Tag: windows
-
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. First seen on hackread.com Jump to article: hackread.com/octlurk-silklurk-backdoors-target-6-countries/
-
Impacket for Pentester: reg
Overview The Windows registry is a hierarchical database that governs application behaviour, user profiles, service configurations, security policies, and system startup. For penetration testers, remote First seen on hackingarticles.in Jump to article: www.hackingarticles.in/impacket-for-pentester-reg/
-
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long”‘running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders’ visibility where command”‘and”‘control (C2) traffic never touches traditional DNS. The attackers added just two lines of JavaScript to an internal Electron renderer HTML file, causing the app…
-
ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates
ScreenConnect is being systematically weaponized in the SMOKE#SCREEN campaign, where attackers hide execution windows, delete installers, and disguise malicious activity as routine software updates to plant fully functional, signed ScreenConnect agents across Windows and macOS endpoints. The result is persistent, “legitimate-looking” remote access that blends into normal IT operations while silently bypassing user awareness and…
-
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/05/fake-bank-of-america-email-account-guard/
-
7-Zip Default Setting Lets Extracted Files Bypass Windows SmartScreen
7-Zip’s default configuration allows files extracted from internet-delivered archives to shed the Mark of the Web (MotW), meaning Windows SmartScreen never runs its reputation check and unsigned payloads can execute without a “Windows protected your PC” warning. That behavior, long treated as a red-team trick, is now formally recognized and tracked in multiple 7-Zip vulnerabilities,…
-
QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
Cybersecurity researchers have disclosed what has been described as a “long-standing supply chain attack” on QuickFox, a virtual private network (VPN) and network acceleration tool designed for overseas Chinese users.According to Fortinet FortiGuard Labs, the supply chain attack has been ongoing since at least August 2025 and involves a trojanized version of the application to…
-
New Google Password Manager Attacks Can Hijack Synced Passkeys
Three Pass-ta-key attacks show how malware on compromised Windows devices could hijack accounts protected by passkeys synced through Google Password Manager. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-password-manager-synced-passkey-attacks/
-
Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
Researchers at Huntress have identified an active phishing campaign impersonating Bank of America that culminates in the covert installation of a remote monitoring and management (RMM) tool, giving attackers persistent, hard-to-detect access to victims’ Windows machines. The campaign was flagged after a message landed in one of Huntress’s spamtrap accounts on 28 July, sent from…
-
Malware Can Steal Google’s Synced Passkeys Without Password or Fingerprint
Security researchers have revealed a series of attacks that could enable malware on a compromised Windows device to hijack accounts protected by Google-synced passkeys. This can occur without stealing a password, capturing a fingerprint, or requiring the victim to unlock their device. In research published on August 23, 2023, Palo Alto Networks’ Unit 42 detailed…
-
New Passkey attacks let malware hijack Google-synced passkeys
Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager’s synced passkeys to take over accounts, bypass user verification, and extract passkey private keys. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/
-
New DOUBLECUP ClickFix service hides malware in browser cache images
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/
-
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen.Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest targets…
-
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support
Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/elastic-defend-vulnerable-driver-detection/
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TAG-195 Upgrades MaaS Ecosystem with Modular Tools Inside a DPRK BlueNoroff ClickFix Kit SourTrade: Browser-Assembled Malware Delivered Through Malvertising MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions Unpacking “Cruciferra”: An Analysis of a…
-
Lautlose Systemübernahme: MedusaHVNC kapert unbemerkt Windows-Desktops
Tags: windowsDie Schadsoftware MedusaHVNC nutzt unsichtbare Windows-Desktops für Fernzugriffe. Angreifer starten dort Browser und umgehen Entdeckungsmethoden. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/windows-medusahvnc
-
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now. The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-151-370-vulnerabilities/
-
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that First…
-
Certighost: PoC-Exploit ermöglicht Übernahme von Windows-Domänen
Ein PoC-Exploit für die Lücke Certighost in Windows AD CS zeigt, wie Angreifer Domänencontroller kapern und Krbtgt-Hashes auslesen können. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/windows-domaenen-poc
-
Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay
Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding environments. The post Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-cursor-git-code-execution-vulnerability-cve-2026-63093/
-
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,…
-
LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing access to resources associated with another account. This technique was published by the Nightmare-Eclipse disclosure actor shortly after Microsoft’s July 2026 Patch Tuesday. Unlike traditional software vulnerabilities, LegacyHive chains legitimate…
-
New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/
-
MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user never touches. It’s a niche capability most people never think about, buried deep in how the…
-
Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware
A newly uncovered cluster of more than 70 impersonation domains targeting popular Windows applications is raising fresh concerns about a scalable malware distribution campaign that leverages trust in legitimate software ecosystems. The discovery, triggered by a developer investigating unusual search results for their own application, reveals a coordinated infrastructure designed to mimic well-known tools while…
-
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra.According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote First…
-
Windows WalletService Flaw Lets Standard Users Gain SYSTEM Privileges
Microsoft Windows WalletService is affected by a local privilege escalation vulnerability tracked as CVE-2026-49176. This flaw could allow a standard authenticated user to obtain SYSTEM-level privileges. The vulnerability arises from WalletService’s handling of user-controlled file paths during initialization. An attacker can exploit this by redirecting the service to a maliciously crafted Extensible Storage Engine (ESE)…
-
Microsoft Introduces KMS Hardware-Secured for Windows Server Activation
Microsoft has introduced KMS Hardware-Secured, an upcoming enhancement to Windows Server activation that utilizes Trusted Platform Module (TPM)-based attestation to validate Key Management Service (KMS) hosts before they can activate Windows devices. Announced in a July 2022 Windows IT Pro Blog post, this initiative addresses risks related to spoofed, cloned, or otherwise untrusted KMS infrastructure.…
-
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno…

