Tag: windows
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance,…
-
Microsoft releases Windows 10 KB5120249 extended security update
Microsoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-10-kb5120249-cumulative-update-released-with-fixes/
-
Windows 11 KB5121003 & KB5120240 cumulative updates released
Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-kb5121003-and-kb5120240-cumulative-updates-released/
-
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
Cisco warns that seven ClamAV flaws affect Secure Endpoint Connector products, with two having public PoCs that could enable remote DoS attacks. Cisco warned that seven ClamAV vulnerabilities affect its Secure Endpoint Connector on Windows, macOS and Linux. ClamAV is an open-source antivirus engine widely used to scan files and emails for malware. The company…
-
Plug Pwn Attack Exploits Windows PnP to Gain SYSTEM Access With Zero Clicks
Security researchers Alejandro Hernando, also known as 0xedh, and Borja MartÃnez have unveiled a research project titled >>Plug & Pwn.<< This project demonstrates how the Windows Plug and Play (PnP) driver installation workflows can be exploited to execute vendor-supplied code with NT AUTHORITY\SYSTEM privileges. Presented at DEF CON 34, the research explores the risky intersection…
-
New Passkey attack reveals all the things we didn’t know about passkeys
Why passkey apps treat Windows differently than other operating systems. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/08/heres-why-the-new-pass-ta-key-attack-is-mostly-a-nothingburger/
-
Kein Klick nötig: PlugPwn-Angriff kapert Windows-Systeme per USB
Windows lädt beim Anschließen neuer USB-Geräte oft Software nach. Angreifer können dadurch Systemrechte erlangen – manchmal sogar aus der Ferne. First seen on golem.de Jump to article: www.golem.de/news/kein-klick-noetig-plug-and-pwn-angriff-kapert-windows-systeme-per-usb-2608-211809.html
-
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine.The same PnP path can be triggered over Remote Desktop without physical hardware when supported Plug and Play or low-level USB…
-
ErrTraffic Combines WordPress Hacks, Blockchain C2 and Rotating Malware Domains in One Delivery Network
An active ErrTraffic malware-as-a-service campaign that combines compromised WordPress sites, ClickFix lures, Polygon blockchain smart contracts and rapidly rotating payload domains to distribute a broad set of Windows malware. ErrTraffic is marketed as a MaaS framework by a forum user known as “LenAI.” Its core feature is a traffic distribution system that routes victims to…
-
DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Files
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered to survive disruption. First observed in July 2025, the operation uses double extortion: encrypting enterprise data while threatening publication of stolen material. The encryptor’s pre-encryption routine is built to degrade both prevention and recovery. After XOR-decoding an embedded configuration,…
-
PassPasskey Attack Exploits Windows and Entra ID to Bypass MFA
Tags: attack, authentication, credentials, cyber, exploit, mfa, microsoft, passkey, phishing, windowsSecurity researchers have recently revealed a new attack family named “Pass-the-Passkey,” which enables adversaries to impersonate enterprise users and circumvent phishing-resistant multi-factor authentication (MFA) protections in Windows 11 and Microsoft Entra ID environments. This research challenges the belief that passkeys are inherently immune to credential replay and session abuse. Pass-the-Passkey Attack Exploits Windows The attack…
-
Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users
Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/entra-id-windows-hello-macos-psso-standalone-mfa/
-
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Tags: attack, authentication, cloud, cryptography, data-breach, malware, mfa, passkey, password, phishing, windowsThree separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim’s machine, and used a First…
-
Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration
Play ransomware is using a familiar Windows-administration disguise to reduce suspicion during intrusions: a custom service binary named PSexesvc.exe. The group’s use of a custom service binary named PSexesvc.exe, mimicking Microsoft Sysinternals PsExec, illustrates how attackers can turn routine Windows administration into cover for lateral movement and payload execution. The binary has been observed alongside…
-
Curl-Entwickler sucht Verstärkung: Niemand hier will mit Windows arbeiten
Der Open-Source-Entwickler Daniel Stenberg sucht Helfer für das Curl-Security-Team. Die derzeitigen sieben Mitglieder haben alle eine Windows-Aversion. First seen on golem.de Jump to article: www.golem.de/news/curl-entwickler-sucht-verstaerkung-niemand-hier-will-mit-windows-arbeiten-2608-211760.html
-
North Korean Hackers Explore AI Transcription for Stolen Calls and Meetings
Tags: ai, breach, cyber, hacker, intelligence, korea, malicious, north-korea, phishing, powershell, spear-phishing, windowsNorth Korea-linked Kimsuky operators are expanding their artificial intelligence capabilities, with newly observed evidence showing experimentation with local large language models. Retrieval-augmented generation, AI agents, and speech-to-text tooling that could accelerate analysis of stolen calls, meetings, and documents. The operation retains Kimsuky’s established use of spear-phishing lures, malicious Windows shortcut files, PowerShell loaders, and Git-based…
-
Fake Zoom Installer Uses .NET Downloader to Deploy Overlord RAT on macOS
A cross-platform malware campaign that disguises itself as a legitimate Zoom installer to deploy Overlord, an open-source remote access trojan (RAT), on both macOS and Windows machines. Documented by Jamf, unlike most macOS malware, which typically relies on Go or Rust for cross-platform reach, this campaign’s first-stage downloader, a macOS ARM64 Mach-O binary named ZoomMeetings,…
-
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.”These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload,”…
-
Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts
Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometric verification, or password. Mollema’s research demonstrates how attackers can effectively “borrow” the cryptographic key that underlies Windows Hello…
-
Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
Google has released Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux. This update delivers 41 security fixes across various components of the browser, including rendering, graphics, JavaScript, user interface (UI), media, and authentication. The Stable channel update began rolling out on August 6 and will reach users over the next several…
-
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and First seen on…
-
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices First…
-
Hackers Can Abuse Microsoft WSUS Servers to Deploy Malicious Updates via NTLM Relay
Security researchers have shown how attackers could exploit Microsoft Windows Server Update Services (WSUS) infrastructure to distribute malicious software updates across enterprise networks. This technique relies on NTLM authentication coercion and relay attacks targeting WSUS deployments that utilize a separate Microsoft SQL Server database. WSUS is commonly used by organizations to centrally manage, approve, and…
-
Day 2 at Black Hat: Check Point Research Takes the Stage
ay two at Black Hat, and Check Point Research brought two talks to the stage that gave the room plenty to think about. One dug into afifteen year oldblind spot sitting inside Windows itself. The other pulled apart the agent frameworks powering today’s AI products and found familiar bugs wearing new clothes. Here’swhat our researchers…
-
Fake Xeno Roblox Executor Delivers Powercat Java Stealer Through Discord
The fake “undetected” Xeno Roblox executor currently circulating on gaming forums and Discord is a weaponized loader for the Powercat Java stealer, a multi”‘stage RAT and infostealer that targets Discord, Roblox, Minecraft, crypto wallets and payment tokens while enabling full remote control of infected Windows systems. Threat actors are promoting trojanized Xeno executors through Roblox”‘focused…
-
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine.Huntress, which tracks the…
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. First seen on hackread.com Jump to article: hackread.com/octlurk-silklurk-backdoors-target-6-countries/
-
Impacket for Pentester: reg
Overview The Windows registry is a hierarchical database that governs application behaviour, user profiles, service configurations, security policies, and system startup. For penetration testers, remote First seen on hackingarticles.in Jump to article: www.hackingarticles.in/impacket-for-pentester-reg/
-
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long”‘running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders’ visibility where command”‘and”‘control (C2) traffic never touches traditional DNS. The attackers added just two lines of JavaScript to an internal Electron renderer HTML file, causing the app…

