Tag: windows
-
Researchers Found a Windows RAT That Turns Victims’ Screens Into Live Streams
A previously undocumented Windows remote access trojan capable of turning an infected victim’s display into a live stream for its operators. Dubbed BotHelper RAT after the Bot.Helper namespace found in its .NET assembly, the malware uses encrypted delivery, process masquerading, AMSI tampering and scheduled-task persistence to remain operational while giving attackers continuous visual access to…
-
Other users can watch your browsing and time your keystrokes through OS file notifications
Researchers at Graz University of Technology have used the file-notification systems in Windows, Linux, and macOS to spy on activity in other accounts. On Windows, a standard … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/cve-2025-68788-file-notification-attacks/
-
New Python Infostealer Targets 17 Browsers to Steal Passwords, Cards and Session Cookies
A Python-based information stealer that targets data from 17 Chromium-based browsers, alongside Firefox, to harvest saved credentials, payment-card details, browsing history and active session cookies. The malware is delivered through a builder framework that enables operators to generate customized Windows payloads and configure their own data-exfiltration webhook. The archive included a “TokenGrabber Builder” folder containing…
-
New Windows Process Injection Technique Bypasses EDR Monitoring Without WriteProcessMemory
A newly disclosed method for Windows process injection utilizes redirected console input and named pipes to transfer payload data into a child process without invoking the heavily monitored APIs VirtualAllocEx and WriteProcessMemory. This technique, called console named-pipe injection, highlights the need for endpoint defenses to correlate events across processes, memory protection, thread context, and interprocess…
-
Windows 11 Update Causes Black Screen and Desktop Loading Issues After Sign-In
Microsoft has confirmed a Windows 11 issue that can leave users with a black screen after sign-in or prevent the desktop from loading automatically. The problem affects devices that installed the August 2026 non-security preview updates and potentially later cumulative updates, with Azure Virtual Desktop environments using FSLogix profile containers most frequently affected. The issue…
-
Uncensored Local AI Model Bypasses EDR to Dump Windows LSASS Credentials
A new demonstration shows how a locally hosted, uncensored AI model can help generate a Windows LSASS credential-dumping utility that reportedly evaded endpoint detection and response products during laboratory testing. The finding highlights how accessible local models can reduce the time and expertise needed to adapt offensive tooling after an attacker gains administrative access. Eddie…
-
Windows Privilege Escalation: SeManageVolumePrivilege
Tags: windowsOverview This article demonstrates how attackers abuse the SeManageVolumePrivilege Windows token right to escalate from a standard user to SYSTEM on a Windows 10 target. First seen on hackingarticles.in Jump to article: www.hackingarticles.in/windows-privilege-escalation-semanagevolumeprivilege/
-
Microsoft plans to deprecate Windows Deployment Services
Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-to-deprecate-windows-deployment-services-after-windows-server-2025/
-
SectopRAT Abuses Legitimate Audio Software Files to Steal PC Data
FortiGuard found SectopRAT hidden in modified audio software files, using staged loading to steal browser data and remotely control infected Windows PCs. First seen on hackread.com Jump to article: hackread.com/sectoprat-abuses-audio-software-steal-pc-data/
-
Recent Windows updates cause desktop loading issues
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/
-
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The “third-party[.]com” domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.”third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,” Manifold Security’s Head of Research, Ax Sharma, said. “Unlike ‘example[.]com,’ third-party[.]com First seen on thehackernews.com…
-
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic.”When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the…
-
Windows 11 KB5124010 update released with 46 changes and fixes
Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-kb5124010-update-released-with-46-changes-and-fixes/
-
Operation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK Files
Tags: cyber, cyberespionage, intelligence, korea, malicious, malware, north-korea, powershell, russia, threat, ukraine, windowsNorth Korea-linked threat actor Konni has launched a targeted cyberespionage operation against Ukraine-focused entities using malicious Windows shortcut files disguised as PDF documents. The campaign, tracked by SOCRadar Threat Research Unit as Operation Conflict Compass, deploys a modular PowerShell malware family dubbed VelvetCake to collect intelligence on the Russia-Ukraine war. The activity appears designed to…
-
New AvisLoader Windows Malware Uses ClickFix Lure and Tox P2P for C2
Varonis Threat Labs discovered AvisLoader, a Windows malware loader that uses the Tox peer-to-peer network for C2 and arrives through a malicious ClickFix lure. First seen on hackread.com Jump to article: hackread.com/avisloader-windows-malware-clickfix-tox-p2p-c2/
-
New Windows Malware Built to Survive Takedowns With a Hidden P2P Command Network
AvisLoader, a newly observed Windows malware loader designed to maintain operator access even when conventional command-and-control infrastructure is disrupted. Instead of relying on a fixed domain, IP address, or centralized server, the malware uses the encrypted Tox peer-to-peer messaging network to receive commands and deliver follow-on payloads. The discovery highlights a growing challenge for defenders:…
-
Microsoft fixes bug that broke Windows File History backup feature
Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-backup-feature-broken-by-september-updates/
-
CLOSEDQUORUM, the malware that asks four AI models what to do next
Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware, dubbed CLOSEDQUORUM, that holds a vote before deciding what to steal from you. Four AI models vote on its next move, without any human interaction. CLOSEDQUORUM is the first Windows…
-
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/
-
Impacket for Pentester: tstool
Overview Terminal Services, better known today as Remote Desktop Services, governs every interactive and remote session on a Windows host. impacket-tstool lets an operator query First seen on hackingarticles.in Jump to article: www.hackingarticles.in/impacket-for-pentester-tstool/
-
Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day
The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender UpdateDoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update. The security researcher…
-
TASK#STOMP PowerShell Backdoor Steals Business Documents and Executes Remote Commands
A Windows-focused backdoor dubbed TASK#STOMP that uses VBScript, PowerShell, Scheduled Tasks, and runtime C# compilation to establish resilient persistence and continuously steal business documents. The implant also captures screenshots, extracts saved Wi-Fi passwords, harvests clipboard data, and executes arbitrary commands received from its operators. While the original delivery method is unconfirmed, the location is consistent…
-
New TASK#STOMP Windows Backdoor Enables Continuous Document Theft
TASK#STOMP Windows backdoor uses PowerShell, scheduled tasks and runtime C# compilation to steal business documents and maintain remote access. First seen on hackread.com Jump to article: hackread.com/taskstomp-windows-backdoor-document-theft/
-
Public PoC Exposes Critical Veeam Agent Privilege Escalation
A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, not tomorrow. On September 14, 2026, public technical details…
-
Hackers Exploit Veeam Agent Vulnerability to Gain SYSTEM-Level Access on Windows
A newly discovered privilege escalation flaw in Veeam Agent for Microsoft Windows could allow attackers with local access to compromised endpoints to execute commands as NT AUTHORITY\SYSTEM. Public proof-of-concept (PoC) code for CVE-2026-32996 was released on September 14, increasing the urgency for organizations to patch affected Veeam deployments. CVE-2026-32996 impacts Veeam Agent for Microsoft Windows…
-
New Windows Defender zero-day blocks Microsoft antivirus updates
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/
-
Umstellung auf Linux: Staatskanzlei Kiel fast vollständig weg von Windows
Die Umstellung auf Linux ist nur eine von vielen Maßnahmen Schleswig-Holsteins, um sich von proprietärer Software zu lösen. First seen on golem.de Jump to article: www.golem.de/news/umstellung-auf-linux-staatskanzlei-kiel-fast-vollstaendig-weg-von-windows-2609-213307.html
-
Forscher eskaliert weiter: Zero-Day-Exploit trickst den Windows Defender aus
Ein neuer Exploit von Nightmare Eclipse hindert den Windows Defender daran, sich zu aktualisieren. Das ermöglicht weiterführende Angriffe. First seen on golem.de Jump to article: www.golem.de/news/forscher-eskaliert-weiter-zero-day-exploit-trickst-den-windows-defender-aus-2609-213306.html
-
Chinese APT Clones Legitimate Websites to Deliver Chrome and Windows Zero-Day Exploits
A third Chinese threat actor has been linked to phishing campaigns that cloned trusted websites and chained Chrome and Windows zero-day exploits to deploy a previously undocumented backdoor. The activity occurred on September 3 and 4, 2026, while the targeted vulnerabilities remained unpatched in Google Chrome. It followed Volexity’s September 9 disclosure that UTA0560 and…
-
Microsoft gesteht: Update-Panne macht Dateiversionsverlauf von Windows kaputt
Die Windows-Updates von September ziehen allerhand Probleme nach sich. Auch der Dateiversionsverlauf funktioniert nicht mehr richtig. First seen on golem.de Jump to article: www.golem.de/news/microsoft-gesteht-update-panne-macht-dateiversionsverlauf-von-windows-kaputt-2609-213294.html

