Tag: windows
-
5 Palo Alto GlobalProtect Flaws Let Attackers Gain SYSTEM/Root Access and Steal AD Passwords
Security researcher Martijn van Ramesdonk has disclosed five vulnerabilities affecting Palo Alto Networks’ GlobalProtect, an enterprise VPN and endpoint agent widely used across corporate environments on Windows, macOS, and Linux. The issues include local privilege escalation vulnerabilities that could allow a low-privileged attacker with access to an endpoint to gain full SYSTEM privileges on Windows…
-
Fake Minecraft Clients Spread WeedHack Malware on Windows to Steal Passwords
Fake Minecraft clients are delivering WeedHack malware that steals gaming sessions, browser passwords, crypto wallets and personal files from infected Windows systems. First seen on hackread.com Jump to article: hackread.com/fake-minecraft-clients-weedhack-malware-windows-passwords/
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups.According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) First seen…
-
WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that’s used to deliver next-stage payloads and likely sell access to ransomware groups.According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stealer or AcridRain Stealer) via ClearFake campaigns, which employ the ClickFix (aka FakeCaptcha) First seen…
-
North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access
Tags: access, cyber, email, hacker, korea, malicious, north-korea, phishing, powershell, software, spear-phishing, theft, windowsNorth Korea-linked Kimsuky operators have targeted organizations in South Korea and Japan with spear-phishing campaigns that install and conceal AnyDesk, giving attackers persistent, interactive remote access while blending into legitimate software activity. The operation combines OneDrive-hosted lures, malicious Windows shortcut files, scheduled-task persistence, PowerShell payloads, and email theft across Thunderbird, Outlook, and Gmail. The archives…
-
Microsoft shares temporary fix for Windows 11 gaming issues
Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-shares-temporary-fix-for-windows-11-gaming-issues/
-
New SynkLoader Malware Uses Fake Windows Lock Screen to Steal Passwords and Pivot Networks
SynkLoader, a newly identified modular malware framework that combines Python, C#, C++, PowerShell, and memory-resident payloads to evade endpoint detection. Delivered through Microsoft Teams phishing, the operation uses a convincing fake Windows lock screen to capture credentials before enabling network tunneling and interactive access to compromised enterprise environments. Compile timestamps and file metadata indicate the…
-
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that’s targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors.The vast majority of the targets are located in Brazil, Bolivia, China, Canada, and Vietnam. Details of the threat activity came to light following the discovery of an…
-
Windows 11 Update Triggers Game Crashes on Systems With RGB Lighting Drivers
Microsoft is currently investigating a compatibility issue with Windows 11, in which certain games crash, freeze, or cause unexpected system restarts on devices equipped with RGB lighting hardware and related low-level drivers. This problem was reported following the release of Windows updates on August 11, 2026, including the KB5121003 update for OS Build 26100.9168. Microsoft…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111
Tags: banking, botnet, edr, infrastructure, international, linux, malware, ransomware, spyware, windowsSecurity Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” StubMaker RubyGems Campaign Delivers a Windows Infostealer Hunting MacSync Stealer infrastructure through behavioral pivots Manic: Blend between Banking Malware & Spyware […]…
-
Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/23/week-in-review-records-allegedly-stolen-from-azure-tenants-medusa-ransomware-hits-500-orgs/
-
Researchers find way to weaponize Windows Defender’s own driver
Tags: windowsFirst seen on scworld.com Jump to article: www.scworld.com/brief/researchers-find-way-to-weaponize-windows-defenders-own-driver
-
Named Pipes Under Attack: Securing Windows Interprocess Communication
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing-windows-interprocess-communication/
-
Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research has disclosed a technique that uses Microsoft Defender’s own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no driver imported from outside the machine.The driver, BTR.sys (Boot Time Removal Tool),…
-
Windows 11 24H2 Home and Pro Support Ends Oct. 13: What Users Should Do
Tags: windowsWindows 11 24H2 Home and Pro support ends Oct. 13, 2026. Here’s what users and IT teams should know about upgrading to Windows 11 25H2. The post Windows 11 24H2 Home and Pro Support Ends Oct. 13: What Users Should Do appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-windows-11-24h2-end-support-october-2026/
-
Microsoft blames Windows gaming issues on RGB lighting devices
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-blames-windows-gaming-issues-on-rgb-lighting-devices/
-
Hackers abuse FTP server banners to deliver new Windows malware
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-abuse-ftp-server-banners-to-deliver-new-windows-malware/
-
UAT-10147 Compromises Web Servers to Deploy BadIIS for SEO Fraud and Data Theft
Tags: china, cyber, cybercrime, data, data-breach, finance, fraud, government, group, linux, malware, technology, theft, vulnerability, windowsA Chinese-speaking cybercrime group, tracked as UAT-10147, targeting vulnerable Windows and Linux web servers worldwide to deploy BadIIS malware, steal data, and manipulate search engine results for financial gain. Talos observed victims in Brazil, Bolivia, China, Canada, and Vietnam, spanning government, education, media, technology, and gaming organizations. An operational security lapse exposed an attacker download…
-
Windows Defender Driver Abuse Enables Kernel-Level EDR and Antivirus Bypass
Security researcher Jiřà Vinopal has published a detailed analysis of BTR.sys, the Microsoft Defender Boot-Time Removal driver. His research reveals how this legitimate, Microsoft-signed component can be exploited to perform file and registry operations under attacker control from kernel mode. This study, titled >>BTR Reforged,<< does not rely on traditional memory-corruption vulnerabilities or the Bring…
-
Windows 11 Hotpatching Explained: How Much Does It Really Reduce Reboots?
Windows 11 hotpatching can install security updates without reboots. Learn who qualifies, how the update cycle works, and what IT teams should expect. The post Windows 11 Hotpatching Explained: How Much Does It Really Reduce Reboots? appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-windows-11-hotpatching-reboots/

