Tag: windows
-
Certighost: PoC-Exploit ermöglicht Übernahme von Windows-Domänen
Ein PoC-Exploit für die Lücke Certighost in Windows AD CS zeigt, wie Angreifer Domänencontroller kapern und Krbtgt-Hashes auslesen können. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/windows-domaenen-poc
-
Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay
Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding environments. The post Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-cursor-git-code-execution-vulnerability-cve-2026-63093/
-
Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia.The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,…
-
LegacyHive Exploit Abuses Windows Profile Loading to Hijack User Registry Hives
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing access to resources associated with another account. This technique was published by the Nightmare-Eclipse disclosure actor shortly after Microsoft’s July 2026 Patch Tuesday. Unlike traditional software vulnerabilities, LegacyHive chains legitimate…
-
New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for “Certighost,” a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/
-
MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data
MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user never touches. It’s a niche capability most people never think about, buried deep in how the…
-
Over 70 Fake Windows App Sites Could Turn Trusted Downloads Into Malware
A newly uncovered cluster of more than 70 impersonation domains targeting popular Windows applications is raising fresh concerns about a scalable malware distribution campaign that leverages trust in legitimate software ecosystems. The discovery, triggered by a developer investigating unusual search results for their own application, reveals a coordinated infrastructure designed to mimic well-known tools while…
-
Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware
The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra.According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote First…
-
Windows WalletService Flaw Lets Standard Users Gain SYSTEM Privileges
Microsoft Windows WalletService is affected by a local privilege escalation vulnerability tracked as CVE-2026-49176. This flaw could allow a standard authenticated user to obtain SYSTEM-level privileges. The vulnerability arises from WalletService’s handling of user-controlled file paths during initialization. An attacker can exploit this by redirecting the service to a maliciously crafted Extensible Storage Engine (ESE)…
-
Microsoft Introduces KMS Hardware-Secured for Windows Server Activation
Microsoft has introduced KMS Hardware-Secured, an upcoming enhancement to Windows Server activation that utilizes Trusted Platform Module (TPM)-based attestation to validate Key Management Service (KMS) hosts before they can activate Windows devices. Announced in a July 2022 Windows IT Pro Blog post, this initiative addresses risks related to spoofed, cloned, or otherwise untrusted KMS infrastructure.…
-
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno…
-
New Dolphin X Malware Uses AI Profiler to Rank High-Value Victims
Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly. First seen on hackread.com Jump to article: hackread.com/dolphin-x-malware-ai-profiler-rank-victims/
-
Microsoft tightens Windows enterprise activation security
Microsoft is making Trusted Platform Module (TPM)-backed attestation a requirement for Windows Key Management Service (KMS), the on-premises service used for Windows volume … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/24/microsoft-kms-tpm-security-update/
-
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that’s dressed up as a Notepad++ plugin to compromise Windows systems.The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed…
-
Hackers Weaponize Notepad++ Plugins to Silently Infect Windows Systems
CERT-UA has issued a warning regarding the UAC-0099 threat cluster, which has revised its malware delivery method by exploiting the legitimate Notepad++ application to load a malicious DLL disguised as a plugin. This campaign, observed since mid-summer 2026, introduces two newly identified tools, LUNCHPOKE and BURNYBEAR, along with an updated MATCHBOIL.V2 loader. This activity highlights…
-
Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained
Learn how BitLocker, passkeys, Microsoft Defender, and other Windows 11 security features protect your data, accounts, apps, and devices. The post Windows 11 Security Cheat Sheet: BitLocker, Passkeys, and Defender Explained appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-windows-11-security-cheat-sheet/
-
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
The Chaos ransomware group ran its command-and-control through the victim’s own browser. Cisco Talos on Thursday detailed msaRAT, the Rust implant behind it, found on a compromised Windows machine ahead of the encryptor.The implant never opens an outbound connection of its own. Its process talks to 127.0.0.1 and nothing else. It starts Chrome or Edge…
-
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it was offline by the time…
-
Critical FreeRDP Clipboard Flaw Could Let Malicious RDP Servers Execute Code
A critical heap buffer overflow vulnerability in FreeRDP’s Windows client could allow a malicious Remote Desktop Protocol (RDP) server to corrupt memory and potentially execute arbitrary code on a connecting client. This flaw specifically affects the Clipboard Redirection (CLIPRDR) virtual channel in wfreerdp, where an attacker-controlled response can exceed the size that the client originally…
-
New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs
Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs. First seen on hackread.com Jump to article: hackread.com/new-trickbot-variant-dns-control-infected-windows-pcs/
-
New Windows Stealer Uses AI Profiling to Identify High-Value Corporate Victims
A new Windows-focused infostealer and remote access trojan (RAT) dubbed Dolphin X is being advertised on cybercrime forums with a clear pitch: automate the theft and triage of high-value corporate targets. Unlike commodity stealers that focus mainly on browser passwords, Dolphin X is positioned as an enterprise-adjacent data vacuum with a built-in AI-powered victim scoring…
-
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs
North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview. The operation targets cryptocurrency and Web3 professionals, tricking candidates into executing terminal commands that infect their devices with platform-specific Remote Access Trojans (RATs): PylangGhost on Windows and GolangGhost on macOS. Detailed analysis by the SOCRadar…
-
SolarWinds Serv-U Update Fixes 15 Critical Vulnerabilities Enabling Remote Code Execution as Root
SolarWinds has released Serv-U 2026.3, which includes fixes for a cluster of 9.1 CVSS critical vulnerabilities that allow remote code execution (RCE) and privilege escalation up to root on Unix-like systems. This update significantly strengthens the managed file transfer (MFT) and FTP server platform against potential takeovers. While Windows instances are rated as having a…
-
Mozilla Firefox 153 – Update bringt QR-Code-Sharing und HDR-Videos für Windows
Die aktuelle Firefox-Version erweitert den Browser um zahlreiche neue Funktionen wie das Teilen von Websites per QR-Code. First seen on computerbase.de Jump to article: www.computerbase.de/news/apps/mozilla-firefox-153-update-bringt-qr-code-sharing-und-hdr-videos-fuer-windows.98495
-
Projekt ‘Windows seziert” – BSI nimmt Windows auseinander
First seen on security-insider.de Jump to article: www.security-insider.de/bsi-windows-hello-for-business-absichern-a-21ecfdf91d777cb58c0d89263b1d8a5b/
-
LG monitors criticized for silently installing McAfee ads via Windows Update
First seen on scworld.com Jump to article: www.scworld.com/brief/lg-monitors-criticized-for-silently-installing-mcafee-ads-via-windows-update
-
Windows Privilege Escalation: SeRestorePrivilege
Overview SeRestorePrivilege is a Windows special privilege that allows its holder to restore files and directories, effectively bypassing discretionary access controls on the file system. First seen on hackingarticles.in Jump to article: www.hackingarticles.in/windows-privilege-escalation-serestoreprivilege/
-
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.Researchers demonstrated that chain, plus six other attacks,…
-
Researchers Uncover North Korean ‘ClickFake’ Campaign Targeting Web3 Pros
In a new campaign, North Korean hacking group Famous Chollima targeted crypto professionals through ClickFix lures to deliver Windows and macOS trojans First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-clickfake-campaign/
-
Microsoft shares manual fix for WSUS sync delays and timeouts
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-shares-manual-fix-for-wsus-sync-delays-and-timeouts/

