Tag: endpoint
-
How RMM abuse gives attackers a way in that looks like business as usual
Huntress found attackers using legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the first quarter of 2026. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/10/05/remote-monitoring-and-management-rmm-abuse/
-
The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/the-edr-blind-spot-3-ways-browser-attacks-evade-endpoint-telemetry/
-
Windows 11 26H2 Enables Settings Backup by Default for Eligible Devices
Microsoft has automatically enabled Windows settings backup for eligible commercial devices running Windows 11, version 26H2. Microsoft positions this capability as a vital resilience measure for enterprise endpoint recovery. The change is applicable when organizations have left the relevant backup policy in a “Not Configured” state. Administrators’ decisions to explicitly turn the feature on or…
-
RMM abuse behind 45% of endpoint incidents as Huntress publishes inaugural Tragic Quadrant
Huntress has published the Huntress Tragic Quadrant, a ranking of the cyber tactics its Security Operations Center (SOC) is detecting and shutting down most often, plotted against what the company calls >>pucker factor<<: how close each tactic puts an organisation to major damage once it lands. Built on telemetry from more than 5 million endpoints…
-
China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor
A China-nexus cyber-espionage campaign that compromised approximately 350 endpoints across Asia using a previously undocumented Rust-based Windows backdoor called Antino. The activity cluster, tracked as UAT-11587, targeted government, defense, diplomatic, policy, academic and civil-society organizations in at least eight countries between September 2025 and July 2026. Talos identified 10 confirmed and five probable affected institutional…
-
China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor
A China-nexus cyber-espionage campaign that compromised approximately 350 endpoints across Asia using a previously undocumented Rust-based Windows backdoor called Antino. The activity cluster, tracked as UAT-11587, targeted government, defense, diplomatic, policy, academic and civil-society organizations in at least eight countries between September 2025 and July 2026. Talos identified 10 confirmed and five probable affected institutional…
-
China-Nexus Hackers Compromise 350 Systems Across Asia With New Antino Backdoor
A China-nexus cyber-espionage campaign that compromised approximately 350 endpoints across Asia using a previously undocumented Rust-based Windows backdoor called Antino. The activity cluster, tracked as UAT-11587, targeted government, defense, diplomatic, policy, academic and civil-society organizations in at least eight countries between September 2025 and July 2026. Talos identified 10 confirmed and five probable affected institutional…
-
Hackers Hide Microsoft Defender Exclusions From Admins to Evade Antivirus Scans
Threat actors are increasingly abusing Microsoft Defender Antivirus exclusions to keep malicious files outside the reach of endpoint scans, and a little-known policy setting can conceal those exclusions from administrators using normal management tools. Huntress researchers found that attackers can combine broad Defender exclusions with the HideExclusionsFromLocalAdmins setting, creating a stealthy defense-evasion path that leaves…
-
OWASP Noir: Open-source static analysis tool
OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/30/owasp-noir-open-source-static-analysis-tool/
-
Attackers Hid Behind Trusted RMM Software Before Deploying a Full Surveillance RAT
Threat actors are abusing trusted remote monitoring and management (RMM) software to gain legitimate-looking access to Windows endpoints before deploying a previously undocumented .NET remote access trojan dubbed AgtaBackup RAT. The operation starts with a fraudulent Microsoft Store-style page impersonating a popular videoconferencing application, but ultimately hands the victim’s machine to an attacker-controlled RMM tenant.…
-
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK’s maintainers said in a security advisory.Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint…
-
New Windows Process Injection Technique Bypasses EDR Monitoring Without WriteProcessMemory
A newly disclosed method for Windows process injection utilizes redirected console input and named pipes to transfer payload data into a child process without invoking the heavily monitored APIs VirtualAllocEx and WriteProcessMemory. This technique, called console named-pipe injection, highlights the need for endpoint defenses to correlate events across processes, memory protection, thread context, and interprocess…
-
Uncensored Local AI Model Bypasses EDR to Dump Windows LSASS Credentials
A new demonstration shows how a locally hosted, uncensored AI model can help generate a Windows LSASS credential-dumping utility that reportedly evaded endpoint detection and response products during laboratory testing. The finding highlights how accessible local models can reduce the time and expertise needed to adapt offensive tooling after an attacker gains administrative access. Eddie…
-
Island Gets $400M to Take Worker Security Into the Agent Era
Non-Human Identity and Transient Networks Extend Controls Beyond Human Workers. Island raised $400 million at a $6.4 billion valuation to extend its worker-centric security platform to AI agents, applying data, identity, network, endpoint and observability controls to non-human workers while funding growth toward profitability and a potential IPO. First seen on govinfosecurity.com Jump to article:…
-
Public PoC Exposes Critical Veeam Agent Privilege Escalation
A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, not tomorrow. On September 14, 2026, public technical details…
-
Hackers Exploit Veeam Agent Vulnerability to Gain SYSTEM-Level Access on Windows
A newly discovered privilege escalation flaw in Veeam Agent for Microsoft Windows could allow attackers with local access to compromised endpoints to execute commands as NT AUTHORITY\SYSTEM. Public proof-of-concept (PoC) code for CVE-2026-32996 was released on September 14, increasing the urgency for organizations to patch affected Veeam deployments. CVE-2026-32996 impacts Veeam Agent for Microsoft Windows…
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…
-
New Rapuncel Infostealer Abuses Microsoft-Signed Driver to Disable 145 Security Tools
Tags: antivirus, credentials, crypto, cyber, data, detection, endpoint, exploit, intelligence, microsoft, mitigation, threat, tool, windowsA newly identified information-stealing campaign, tracked as Rapuncel, is exploiting a Microsoft-attested kernel driver to terminate up to 145 antivirus (AV) and endpoint detection and response (EDR) processes. This allows attackers to steal browser credentials, cryptocurrency wallet data, chat tokens, and Windows credentials. Researchers from the LastPass Threat Intelligence, Mitigation, and Escalation team, in collaboration…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco’s Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues
-
AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection
AI-powered malware is beginning to erode one of endpoint security’s oldest assumptions: that malicious code will remain stable long enough to identify, fingerprint, and block. A new class of threats uses large language models during execution to rewrite scripts, generate commands, and alter obfuscation on demand producing variants that can evade static hashes and traditional…
-
Mind Raises $72M to Rebuild DLP Around AI Agents
AI Agents Could Help Analysts Separate Meaningful Data Events From Routine Activity. Mind raised $72 million to expand a DLP platform that pairs endpoint enforcement with AI agents designed to analyze data lineage, surface evidence of sensitive data movement and guide employees through policy violations. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/mind-raises-72m-to-rebuild-dlp-around-ai-agents-a-32860
-
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.”This vulnerability is due to insufficient authentication control on an API endpoint,” Cisco said. “An attacker First seen on thehackernews.com…
-
GPT4Free Privacy Risks Expose AI Prompts to Third-Party Servers and Hidden Logs
Users of the GPT4Free hosted platform might believe they are directly interacting with the selected artificial intelligence model in its web interface. However, recent research suggests that prompts submitted through g4f.dev may travel through a complex network of provider code, intermediary services, external model endpoints, and potentially unrelated AI servers. These findings raise significant privacy…

