Microsoft faces fresh Windows Recall security concerns

Microsoft's Windows Recall feature, which captures continuous screenshots and sensitive data, faces renewed security vulnerabilities after a year-long redesign intended to address privacy concerns—a researcher demonstrated that malware can bypass the security vault by forcing user authentication and extracting all captured data, undermining Microsoft's core security promises. This exposes IT organizations to significant risk of data exfiltration, as Recall captures far more than passwords, including emails, messages, and browsing history, creating a high-value target for attackers. Organizations must reassess their deployment strategy for Copilot Plus PCs and establish controls to manage the security posture of this feature across their enterprise environment.

The Verge2 min read
Read full article
Microsoft faces fresh Windows Recall security concerns
When Microsoft tried to launch Recall, an AI-powered Windows feature that screenshots most of what you do on your PC, it was labeled a "disaster" for cybersecurity and a "privacy nightmare." After the backlash and a year-long delay to redesign and secure Recall, it's once again facing security and privacy concerns. Cybersecurity expert Alexander Hagenah has created TotalRecall Reloaded, a tool that extracts and displays data from Recall. It's an update to the TotalRecall tool that demonstrated all the weaknesses in the original Recall feature before Microsoft redesigned it. Microsoft's redesign focused on creating a secure vault for Recall … Read the full story at The Verge.