memory is low, and improves Start menu and taskbar reliability during startup.



System sounds are more consistent when using Windows in dark mode, and you wonder how sounds and dark mode are even related!.

Time zone change detection is more accurate, and daylight saving time data has been corrected for Middle East Standard Time in Beirut, Morocco Standard Time in Casablanca, Israel Standard Time in Jerusalem, and Greenland Standard Time in Nuuk.

Fonts get attention too, with restored support for Unicode variation sequences in the Myanmar Text font and improved character shaping for the Mongolian Baiti font. The taskbar’s system tray area also loads more reliably on touch devices used in tablet mode.

And an important feature for parents, Windows Setup now shows a parental controls notice highlighting available family safety features during setup.

Secure Boot certificate rollout continues in the normal phase

Unlike most of the changes above, Secure Boot updates ship in the normal rollout phase, so it applies as soon as you install the update. The release adds more high-confidence device targeting data, expanding the pool of devices eligible to automatically receive the 2023 Secure Boot certificates. Certificate deployment through Windows Update keeps continuing across supported PCs and non-managed business devices over the coming months.



Microsoft has been clear that devices still waiting on the new certificates are not at any immediate risk. Standard Windows updates keep installing normally, and the certificates will arrive automatically once a device shows enough successful update signals. If you want to check your own status, open Windows Security > Device Security, and look under Secure Boot for a green checkmark, yellow warning, or red alert.

Other fixes shipping in the normal rollout

Office applications running in virtualized environments are more stable, both while in use and when closing.

File Explorer no longer incorrectly marks files on a DFS mapped drive as originating from the internet after a device starts offline and later reconnects, which had been triggering a false “this file could harm your computer” warning in the Preview Pane along with an unexpected Mark of the Web on copied files.

File History backups to network shares over SMB are fixed too. Backups were failing with a false “invalid credentials” error even when the credentials were correct, and that is resolved now.

AI components are updated in the background

The August update refreshes the internal AI components Windows 11 uses across the system to version 1.2607.840.0, covering Image Search, Content Extraction, Semantic Analysis, and the Settings Model. These update silently and do not need any action from you.

Servicing stack update and known issues

Microsoft is shipping servicing stack update KB5101711 (build 26100.8962) alongside this release, which improves the reliability of the Windows update installation process itself.

As of this writing, Microsoft says it is not aware of any known issues with this update, a welcome change after July’s update briefly caused shutdown and overheating problems on some Dell PCs before Microsoft shipped an emergency fix.

How to install the August 2026 Patch Tuesday update

Go to Settings > Windows Update > Check for updates to grab it. Your PC moves to build 26200.9165 if you are on 25H2, or 26100.9165 on 24H2, once installed. Turning on “Get the latest updates as soon as they’re available” can help it appear sooner.



Given how much of this update is gradual, do not be surprised if some of the smaller items above, particularly the File Explorer file size change or the touchpad gestures, take a few days to show up even after installing. Yes, this isn’t a feature-rich update, but if Microsoft keeps shipping quality fixes like this every month, Windows 11 ends up a noticeably stable OS by the end of the year.

source
2


It's the second Tuesday of the month, which means it's Patch Tuesday time again. As such, today, Microsoft is rolling out the monthly security update (also called "B release") for August 2026 on Windows 10 under the Extended Security Updates (ESU) program.

The new updates are being distributed under KB5120249, bumping up the builds to and . You can find standalone links to download the new update on the Microsoft Update Catalog at this link.

source
3
Windows 11 / Admins unhappy as Microsoft found installing new "OneDrive Photos" app
« Last post by javajolt on August 11, 2026, 09:21:22 PM »
After a lot of criticism recently, Microsoft has been trying to do some real good work. For example, the company recently announced a couple of new tools which will use AI to improve Windows 11 performance optimization. And it's not just general users; Microsoft recently released a new utility for IT admins that has been described by some as a "game changer".

However, despite those positives, the company manages to do a lot of things wrong. The latest such case happens to be the installation of a new OneDrive feature on enterprise PCs without any caution or warning, and as such, this has angered some system administrators.

That is because Microsoft appears to be quietly rolling out a new OneDrive Photos app to Windows 11 PCs. The biggest problem, however, is that admins say they were not informed about the rollout, with some claiming that they could not find any mention of the app in Microsoft's roadmap, Message Center or similar such documentation.

If you are wondering why this is a big deal, the app is reportedly showing up even on Windows 11 Enterprise machines, despite apparently being a beta application aimed at consumer functionality. One admin questioned why a beta app was appearing on an Enterprise SKU in the first place, while another described the situation as yet another consumer-oriented feature being forced onto corporate PCs.

Things get even more frustrating for IT departments because there does not appear to be a straightforward Microsoft-provided way to disable the app. Instead, one community member created a Remediation script for Intune that can remove OneDrive Photos from managed devices, while others suggested scheduling the script to run regularly in case Microsoft installs the app again. You can find it at the source link below.

And this is arguably the biggest issue here. Enterprise administrators generally need to know what is being installed on their managed devices, particularly when a software is labeled as beta. Quietly adding another application and leaving admins to clean it up themselves is therefore unlikely to win Microsoft many fans, despite all the good deeds it has been trying to do recently.

Update 18:03 ET: We reached out to Microsoft and a spokesperson provided the following statement:

Quote
“We are incubating a new photos experience in OneDrive that went more broadly than it should have in Windows. We’re fixing that. Windows Photos will always give you the option of local and cloud photos and the choice to use OneDrive or not.”

Beyond that Microsoft did not have anything more to share.

source
4


The Android RAT’s official operation is surrounded by cheaper resellers, alleged source-code vendors, independent server owners, and possible impersonators.

BTMOB has been covered by several cybersecurity publications, primarily through technical analyses of the malware and its capabilities, but much less has been reported about the ecosystem that has developed around it.

Activity observed by Flare researchers in underground forums and chat platforms reveals another story: a criminal software business that appears to have become increasingly difficult for its original operator to control.

Posts reviewed by Flare show the channel presenting itself as BTMOB’s official outlet continuing to release new versions and sell access, private infrastructure, and source code. Around it, other actors advertise cheaper subscriptions, reseller panels, purported source files, and versions carrying the BTMOB name.

To understand how this ecosystem developed, the research examined thousands of posts from forums and chat platforms, following BTMOB’s underground activity from its early stages in 2025 through the present.

The material includes announcements from the apparent official operation, alongside activity by resellers, source-code vendors, and other actors using the BTMOB name.

Key points

■ BTMOB developed from a centrally operated malware service into a broader ecosystem involving private servers, source-code buyers, custom versions, and independent administrators.

■ The official operator repeatedly reduced the price, while third parties advertised alleged access and source files at substantially lower prices.

■ The BTMOB name is now used by coordinated reseller campaigns and accounts that imply an official connection, although the authenticity of many offers cannot be verified.

■ The official BTMOB operation remained active as a secondary market developed around it, continuing to release new versions and advertise access, private infrastructure, and server code.

What is BTMOB?

BTMOB is primarily an Android remote access trojan where its malicious application is installed on a victim’s phone to steal information and provide remote control. It is sold as a malware-as-a-service package that includes droppers, a payload builder, a Windows-based operator panel, server infrastructure, and tools for phishing and credential-stealing.

BTMOB attracts actors because it provides both the malware and much of what is needed to operate it. Customers can use a software tool to configure and create malicious Android applications without developing them from scratch.

Depending on the package purchased, they may also receive access to server infrastructure, customized versions, and technical support.



Infrastructure problems became a sales opportunity

In January 2025, the official channel advertised BTMOB V2 for $700 a month, $3,000 for a lifetime license, or $5,000 plus monthly payments for private infrastructure and support.

Less than a month later, it acknowledged server errors. The operator claimed that more than 4,000 mobile devices were connected but could not determine whether heavy traffic represented customer activity or a DDoS attack. See screenshots below: 





Screenshots taken from Flare platform showing BTMOB acknowledging server availability issues.
Sign up for the free trial to access if you aren’t already a customer.

Although these claims could not be verified, the announcement provides insight into how BTMOB operated at the early stages, with the apparent official operator managing its shared infrastructure and customer communications.

Selling the code behind the service

In May 2025, the channel offered complete BTMOB source code and setup tutorials for $20,000. The package included its PHP and Node.js server components, VB.NET control panel, and Java Android code. See screenshot below: 



Screenshot taken from Flare platform showing BTMOB’s offering the full source code for $20,000.
Sign up for the free trial to access if you aren’t already a customer.

The operator later explained that source sales would generate profit, let customers inspect the code, and enable custom or alternative versions without ending the development of the original service.



Screenshot taken from BTMOB Telegram channel,
showing a BTMOB administrator explaining the decision to sell its source code.


At the same time, the organization showed signs of fragmentation. A Spanish- and Portuguese-language support channel announced that servers were temporarily offline during a dispute with two former administrators. It suspended sales and accused them of acting in bad faith.

In July, the main channel said its administrators would begin operating independently, becoming responsible for their own clients and reputations. It also said a Brazilian administrator had purchased the source and was maintaining a separate version.

The advertised source-code price subsequently fell to $10,000. When BTMOB V4 arrived in December, the public offer emphasized lifetime access, private servers, custom versions, and recurring fees.

Customers were also told that migration from V3 required contacting the operator.

A cheaper secondary market

During the same period, a coordinated Telegram campaign offered BTMOB V4.1.2 and V4.2 access. One representative advertisement priced lifetime access at $500 and “RAT and server file source code” at $1,500, directing buyers to @thebtmobadmin and @btmobportal.

The advertisement was repeatedly distributed across multiple Telegram groups by several accounts using substantially the same wording, prices, and contacts. A later variation promoted purported V4.5.4 access at similar prices but used another contact handle.

The timing is notable, although it does not prove that the official warning referred to these particular sellers. On April 26, the main BTMOB channel said it had only one official channel and denied responsibility for other accounts claiming to represent the project. See screenshot below:



Screenshot taken from Flare platform showing BTMOB’s channel warning about impersonators and scam accounts.
Sign up for the free trial to access if you aren’t already a customer.

Other actors advertised even lower prices of the different options. One offered several BTMOB versions through weekly, monthly, and lifetime plans, including purported source code. Another invited customers to become BTMOB sellers by purchasing inexpensive user or administrator panels.

Substantially similar source-code and reseller-panel advertisements appeared across numerous sites, frequently pointing to the same contact and website. Separate posts offered free trials and an $800 lifetime license, custom branding, and alleged free source downloads.

None of these advertisements proves that the files are authentic. Some may represent genuine reselling or modified versions while others may involve repackaged software, nonfunctional files, or scams.

Official development continued in 2026

The main channel released BTMOB V4.1 in February 2026 and V4.5 in April. The V4.5 offered a $1,200 lifetime account, a $3,000 private server with multiple accounts, or server source code for $7,000.

This may indicate that infrastructure-level code sales remained part of the official business, although the offer had become narrower and cheaper than the complete package promoted in 2025.

V4.5 also introduced several server locations and a central page for managing multiple servers.

From a single service to a fragmented market

When the creator of a successful product sells its recipe, others can reproduce it without bearing the original development costs. Cheaper versions emerge, but their quality varies: some may improve on the original, while others are unstable, poorly supported or even fraudulent.

This appears to be what happened with BTMOB. We do not know what prompted the source-code sale or the dispute between its administrators.

However, what began as an established MaaS operation seems to have developed into a mixture of independently managed versions, cheaper copies, competing sales channels and offers of uncertain legitimacy.

As a result, the BTMOB name no longer identifies a single operator, infrastructure or level of service.

In this fragmented market, buyers must evaluate not only the software but also the seller’s reputation, technical support and evidence that the service actually works.

source
5
Microsoft / Microsoft denies Windows 11 is spying on desktop PCs,
« Last post by javajolt on August 04, 2026, 12:18:59 PM »
Reveals what the service actually does.


Microsoft shuts down a viral rumor claiming Windows 11 secretly added a tracking service

A viral X post claiming Microsoft secretly added a new background service to spy on Windows 11 desktop PCs has racked up over 110,000 views since Friday. But the account behind it sells a paid PC optimization service to gamers.

A couple of sharp-eyed users commented that the service is over a year old and fully documented in public builds. Eventually, the post got a Community Note, and finally, to put matters to rest, Microsoft’s Scott Hanselman stepped in.



However, most of the damage was already done because Windows 11 has earned a reputation for feeling slower and bloated, so a post like this fits right where people expect it to. Microsoft does run a service as the one described, but once you look at what it does, it isn’t the problem people assumed it was.

Windows Health and Optimized Experiences Properties in a misunderstood feature

X user Xilly posted in all caps that Microsoft “ADDED A NEW BACKGROUND SERVICE TO YOUR PC IN WINDOWS 11” called Windows Health and Optimized Experiences, framing it as a laptop battery tool that does nothing but run in the background on desktop gaming PCs while quietly sending data to Microsoft every 15 minutes. Yes, that sounds dystopian and very much like Microsoft, but fortunately, this claim is false.



Note that Xilly runs a paid PC tuning business that manually adjusts BIOS, Windows settings, and hardware parameters for gamers chasing lower input lag and higher FPS. In a reply to their own post, Xilly wrote that most background services “do not affect gaming performance as much as people like to believe,” an odd thing to admit while implying this particular one is worth panicking over.

Commenters were tech-savvy enough to catch Xilly in the act. The service, known internally as whesvc, first showed up in a Windows 11 Canary build back in May 2025, where developer Albacore flagged it as a Lua-driven component tucked inside whesvc_assets.dll.



Windows Latest broke down the service’s code at the time and found it runs a script called ecp.v2.lua, sandboxed with disable_global_variables(), sampling metrics like CPU load, thermals, brightness, and battery percentage through environment variables such as WINDIAG_ECP_EVAL_SEC and WINDIAG_ECP_TELEMETRY_FREQUENCY_MINUTES. The “every 15 minutes” figure people are quoting today is about that May 2025 code analysis.



X eventually added a Community Note to Xilly’s post, and Albacore’s original 2025 post was cited directly as the source proving the service wasn’t new.

It’s also not a secret. Windows 11 documented builds show whesvc now powers Adaptive Energy Saver, a real, working feature that automatically dials in battery-saving settings, which is a strange thing for a service supposedly built to do nothing useful on your PC.

How to disable Windows Health and Optimized Experiences Properties

Disabling it, if you want to, is easy. Open Services (services.msc), find Windows Health and Optimized Experiences, and set its startup type to Disabled, or run sc stop whesvc and sc config whesvc start=disabled from an elevated terminal.



Of course, like with any negative post about Microsoft, this rumor too was already hard-etched as a reality in users’ minds. But the person who finished it off was Scott Hanselman, VP and member of technical staff at Microsoft.

Senior Microsoft VP shuts down rumours of a new viral Windows 11 tracking tool that reduces PC performance

The service was added in 2025 for performance-diagnostic capture. When Windows detects sluggish behavior, it can record targeted performance traces locally under %SystemRoot%\Temp\DiagOutputDir\Whesvc, which get bundled into a Feedback Hub report only if you choose to file one under the Desktop > System Sluggishness category.



The traces stay on your machine unless you actively submit feedback; they aren’t silently phoned home on a schedule the way the viral post implied. Hanselman also directly rejected the false claim that this was laptop-only, confirming the service isn’t battery-specific and instead falls under Windows’ diagnostics stack along with tools like Windows Performance Counters, the same built-in mechanism Windows has used for years to track CPU, memory, disk, and network behavior across both desktops and laptops.

When one commenter asked what specifically counts as “sluggish” if raw hardware usage numbers don’t tell the whole story, Hanselman clarified that the service works off Windows performance counters instead of anything resource-heavy like screen recording, which actually addressed a fair technical question that had nothing to do with the induced panic from the original post.



It’s not always that we see senior Microsoft staff shutting down fake rumours like this, and there is good reason. Scott Hanselman is aware of this, as he rightfully said, “SAYING THINGS IN ALL CAPS FOR DRAMA DOESN’T MAKE THEM DRAMATIC.”

People believe rumors like this because Windows 11 gave them reasons to

If Apple quietly shipped the same diagnostic service, most people wouldn’t blink. Windows 11 doesn’t get that benefit of the doubt anymore, and Microsoft largely did this to themselves.

As Windows Latest’s Mayank Parmar replied: “hating Windows for absolutely stupid reasons is the new gig economy for these so called X ‘independent’ creators.”

Several people asked why the service’s official description just says “Monitors the device for a better user experience” instead of something closer to what Hanselman explained in the thread. He agreed and said he’d ask for the description to be expanded.

Now, this is where Apple differs from Microsoft. California cares too much about how users perceive their brand, and it has largely worked in their favour, except for the times when they have to announce a new product, and it’s almost always the same one from last year.

Also, multiple users said some version of “just make Windows faster,” and mentioned their real, lived experience of a sluggish Windows 11 as the reason a vague rumor felt believable in the first place.

Windows Latest has been tracking this closely, from Windows 11’s rough run of update problems through 2025 to how the Task Manager creator had to publicly correct a claim about a different tracking identifier just last week. Distrust like this doesn’t come from nowhere.



Microsoft is trying to earn that trust back

Windows 11 became one of the most criticized versions of Windows for real reasons, and Redmond has been working to reverse that since March, when the company committed to fixing Windows 11’s quality and fundamentals.

Satya Nadella reinforced that commitment on Microsoft’s most recent earnings call, telling investors the company is investing directly in Windows 11’s quality this year.

That said, the years of bloat, forced upsells, and confusing background services that got Windows 11 here don’t just go away because of one good week. But the next viral rumor about a “secret” Windows service deserves a beat of skepticism, especially when the person posting it happens to sell the fix.

source
6
Intel just released version 24.60.0 of its Wi-Fi driver. The new update improves stability and functionality of Intel's wireless adapters.



Intel has released version 24.60.0 of its Wi-Fi driver package for its wireless adapters. The new update brings a couple of stability improvements and is now available to download for eligible wireless adapters.

Intel joined Microsoft's K2 initiative with last month's driver release, and this one continues to build on that. The aim of the K2 push is to enhance the quality of the Windows ecosystem, which in this case means improving performance and stability of various OS components, including drivers.

This release doesn't introduce any notable changes, but instead brings general improvements. Intel says it improved wireless stability and functionality, along with enhancing regional regulatory compliance. Both changes apply to Windows 10 and Windows 11.

Here's the full changelog:

• Improved wireless stability and functionality - Windows 10/11

• Enhanced regional regulatory compliance - Windows 10/11

• Software version 24.60.0 includes new functional updates, as well as minor fixes that improve performance, stability, and vendor-specific features. Users are encouraged to update to the latest version for best performance - Windows 10/11

The 24.60.0 package installs the Wi-Fi driver version 24.60.0.3 for the following Intel wireless adapters, both on Windows 10 64-bit and Windows 11:

   • Intel® Wi-Fi 7 BE213

   • Intel® Wi-Fi 7 BE211

   • Intel® Wi-Fi 7 BE202

   • Intel® Wi-Fi 7 BE201

   • Intel® Wi-Fi 7 BE200

   • Intel® Wi-Fi 6E AX411 (Gig+)

   • Intel® Wi-Fi 6E AX211 (Gig+)

   • Intel® Wi-Fi 6E AX210 (Gig+) IOT Industrial Kit

   • Intel® Wi-Fi 6E AX210 (Gig+) IOT Embedded Kit

   • Intel® Wi-Fi 6E AX210 (Gig+)

   • Intel® Wi-Fi 6 AX231

   • Intel® Wi-Fi 6 AX203

   • Intel® Wi-Fi 6 AX201

   • Intel® Wi-Fi 6 AX101

   • Intel® Wireless-AC 9560

   • Intel® Wireless-AC 9461

   • Intel® Wireless-AC 9462

   • Intel® Wireless-AC 9260

   • Intel® Dual Band Wireless-AC 9260 IoT Kit

This download is primarily aimed at IT administrators, large organizations, universities, and medical centers, though Intel notes smaller organizations may still find the installation and deployment tools useful.

To download Intel's Wi-Fi driver 24.60.0 head over to the official download page.

source
7
70+ fake sites are pushing malware right now



More than 70 popular Windows apps now have fake websites impersonating them, and some are already serving malware. The list includes widely used tools like PowerToys, CrystalDiskMark, EasyBCD, Lively Wallpaper, and Wintoys, all cloned onto lookalike domains that in most cases rank above the real project pages on Google.

Some apps on this list have already had their fake sites confirmed as active malware distributors. They may be pushing a trojanized installer that sets up a remote-access service on victims’ PCs.


Credit: u/Bogdan_X via Reddit

We strongly recommend downloading Windows apps only from the Microsoft Store or from the developer’s official website or GitHub page, and never from a random search result, however convincing it looks. If you’ve visited any of the following websites, treat your PC as compromised and scan it immediately:

Full list of fake websites impersonating Windows apps

The following domains were identified as impersonating legitimate Windows applications, all registered to the same owner through Epik Inc. before being moved to Dynadot LLC in July. Remember, not a single one of these is an official source for the apps it claims to represent, and please do not open these URLs. For testing, you can use Windows Sandbox.



Again, in case we are not clear already, steer clear of every domain on this list. They are not affiliated with the developers whose apps it claims to host.

How a developer discovered 70+ lookalike domains while checking his own app’s reviews

The developer behind Wintoys, a Windows optimization tool available on the Microsoft Store that lets users clean, repair, and tweak system settings without opening the terminal, habitually searches his app’s name on Google to see new reviews or user questions. During one of these searches, he found a domain he had not purchased showing up in the results (wintoys.app).



u/Bogdan_X explained on Reddit that the site was built on WordPress, with generic, inaccurate AI content, and used their old logo. Its download button surprisingly goes to the real Microsoft Store listing, which is likely why it hadn’t raised alarms yet.

He tried to trace ownership of the domain but couldn’t, since it was registered through Epik Inc., which bundles free WHOIS privacy into every domain, keeping the buyer’s identity hidden by default. What he did find was a troubling list of 72 domains.

Even Microsoft’s own PowerToys has a fake website!

These sites build trust first, then swap in malware later

According to Check Point Research, these impersonation sites have a three-stage playbook:

   1. They rank for a popular app’s name in search results

   2. Appear harmless at first by linking to real download sources

   3. Then quietly swap those links for malware after getting traffic and trust.


Impersonated websites of popular software tools (Source: Check Point Research)

Check Point found that some of these sites load a script from Amazon CloudFront that intercepts the click on a download button and reroutes it through a Traffic Distribution System, a filtering layer that decides where to send each visitor based on their location, browser, and whether they look like a bot or a security researcher.

Check Point traced malware families including RemusStealer, an infostealer targeting over 20 browsers and cryptocurrency wallets, and AnimateClipper, which swaps copied crypto wallet addresses for the attacker’s own. A cluster of these domains had been silently building search rankings since at least September 2025, with malware distribution that began in January 2026.


VirusTotal total submitters crossing 5,000 shows the scale of the operation (Source: Check Point)

Lively Wallpaper and SignalRGB confirm active attacks

Two developers on this list have already confirmed their impersonators are distributing real malware.

A GitHub issue filed against Lively Wallpaper describes a fake site at livelywallpaper.app serving a trojanized installer through a script hosted on giize.com. The installer bundled a legitimate DirectX setup file alongside a malicious, unsigned DLL, and installed a persistent remote-access service along with bandwidth-sharing software that likely resold the victim’s internet connection.



Lively’s developer confirmed the domain has no affiliation with the project and recommended users to the official Microsoft Store listing instead.

SignalRGB posted on Reddit about a fake site at signalrgb.io, which the team says has managed to rank near the top of some search engines, including Bing. The team later flagged a second impersonating domain, signal-rgb.net, and urged users who downloaded from either site to delete the file and run a full malware scan.

One commenter on the SignalRGB thread reported success getting a domain taken down after reporting it to Cloudflare with evidence, with Cloudflare confirming it had restricted access to the reported URL and forwarded the abuse report to the hosting provider.

Cloudflare flagged one domain within an hour, but most others are still unprotected

Cloudflare acted fast when the wintoys.app domain was reported, adding a “Suspected Phishing” interstitial warning that shows if a user visits the fake site, telling them the page has been reported for potential phishing. u/Bogdan_X confirmed the warning went up in under an hour of filing the report.



However, Cloudflare’s abuse form only accepts one domain per report, and u/Bogdan_X said that despite listing all 72 domains in his submission, the other 71 will likely be unprotected.

The 72 original domains have since been added to Hagezi’s DNS blocklist, a popular adblock list used by millions of people, which will now block those sites automatically for anyone running it. MKVToolNix, the popular video remuxing tool, has also been listed in this project.

Mica For Everyone, a Windows theming tool, is also being impersonated through a domain registered with Spaceship and hosted via Hetzner behind Cloudflare, the same registrar used for the fake Lively Wallpaper and SignalRGB sites. Its maintainer said the registrar’s abuse email went nowhere, and without a trademark on the app’s name, a formal takedown wasn’t an option, so the only workaround was asking Cloudflare to add a malware warning.

It isn’t confirmed if this is one operator spreading impersonation targets across multiple registrars to slow down takedowns, or several unrelated attackers copying the same playbook.

Windows apps aren’t uniquely at risk, but the platform makes them an easier target

This isn’t a Windows-specific flaw, and macOS isn’t inherently safe. The difference is scale. Windows is on a far larger share of desktop PCs than macOS, and a larger user base means more search volume for utility software, which makes Windows tools a bigger, more profitable target for this kind of operation.

Microsoft’s reputation adds to the problem. Years of ads, bloatware, and upsells in Windows 11 have left plenty of users skeptical of the Microsoft Store, so they turn to Google Search.


Fake Ghidra project website in Google search (Source: Check Point)

Ironically, searching the Microsoft Store first is still the safer move. If something goes wrong with an app sourced from the Store, at least Microsoft’s review and reporting systems give you a place to escalate.

Windows Security has also gotten considerably better at catching this kind of threat. We previously reported that Microsoft has quietly confirmed most Windows 11 users don’t need third-party antivirus software, since Windows Security already runs Microsoft Defender Antivirus, SmartScreen, Smart App Control, ransomware mitigation, and cloud-delivered protection as one stack.


Microsoft Defender SmartScreen Demo

Smart App Control can block unsigned or unrecognized executables from running, including installers downloaded from a fake site. SmartScreen also checks the reputation of files and URLs as you download them.

How to download Windows apps safely

• Always check the domain in your address bar before downloading anything, especially if you reached the site from a Google search.

• Use the Microsoft Store or the developer’s official GitHub releases page over a project’s standalone website when both exist.

• If you download an installer from a site you’re not fully sure about, scan it with VirusTotal before running it (Note that even VirusTotal is not foolproof).

• Check whether the file is digitally signed by right-clicking it, going to Properties, and looking at the Digital Signatures tab.



App development has increased drastically, and the internet still isn’t safe

Claude Code and Codex have drastically lowered the barrier to building software, and more developers means more targets for this kind of operation. We need to understand that not every developer has the budget or time to run brand-monitoring services.

However, there are a few things that devs must take care of. Listing an app on the Microsoft Store is the most effective step and it now costs nothing to do. Microsoft dropped its one-time developer registration fee for individual developers in 2025, and extended the same to company accounts in May 2026, removing what used to be a $19 to $99 barrier.

For developers who already run their own project website, investing a little time in basic SEO, clear page titles, proper meta descriptions, and submitting to Google Search Console, makes it harder for a fresh impersonation domain to outrank the real one.

Of course, none of this makes impersonation impossible, but it raises the cost of running the scam.

I know I’m repeating myself, but if you’re downloading a Windows app, check the Microsoft Store first. If a developer only distributes through their own website, verify the URL.

source
8
Scammers are impersonating popular Windows app websites, raising fears of a coordinated malware campaign targeting unsuspecting users.

Here at Neowin, we regularly cover first- and third-party Windows applications like Wintoys, PowerToys, Windhawk, Flyoobe, and more. We typically link to official download sources for these applications, such as the developer's own verified website, GitHub repository, or the Microsoft Store. However, it now appears that a coordinated operation is now underway through which scammers are impersonating websites of popular Windows applications to potentially distribute malware.

This discovery was made by Wintoys developer Bogdan_X on Reddit, who noticed a wintoys.app website set up for their popular customization app. This website was not configured by Bogdan_X, and according to the developer, it showcases inaccurate information, but interestingly, the download link points to the official app on the Microsoft Store. However, a disclaimer on the bottom of the page does indicate that it's not the official Wintoys website:

Quote
Not affiliated with Wintoys. This is an independent site providing documentation, guides and links to the official project repositories.

We visited the website in Chrome, and Cloudflare showed a warning that Wintoys.app is suspected of phishing. However, it's certainly interesting that the download link points to an official source and even contains an obscure disclaimer, likely to reduce chances of legal action.

Bogdan_X tried to trace the owner of the scam website and discovered that the contact email of the owner is associated with over 70 other websites, all posing as Windows applications. These include popular utilities like PowerToys, CrystalDiskMark, WinUtil, and more. Bogdan_X noticed that some websites are under construction, which indicates that this operation has recently kicked off. The complete list of discovered fake websites is as follows:

   • christitustool.com

   • droidkit.pro

   • easybcd.app

   • powertoys.app

   • shellmenuview.com

   • winexp.app

   • zhpcleaner.com

   • cursorslibrary.com

   • fakeflashtest.com

   • searchmyfiles.com

   • wintoys.app

   • themouseclicker.com

   • quickassistapp.com

   • move-mouse.com

   • movemouse.net

   • nircmd.net

   • crystaldiskinfo.app

   • freewheelofnames.com

   • productkeyscanner.com

   • power-toys.com

   • chatmate.info

   • usblogview.com

   • mouse-mover.com

   • mouse-cursors.com

   • mouse-clicker.com

   • mimalloc.com

   • mumuplayer.app

   • wushowhide.com

   • guiformat.app

   • freefilesync.net

   • winutil.app

   • spacesniffer.app

   • simplestickynotes.app

   • showmore.app

   • mousecape.app

   • hashcat.app

   • dshidmini.app

   • darktable.app

   • daijisho.app

   • wiblr.com

   • skse64.com

   • sageattention.com

   • rezygisk.com

   • pwndbg.com

   • ocrmypdf.com

   • notatnikonline.com

   • noisium.com

   • mousecape.net

   • mongosh.com

   • lspconfig.com

   • liveclockwithseconds.com

   • lax1dude.com

   • je2be.com

   • iso2god.com

   • hifiasm.com

   • hddsentinel.com

   • hakchi2.com

   • gliden64.com

   • furfsky.com

   • freeminutetimer.com

   • findoutdate.com

   • crystaldiskmark.net

   • bepisdb.com

   • beardlib.com

   • 10mintimer.com

   • pyjwt.com

   • moliyachi.com

   • arduinodroid.com

   • cxxdroid.com

   • kalkulyator.com

   • retraitedz.com

   •urlaubscountdown.com

It's unclear what the goal of this supposed scamming operation is, since the domains don't seem to be doing anything obviously malicious right now. It is possible that the fake websites are posing as official sources to gain trust and traffic before eventually injecting malware in their download links.

When Bogdan_X reported the fake domains to the registrar, the registrar terminated services for the scammer. However, this didn't really solve the problem as they migrated to another registrar.

It's unlikely that there is a long-term solution to this problem, but users and developers should report illegal activity to the cloud hosting provider and the domain registrar if they come across it. And as always, it is better to carefully vet a URL and essentially any portal hosting a download link before you click on it.

source
9
Apple has released iOS 26.6 and iPadOS 26.6. The updates bring no new features, but include a lengthy list of bug fixes and imrpovements.

Apple has just released iOS 26.6 and iPadOS 26.6 to the public. This is mainly a security update, as it brings no new features to the mix. On the other hand, the update fixes a large number of known bugs.

Apple’s release notes only say the following:

Quote
“This update includes bug fixes, security updates and optimizes the Spotlight index to prepare for iOS 27.”

Along with the bug fixes, the update also optimizes the Spotlight search index in preparation for iOS 27 and iPadOS 27, expected later this year. Still, it’s worth mentioning that the full capabilities of the optimized Spotlight search will only be available to users of iPhone 15 and later, as the feature is connected to Siri AI.

Additionally, a few of the fixes stand out. Apple patched a MediaRemote bug that could have let a malicious app gain root privileges on the device. There's also a fix that could have let a fake, tampered app slip past one of iOS's core security checks and a WebKit fix that addressed a privacy leak. That leak could’ve let websites detect what other webpages you visited before, and, in turn, compromise your browsing history.

This is the last update before iOS 27 and iPadOS 27 arrive this fall. So, it’s not surprising that this one doesn’t introduce any new features, as Apple has reserved all the novelties for the fall. You can check if your iPhone supports the upcoming iOS 27 update here.

Even though you’re not getting anything new, it’s still worth updating your iPhone or iPad to iOS 26.6 because of the sheer number of bug and vulnerability fixes. iOS 26.6 and iPadOS 26.6 can be installed from Settings >  > Software Update.

You can check the full list of bugs Apple has addressed in iOS 26.6 and iPadOS 26.6 updates here.

source
10
The official list of supported models for the new iOS 27 update goes all the way back to iPhone 11, which is also getting a new CPU Scheduler.



It's that time of year when we get to know about the latest operating system updates for Apple devices. For iPhone, Apple previewed the iOS 27 update at WWDC 2026, where the company finally introduced an upgraded version of Siri.

Apple typically supports iPhone models for up to five years. But it has been making exceptions in recent years (read iPhone 11). If you're wondering whether your iPhone is compatible with the iOS 27 update, here is the official list of devices:

   • iPhone 17 Pro Max, iPhone 17 Pro, iPhone 17, iPhone 17e, iPhone Air

   • iPhone 16 Pro Max, iPhone 16 Pro, iPhone 16, iPhone 16 Plus, iPhone 16e

   • iPhone 15 Pro Max, iPhone 15 Pro, iPhone 15 Plus, iPhone 15

   • iPhone 14 Pro Max, iPhone 14 Pro, iPhone 14 Plus, iPhone 14

   • iPhone 13 Pro Max, iPhone 13 Pro, iPhone 13, iPhone 13 mini

   • iPhone 12 Pro Max, iPhone 12 Pro, iPhone 12, iPhone 12 mini

   • iPhone 11 Pro Max, iPhone 11 Pro, iPhone 11

   • iPhone SE (2nd generation), iPhone SE (3rd generation)

So, you can download the iOS 27 developer beta on up to 31 different iPhone models. There has been no change to the list of supported iPhones since iOS 26. However, it will expand to include more devices when the iPhone 18 series arrives later this year.

To download the developer beta on your iPhone, go to Settings > General > Software Update > Beta Updates. Here, select "iOS 27 Developer Beta" from the list of choices to get the new update. In addition to iOS 27, you can try the developer beta versions of macOS 27, iPadOS 27, watchOS 27, tvOS 27, and HomePod software 27 on your supported devices.

iOS 27 comes with improved Liquid Glass, which you can adjust using a new transparency slider. Apple said during the keynote that iPhone apps now launch up to 30% faster, new photos appear in the Photos app up to 70% faster, and AirDrop transfers work up to 80% faster. The new update promises to improve performance on older iPhones by introducing a new CPU Scheduler that supports devices all the way back to the iPhone 11.

While iOS 27 is supported on older iPhones, it goes without saying that they'll lack several features due to hardware differences. For instance, iPhone 14/14 Plus and older models come with a notch instead of the Dynamic Island. Similarly, Apple Intelligence features are supported on iPhone 15 Pro/Pro Max and later models.

source
Pages: [1] 2 3 ... 10