Microsoft Initiates Removal of Insecure RC4 Encryption in Windows Update

Microsoft Initiates Removal of Insecure RC4 Encryption in Windows Update

First seen 19 Jan 2026, 18:32 UTC Heise.De 21.4

Article Content

Browse articles
ThreatCluster

Microsoft's January Patchday updates address a security vulnerability in Kerberos authentication and mark the beginning of the phase-out of the insecure RC4 encryption method. The patch aims to enhance the security of Kerberos by mitigating potential information leaks associated with RC4. Users of Windows systems utilizing Kerberos authentication are affected by this update.