
Windows 10 security flaws leave millions vulnerable
Windows 11 is the latest and greatest operating system from Microsoft, but it has its flaws, so much so that even four years after its release, some people are sticking with older versions. Windows 10 remains the operating system of choice for many, even though Microsoft has shifted its focus entirely to Windows 11. In fact, the Redmond-based company will end security updates for Windows 10 this October.
If that's not enough to push you toward upgrading, the latest news might be. The 240 million Windows 10 users are vulnerable to dozens of security vulnerabilities, six of which are reportedly already being exploited by bad actors.
The vulnerabilities in question were part of a recent Microsoft Patch Tuesday update, a monthly release where the company addresses security flaws. In this case, six specific exploits were identified as being actively used by hackers to target Windows 10 systems. These exploits are particularly alarming because they are already in the wild, meaning attackers are leveraging them to compromise systems before all users have had a chance to update their devices.
The affected population, estimated at 240 million, refers to users whose PCs cannot upgrade to Windows 11 due to hardware limitations, such as lacking TPM 2.0 (Trusted Platform Module) or other system requirements.
The six exploits include a mix of flaws that allow hackers to achieve various malicious outcomes, such as executing arbitrary code, escalating privileges to take full control of a system or bypassing security features.
For example, one exploit might overload system memory to overwrite critical data (a buffer overflow), while another could allow attackers to access sensitive information by exploiting a flaw in the Windows Kernel. These vulnerabilities are especially dangerous because they can be triggered remotely or through seemingly innocuous actions, like opening a malicious file or mounting a compromised virtual hard disk.
Microsoft has released patches to address these issues, and America's Cyber Defense Agency has urged users to update their systems immediately, ideally by this month, or risk severe consequences. The agency even suggested turning off unpatched computers as a precaution. Updating to the latest Windows 10 patch is the simplest and most effective way to protect against these exploits right now.
However, a bigger problem looms later this year. Microsoft will officially end free security updates for Windows 10 on October 14, 2025. After that, systems running Windows 10 will no longer receive critical security patches, unless users enroll in Microsoft's Extended Security Updates (ESU) program.
This ESU program will be available to individual users for the first time and will cost $30 per device for one additional year of updates. It's designed to give users more time to transition, especially those who can't upgrade to Windows 11 due to hardware limitations. While this offers a temporary reprieve, it's not a long-term solution; the ESU program will only extend support for a limited time (typically three years in enterprise settings) and prices may increase annually.
The scale of the problem remains significant. Millions of devices lack the hardware requirements for Windows 11, such as TPM 2.0 and newer CPUs, making the shift costly or impractical for some. Analysts warn this could contribute to a surge in electronic waste, unless recycling and repurposing efforts improve dramatically.
If you're a Windows 10 user, the immediate step is to ensure your system is updated with the latest patches. Follow the steps below to do that:
1) Use strong antivirus software: Even with the latest patches, no system is entirely immune to threats. Strong antivirus software can act as a second line of defense, detecting and neutralizing malware that exploits vulnerabilities before they cause harm. Look for solutions with real-time protection and frequent updates to tackle emerging threats. While this won't fix unpatched system flaws after October 2025, it can reduce risks from common attack vectors like phishing or malicious downloads. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices.
2) Limit exposure: Many exploits rely on user interaction, such as clicking a shady link, downloading a compromised file or mounting an untrusted virtual disk. Stick to reputable websites, avoid opening unsolicited email attachments and use a browser with built-in security features (like Microsoft Edge or Chrome with Safe Browsing enabled).
3) Plan for the future: The clock is ticking on Windows 10's security updates. If your hardware can't handle Windows 11, weigh your long-term options. Buying a new PC might be inevitable, but you could also explore alternatives like Linux, which offers free, secure operating systems (e.g., Ubuntu or Linux Mint) that run well on older hardware.
The road ahead for Windows 10 users is anything but smooth. With critical vulnerabilities emerging and official support coming to an end, millions are being pushed into a difficult decision. They can upgrade their hardware, pay for temporary patches or continue using increasingly vulnerable systems. As October draws closer, the risks will only increase. Updating your system is essential, but it's just a short-term measure. Now is the time to start preparing for what comes after, before the window of protection closes for good.
Do you think tech companies are doing enough to prevent hackers from obtaining your data? Let us know by writing us at Cyberguy.com/Contact.
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter.
Follow Kurt on his social channels:
Answers to the most-asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Associated Press
an hour ago
- Associated Press
Sprouting Gear Inc. Founder Paul Pluss Announces Report on:
RAMONA, Calif., June 07, 2025 (GLOBE NEWSWIRE) -- The U.S. livestock industry, already grappling with rising feed costs and shrinking herd sizes, now faces a fast-approaching and under-recognized threat: the massive expansion of artificial intelligence (AI) infrastructure—especially data centers—and its impact on water availability, says Paul Pluss, a veteran livestock rancher and researcher focused on the intersection of agriculture, water policy, and emerging infrastructure demands. 'The water usage of data centers operated by Microsoft, Google, Meta, and Amazon remains largely unrecognized by agricultural stakeholders. Prime location for data centers is the same hot dry inland location preferred for feedlots and are often sharing the same aquifers and rivers' said Pluss. Fueled by public and private investment in AI infrastructure, the number of U.S. data centers is expected to grow from 5,426 today to more than 8,378 within five years. Many existing facilities are also expanding. These data centers—crucial for powering AI models, cloud computing, and digital services—require enormous amounts of water to cool their servers. Key figures: This level of water consumption rivals agricultural water use in major farming states and could soon surpass the entire livestock industry's combined water footprint, including feed crop irrigation, drinking water, and processing needs. View the report here, as well as a articles and short videos to explain hydroponic livestock feeding and the economics behind it: Paul Pluss CEO & Founder [email protected]
Yahoo
an hour ago
- Yahoo
Why D-Wave Quantum Inc. (QBTS) Soared On Friday
We recently published a list of . In this article, we are going to take a look at where D-Wave Quantum Inc. (NYSE:QBTS) stands against other Friday's best-performing stocks. D-Wave Quantum grew its share prices by 13.05 percent on Friday to finish at $18.62 apiece as investors resumed buying following news that its new quantum computer, said to be capable of solving problems beyond the capabilities of a classical GPU-based supercomputer, is now generally available in the market. Called the Advantage2, the new quantum computer features a 4,400+ qubit processor with improved coherence and connectivity. It targets real-world applications in optimization, materials simulation, and AI, and features a 75 percent reduction in noise and a 40 percent energy scale increase over the predecessor Advantage(TM) quantum system. A modern computer datacenter, running an advanced quantum computer system. In other news, D-Wave Quantum Inc. (NYSE:QBTS) recently raised $95.8 million from the issuance of warrants. Under the transaction, approximately 8.33 million warrants were exercised at a price of $11.50 apiece. The warrants were assumed by D-Wave Quantum Inc. (NYSE:QBTS) in connection with its merger with DPCM Capital Inc., which was completed on August 5, 2022. Overall, QBTS ranks 6th on our list of Friday's best-performing stocks. While we acknowledge the potential of QBTS as an investment, our conviction lies in the belief that some AI stocks hold greater promise for delivering higher returns and have limited downside risk. If you are looking for an extremely cheap AI stock that is also a major beneficiary of Trump tariffs and onshoring, see our free report on the best short-term AI stock. READ NEXT: 20 Best AI Stocks To Buy Now and 30 Best Stocks to Buy Now According to Billionaires. Disclosure: None. This article is originally published at Insider Monkey.
Yahoo
an hour ago
- Yahoo
Why Rocket Lab Corp. (RKLB) Soared On Friday
We recently published a list of . In this article, we are going to take a look at where Rocket Lab Corp. (NASDAQ:RKLB) stands against other Friday's best-performing stocks. Rocket Lab grew its share prices by 9.34 percent on Friday to finish at $28.92 apiece as investors loaded up portfolios ahead of its launch of a new mission on Tuesday. Rocket Lab Corp. (NASDAQ:RKLB) is scheduled to launch The Mountain God Guards mission for the Institute for Q-shu Pioneers of Space, Inc. (iQPS), a Japan-based Earth imaging company, through 'Electron,' the world's most frequently launched orbital small rocket. The mission will launch a single synthetic aperture radar imaging satellite called QPS-SAR-11 to a 575-kilometer circular Earth orbit, which will join the rest of the iQPS constellation in providing high-resolution images and Earth monitoring services globally. A launch pad atop a grassy hill, smoke filled sky from a successful voyage to space. The launch will take place at Rocket Lab Corporation's (NASDAQ:RKLB) Launch Complex 1 in New Zealand. Rocket Lab Corporation (NASDAQ:RKLB) said that The Mountain God Guards will mark its 8th mission for this year alone, its 4th out of the 8 missions dedicated to iQPS, its 66th Electron launch overall, and the 227th satellite delivered to space. Overall, RKLB ranks 9th on our list of Friday's best-performing stocks. While we acknowledge the potential of RKLB as an investment, our conviction lies in the belief that some AI stocks hold greater promise for delivering higher returns and have limited downside risk. If you are looking for an extremely cheap AI stock that is also a major beneficiary of Trump tariffs and onshoring, see our free report on the best short-term AI stock. READ NEXT: 20 Best AI Stocks To Buy Now and 30 Best Stocks to Buy Now According to Billionaires. Disclosure: None. This article is originally published at Insider Monkey.