Tag: windows
-
Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS
A cross-platform malware campaign that disguises itself as a legitimate Zoom installer to deploy Overlord, an open-source remote access trojan (RAT), on both macOS and Windows machines. Documented by Jamf, unlike most macOS malware, which typically relies on Go or Rust for cross-platform reach, this campaign’s first-stage downloader, a macOS ARM64 Mach-O binary named ZoomMeetings,…
-
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.”These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,”…
-
Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts
Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometric verification, or password. Mollema’s research demonstrates how attackers can effectively “borrow” the cryptographic key that underlies Windows Hello…
-
Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
Google has released Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update delivers 41 security fixes across various components of the browser, including rendering, graphics, JavaScript, user interface (UI), media, and authentication. The Stable channel update began rolling out on August 6 and will reach users over the next several…
-
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and First seen on…
-
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices First…
-
Hackers Can Abuse Microsoft WSUS Servers to Deploy Malicious Updates via NTLM Relay
Security researchers have shown how attackers could exploit Microsoft Windows Server Update Services (WSUS) infrastructure to distribute malicious software updates across enterprise networks. This technique relies on NTLM authentication coercion and relay attacks targeting WSUS deployments that utilize a separate Microsoft SQL Server database. WSUS is commonly used by organizations to centrally manage, approve, and…
-
Day 2 at Black Hat: Check Point Research Takes the Stage
ay two at Black Hat, and Check Point Research brought two talks to the stage that gave the room plenty to think about. One dug into afifteen year oldblind spot sitting inside Windows itself. The other pulled apart the agent frameworks powering today’s AI products and found familiar bugs wearing new clothes. Here’swhat our researchers…
-
Fake Xeno Roblox Executor Delivers Powercat Java Stealer Through Discord
The fake “undetected” Xeno Roblox executor currently circulating on gaming forums and Discord is a weaponized loader for the Powercat Java stealer, a multi”‘stage RAT and infostealer that targets Discord, Roblox, Minecraft, crypto wallets and payment tokens while enabling full remote control of infected Windows systems. Threat actors are promoting trojanized Xeno executors through Roblox”‘focused…
-
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine.Huntress, which tracks the…
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. First seen on hackread.com Jump to article: hackread.com/octlurk-silklurk-backdoors-target-6-countries/
-
Impacket for Pentester: reg
Overview The Windows registry is a hierarchical database that governs application behaviour, user profiles, service configurations, security policies, and system startup. For penetration testers, remote First seen on hackingarticles.in Jump to article: www.hackingarticles.in/impacket-for-pentester-reg/
-
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long”‘running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders’ visibility where command”‘and”‘control (C2) traffic never touches traditional DNS. The attackers added just two lines of JavaScript to an internal Electron renderer HTML file, causing the app…
-
ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates
ScreenConnect is being systematically weaponized in the SMOKE#SCREEN campaign, where attackers hide execution windows, delete installers, and disguise malicious activity as routine software updates to plant fully functional, signed ScreenConnect agents across Windows and macOS endpoints. The result is persistent, “legitimate-looking” remote access that blends into normal IT operations while silently bypassing user awareness and…
-
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/05/fake-bank-of-america-email-account-guard/
-
7-Zip Default Setting Lets Extracted Files Bypass Windows SmartScreen
7-Zip’s default configuration allows files extracted from internet-delivered archives to shed the Mark of the Web (MotW), meaning Windows SmartScreen never runs its reputation check and unsigned payloads can execute without a “Windows protected your PC” warning. That behavior, long treated as a red-team trick, is now formally recognized and tracked in multiple 7-Zip vulnerabilities,…
-
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users.According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to…
-
New Google Password Manager Attacks Can Hijack Synced Passkeys
Three Pass-ta-key attacks show how malware on compromised Windows devices could hijack accounts protected by passkeys synced through Google Password Manager. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-password-manager-synced-passkey-attacks/
-
Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
Researchers at Huntress have identified an active phishing campaign impersonating Bank of America that culminates in the covert installation of a remote monitoring and management (RMM) tool, giving attackers persistent, hard-to-detect access to victims’ Windows machines. The campaign was flagged after a message landed in one of Huntress’s spamtrap accounts on 28 July, sent from…
-
Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint
Security researchers have revealed a series of attacks that could enable malware on a compromised Windows device to hijack accounts protected by Google-synced passkeys. This can occur without stealing a password, capturing a fingerprint, or requiring the victim to unlock their device. In research published on August 23, 2023, Palo Alto Networks’ Unit 42 detailed…
-
New Passkey attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager’s synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/
-
New DOUBLECUP ClickFix service hides malware in browser cache images
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/
-
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen.Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets…
-
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support
Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/elastic-defend-vulnerable-driver-detection/
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TAG-195 Upgrades MaaS Ecosystem with Modular Tools Inside a DPRK BlueNoroff ClickFix Kit SourTrade: Browser-Assembled Malware Delivered Through Malvertising MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions Unpacking “Cruciferra”: An Analysis of a…
-
Lautlose Systemübernahme: MedusaHVNC kapert unbemerkt Windows-Desktops
Tags: windowsDie Schadsoftware MedusaHVNC nutzt unsichtbare Windows-Desktops für Fernzugriffe. Angreifer starten dort Browser und umgehen Entdeckungsmethoden. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/windows-medusahvnc
-
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-151-370-vulnerabilities/
-
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that First…

