:

MICROSOFT REMOVES WMIC TOOL FROM WINDOWS 11

SECURITY DESK1 MIN READ
TUE, AUG 18, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11, citing widespread abuse by cybercriminals. The tool is being eliminated from Windows 11 versions 24H2 and 25H2.

The WMIC utility, a command-line interface for system administration tasks, has become a favored tool for attackers executing malicious scripts and lateral movement within networks. By removing it, Microsoft aims to reduce attack surface and limit unauthorized system access. The deprecation applies to the latest Windows 11 builds, with the tool already absent from beta releases. Users relying on WMIC functionality can transition to PowerShell alternatives, which offer comparable capabilities with better security controls. This move aligns with Microsoft's broader security strategy of phasing out legacy tools exploited by threat actors. The company has previously deprecated similar utilities as part of efforts to harden Windows against evolving threats. Organizations running older Windows versions should begin planning migration strategies to PowerShell-based solutions. The removal does not affect currently supported versions immediately, providing time for compliance and transition planning.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Israel has established a fabricated think tank apparently designed to influence AI chatbot outputs and shape how these systems respond to queries about Israeli policy. The scheme highlights vulnerabilities in how large language models source and validate information.

5H AGOAI Desk

A threat actor claims to have stolen employee databases from Microsoft Azure infrastructure across multiple Fortune 500 companies using compromised credentials. The stolen records are now being offered for sale.

12H AGOAI Desk

Pokémon Center notified customers in the UK and Germany of a data breach affecting personal and order information. The breach occurred through third-party logistics provider CEVA Logistics, which was compromised by hackers.

13H AGOSecurity Desk

Australia's major supermarket chains Coles and Woolworths have confirmed testing facial recognition technology in their stores, sparking privacy concerns from advocates who warn the systems could normalize mass surveillance.

16H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.