Find notable cyber news and cases, enriched with sources, timelines, and signals.

Microsoft Windows October 2025 security update smart card and certificate disruption

Service Disruption
First reported
Last updated
Happening score
H score 0
1 unique sources, 1 articles

Summary

Hide ▲

Microsoft's October 2025 Windows security updates are causing smart card authentication and certificate-based authentication failures across Windows 10, Windows 11, and Windows Server, disrupting document signing and access on affected systems. The issue comes from a hardening change in Windows Cryptographic Services that shifts RSA smart card certificates from CSP to KSP. Microsoft says affected users can temporarily work around the problem by setting DisableCapiOverrideForRSA to `0`, with the registry key slated for removal in April 2026.

Related Happenings

Microsoft Windows Autopatch fix for EU restricted driver update deployment bug

Security Tool/Service
First: 13.05.2026 17:36 Last: 13.05.2026 17:36 Sources 1

About this happening: **Microsoft** fixed a **Windows Autopatch** service bug that let **restricted driver updates** reach some managed devices in the **EU**, bypassing admin approval controls and crea...

Microsoft May 2026 Patch Tuesday release

Security Patch Release
First: 13.05.2026 13:36 Last: 13.05.2026 13:36 Sources 1

About this happening: Microsoft's **May 13, 2026 Patch Tuesday** release fixed **138 vulnerabilities** across its product portfolio, including **Windows**, **Azure**, and **Edge**. None of the flaws we...

Windows 10 KB5087544 extended security update

Security Patch Release
First: 12.05.2026 21:58 Last: 12.05.2026 21:58 Sources 1

About this happening: **Microsoft** released **Windows 10 KB5087544** for **Windows 10 ESU/LTSC systems**, addressing **May 2026 Patch Tuesday vulnerabilities** and a **Remote Desktop warnings** issue....

Microsoft Defender false-positively flags DigiCert root certificates and removes some from Windows trust store

Security Tool/Service
First: 03.05.2026 21:11 Last: 03.05.2026 21:11 Sources 1

About this happening: **Microsoft Defender** began falsely flagging valid **DigiCert root certificates** as **Trojan:Win32/Cerdigent.A!dha**, creating widespread false positives and risking certificate...

Microsoft out-of-band security update for ASP.NET Core Data Protection (CVE-2026-40372)

Security Patch Release
First: 22.04.2026 11:08 Last: 22.04.2026 11:08 Sources 1

About this happening: **Microsoft** released **out-of-band security updates** for **CVE-2026-40372**, an **ASP.NET Core Data Protection** flaw that could let attackers forge authentication cookies and...

Timeline

  1. 20.10.2025 17:21 2 articles · 7mo ago

    Microsoft Windows October 2025 security update smart card and certificate disruption

    Initial Disclosure

    After installation of the **October 2025 Windows security update**, some systems began failing **smart card** and **certificate-based** operations. Microsoft linked the breakage to a security hardening change in **Windows Cryptographic Services**.

    Show sources