Microsoft has warned users about the ease with which hackers can spread malware through its Outlook email client. The tech giant has released a patch for the CVE-2025-21298 vulnerability, which it rated as 9.8 (critical) in severity. Microsoft advises users to view emails in plain text and turn off or restrict NTLM traffic if they are unable to apply the patch immediately. The vulnerability lies in the Windows Object Linking and Embedding function and could potentially lead to remote code execution.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.