Tag: windows
-
PupkinStealer Targets Windows Users to Steal Browser Login Credentials
A newly identified information-stealing malware dubbed PupkinStealer has emerged as a significant threat to Windows users, with its first sightings reported in April 2025. Written in C# using the .NET framework, this malicious software is engineered to pilfer sensitive data, including browser credentials, messaging app sessions from platforms like Telegram and Discord, desktop documents, and…
-
Microsoft Defender for Business Server – Malwareschutz für Windows- und Linux-Server
First seen on security-insider.de Jump to article: www.security-insider.de/microsoft-defender-business-server-malwareschutz-kmu-a-3580f6c82997dd284a31b4e1842dcc7e/
-
Nach Windows-10-Ende 365-Apps sollen bis 2028 Sicherheitsupdates erhalten
Wenn der Support für Windows 10 endet, sollen die Microsoft-365-Apps weiterhin noch Sicherheitsupdates erhalten. First seen on computerbase.de Jump to article: www.computerbase.de/news/betriebssysteme/nach-windows-10-ende-microsoft-365-apps-sollen-bis-2028-sicherheitsupdates-erhalten.92595
-
“PupkinStealer” .NET Malware Steals Browser Data and Exfiltrates via Telegram
A new information-stealing malware dubbed “PupkinStealer” has emerged as a significant threat to individuals and enterprises. Developed in C# using the .NET framework, this 32-bit GUI-based Windows executable targets sensitive user data with a focused and efficient approach. First observed in April 2025, PupkinStealer is designed to harvest a specific range of data, including browser…
-
Defendnot: A Tool That Disables Windows Defender by Registering as Antivirus
Cybersecurity developers have released a new tool called >>defendnot,>no-defender
-
Microsoft 365: Support für Office-Apps unter Windows 10 plötzlich erweitert
Entgegen früheren Angaben will Microsoft Windows-10-Nutzer nun doch noch weiter mit Sicherheitsupdates für Office-Anwendungen versorgen. First seen on golem.de Jump to article: www.golem.de/news/windows-10-support-fuer-microsoft-365-apps-ueberraschend-erweitert-2505-196095.html
-
Windows 10: Support für Microsoft-365-Apps überraschend erweitert
Entgegen früheren Angaben will Microsoft Windows-10-Nutzer nun doch noch weiter mit Sicherheitsupdates für Office-Anwendungen versorgen. First seen on golem.de Jump to article: www.golem.de/news/windows-10-support-fuer-microsoft-365-apps-ueberraschend-erweitert-2505-196095.html
-
Securing Windows Endpoints Using Group Policy Objects (GPOs): A Configuration Guide
Securing Windows endpoints is a top priority for organizations seeking to protect sensitive data and maintain operational integrity. Group Policy Objects (GPOs) are among the most effective tools for IT administrators to manage and enforce security settings across all domain-joined computers. When properly designed and implemented, GPOs provide a scalable, centralized way to minimize vulnerabilities,…
-
North Korea’s OtterCookie Malware Added a New Feature to Attack Windows, Linux, and macOS
A North Korea-linked attack group, known as WaterPlum (also referred to as Famous Chollima or PurpleBravo), has been actively targeting financial institutions, cryptocurrency operators, and FinTech companies globally. Since 2023, their infamous Contagious Interview campaign has utilized malware such as BeaverTail and InvisibleFerret to infiltrate systems. However, in September 2024, WaterPlum introduced a sophisticated new…
-
Cyber Then & Now: Inside a 2-Decade Industry Evolution
On Dark Reading’s 19-year anniversary, Editor-in-Chief Kelly Jackson Higgins stops by Informa TechTarget’s RSAC 2025 Broadcast Alley studio to discuss how things have changed since the early days of breaking Windows and browsers, lingering challenges, and what’s next beyond AI. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/cyber-then-now-2-decade-industry-evolution
-
After that 2024 Windows fiasco, CrowdStrike has a plan job cuts, leaning on AI
CEO: Neural net tech ‘flattens our hiring curve, helps us innovate’ First seen on theregister.com Jump to article: www.theregister.com/2025/05/07/crowdstrike_trims_workforce_ai/
-
Bericht von Google Day-Schwachstellen in Windows nehmen zu
First seen on security-insider.de Jump to article: www.security-insider.de/cyberkriminalitaet-zero-day-sicherheitsluecken-betriebssysteme-a-b9c06d4f74bc56172debe3883aaefdf2/
-
New Mamona Ransomware Targets Windows Systems Using Abused Ping Command
Cybersecurity researchers are raising the alarm about a newly discovered commodity ransomware strain dubbedMamona, which is rapidly spreading across Windows systems. Unlike traditional ransomware, Mamona employs a unique set of tactics, notably exploiting the humble Windows “ping” command as a timing mechanism, and operates entirely offline, making detection and response more difficult. Emerging on the…
-
Hackers Exploit PDF Invoices to Target Windows, Linux, and macOS Systems
A recent discovery by the FortiMail Incident Response team has revealed a highly sophisticated email campaign targeting organizations in Spain, Italy, and Portugal. This attack distributes a potent Remote Access Trojan (RAT) known as RATty, primarily affecting Windows systems, but also posing a threat to Linux and macOS environments where the Java Runtime Environment (JRE)…
-
Hackers Exploit Windows Remote Management to Evade Detection in AD Networks
A new wave of cyberattacks is targeting Active Directory (AD) environments by abusing Windows Remote Management (WinRM), a legitimate administrative tool, to move laterally and evade detection across enterprise networks. Security researchers and incident responders are raising alarms as attackers increasingly leverage WinRM to blend in with normal network activity, making their malicious actions harder…
-
Play Ransomware Deployed in the Wild Exploiting Windows 0-Day Vulnerability
Patched Windows zero-day vulnerability (CVE-2025-29824) in the Common Log File System (CLFS) driver was exploited in attacks linked to the Play ransomware operation prior to its disclosure on April 8, 2025. The flaw, which enabled privilege escalation via a use-after-free condition in the clfs.sys kernel driver, was weaponized by Balloonfly, the cybercrime group behind Play…
-
Fedora Linux Joins the Windows Subsystem for Linux Officially
Fedora Project has announced the official availability of Fedora Linux on the Windows Subsystem for Linux (WSL), marking a significant expansion of Fedora’s ecosystem. Starting with Fedora 42, users can now seamlessly integrate Fedora’s cutting-edge tools and development environment directly into Windows via WSL’s tar-based architecture. This integration empowers developers and enthusiasts to leverage Fedora’s…
-
Microsoft Launches >>Copilot+ PC<< for an Upgraded Windows Experience
Microsoft has announced a significant wave of new Windows experiences designed for Copilot+ PCs, which the company describes as >>the fastest, most intelligent and most secure Windows PCs ever built.
-
Microsoft OneDrive move may facilitate accidental sensitive file exfiltration
want to make syncing easier, as it can create lots of security and IT headaches.The rollout was originally scheduled for this weekend (May 11), but sometime late on Thursday, the Microsoft page about the feature was changed to say that it was being pushed out in June. Microsoft did not immediately explain the delay, but discussions…
-
The 12 KB that Windows just can’t seem to quit
Tags: windowsIcons from a more civilized time First seen on theregister.com Jump to article: www.theregister.com/2025/05/08/moricons_dll_raymond_chen/
-
Microsoft updates the Windows 11 Start Menu
Plus it is solving the ‘I can’t find the settings’ problem with AI. That’s what you wanted, right? First seen on theregister.com Jump to article: www.theregister.com/2025/05/07/microsoft_updates_the_windows_11/
-
Windows CLFS zero-day leveraged in Play ransomware attacks
First seen on scworld.com Jump to article: www.scworld.com/brief/windows-clfs-zero-day-leveraged-in-play-ransomware-attacks
-
IXON VPN Client Vulnerability Allows Privilege Escalation for Attackers
A critical security vulnerability in IXON’s widely used VPN client has exposed Windows, Linux, and macOS systems to local privilege escalation attacks, enabling non-privileged users to gain root or SYSTEM-level access. Designated as CVE-2025-26168 and CVE-2025-26169, these flaws affect versions 1.4.3 and earlier of the software, posing severe risks to industrial, enterprise, and managed service…
-
Nmap 7.96 Released with Enhanced Scanning Capabilities and Updated Libraries
The popular network mapping and security auditing tool Nmap has released version 7.96, featuring a host of significant improvements. This latest version introduces parallel forward DNS resolution for dramatically faster hostname scanning, upgraded core libraries, new scripting capabilities, and enhanced compatibility across platforms, especially for Windows users. One of the headline features in Nmap 7.96…
-
How to capture forensic evidence for Microsoft 365
Tags: access, antivirus, attack, authentication, cloud, compliance, control, data, firewall, microsoft, network, risk, risk-management, windowsA Microsoft 365 E5 license (E5, E5 Compliance, or E5 Insider Risk Management)Workstations that run Windows 11 Enterprise with Microsoft 365 applicationsDevices joined via Microsoft Entra with certain Defender antivirus versions and application versions on boardOnly organizations that meet those criteria will be able to run Microsoft Purview Insider Risk Management to get the forensic…
-
Windows flaw exploited as zero-day by more groups than previously thought
Attackers managed to deploy infostealer: In this attack, the Balloonfly group didn’t get to the stage of deploying the Play ransomware, as that is usually one of the final stages when attackers have control over significant parts of the network for maximum damage. However, the group did deploy an infostealer called Grixba that’s usually part…
-
After that 2024 Windows fiasco, CrowdStrike has a plan jobs cuts, leaning on AI
CEO: Neural net tech ‘flattens our hiring curve, helps us innovate’ First seen on theregister.com Jump to article: www.theregister.com/2025/05/07/crowdstrike_trims_workforce_ai/
-
Windows Server: April 2025-Updates Windows Hello-Problem und Kerberos-Ereignisse bestätigt
Die Sicherheitsupdates vom April 2025 für Windows Server können Probleme bei Domänencontrollern verursachen, so dass die Kerberos-Ereignis-IDs 45 und 21 protokolliert werden. Microsoft hat dieses Problem bestätigt und schreibt, dass die Anmeldung mit Windows Hello im Key Trust-Modus fehlschlagen kann. … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/05/08/windows-server-april-2025-updates-windows-hello-problem-und-kerberos-ereignisse-bestaetigt/

