Tag: windows
-
Windows LegacyHive zero-day flaw gets free, unofficial patches
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-free-unofficial-patches/
-
Windows 11 24H2 und 25H2 – Release Preview bringt Voice Isolation und neue Touchpad-Funktionen
Microsoft hat mit den Versionen 26100.8942 (24H2) und 26200.8942 (25H2) neue Release-Preview-Builds für Windows 11 veröffentlicht. First seen on computerbase.de Jump to article: www.computerbase.de/news/betriebssysteme/windows-11-24h2-und-25h2-release-preview-bringt-voice-isolation-und-neue-touchpad-funktionen.98476
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert CommandControl Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and to exfiltrate stolen data via a compromised Microsoft 365 mailbox. This technique enables malicious communications…
-
DocuSign Phishing Kit Delivers RMM Tools to Windows and macOS
BlueVoyant uncovered a DocuSign phishing campaign delivering legitimate RMM tools to Windows and macOS for persistence. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/docusign-phishing-kit-delivers-rmm-tools-to-windows-and-macos/
-
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV.What makes it more…
-
LG Monitors Spotted Installing Adware-Like App on Windows PCs
Connecting certain LG monitors prompts Windows Update to install an LG app without consent, while the software runs at startup and displays McAfee trial adverts. First seen on hackread.com Jump to article: hackread.com/lg-monitors-install-adware-app-windows-pcs/
-
Researchers Uncover HOLLOWGRAPH: Malware That Hides Inside Microsoft 365 Calendar Invites
A previously undocumented strain of Windows malware is using Microsoft 365 calendar invites as a covert communications channel, allowing attackers to issue commands and exfiltrate stolen files from victim networks while hiding in plain sight among ordinary enterprise traffic, according to new research from the threat intelligence firm Group-IB. The malware, dubbed HOLLOWGRAPH, was detailed…
-
Microsoft confirms Windows Server Update Services sync delays
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-working-to-fix-wsus-server-sync-delays-and-timeouts/
-
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-bug-causing-some-dell-pcs-to-shut-down/
-
Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier
Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier on August 15, 2026. This change was announced in the Microsoft 365 Message Center notification MC1426708 and leaves organizations with older Windows endpoints exposed to an increasingly unsupported file synchronization client,…
-
LG Monitors Silently Install McAfee Adware on Windows PCs With Full System Access
Concerns have arisen regarding LG monitors that reportedly trigger the silent installation of an LG companion application on Windows PCs. This installation is followed by promotional prompts for a McAfee security trial, raising issues related to device-software delivery mechanisms, user consent, and the permissions granted to automatically installed applications. Gamers Nexus, a YouTube hardware-testing outlet,…
-
Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues
Microsoft has released KB5121767, an out-of-band (OOB) cumulative update for Windows 11 versions 22H2 and 21H2. This update addresses a system performance issue related to the Intel Innovation Platform Framework (Intel IPF) drivers. The update was made available on July 18, 2023, specifically for devices affected by this issue, which arose after installing recent Windows…
-
The Windows 10 hangover is becoming a security problem
Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/windows-10-support-risks-report/
-
Windows 11: Microsoft veröffentlicht Notfallupdate gegen Abstürze
Zwei Windows-11-Updates von Juni und Juli konnten einige Dell-PCs übermäßig erhitzen, ausbremsen und abstürzen lassen. Dafür gibt es nun einen Fix. First seen on golem.de Jump to article: www.golem.de/news/windows-11-microsoft-veroeffentlicht-notfallupdate-gegen-abstuerze-2607-211045.html
-
GoldenEyeDog Threat Group Behind DigiCert Code-Signing Certificate Attack
GoldenEyeDog, a Chinese cybercrime group increasingly tracked as an advanced threat cluster, has been linked to a sophisticated intrusion into DigiCert that enabled the theft and abuse of legitimate code-signing certificates. The group has been active since at least 2015 and, since 2024, has consistently leveraged stolen or abused code-signing certificates to bypass Windows SmartScreen…
-
Windows 10 devices carry 3 times the risk of Windows 11, data shows
First seen on scworld.com Jump to article: www.scworld.com/brief/windows-10-devices-carry-three-times-the-risk-of-windows-11-data-shows
-
Microsoft pauses Windows 11 update for Dell PCs due to compatibility issues
First seen on scworld.com Jump to article: www.scworld.com/brief/microsoft-pauses-windows-11-update-for-dell-pcs-due-to-compatibility-issues
-
Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network
Researchers found China’s Daxin rootkit and a new Stupig backdoor on a Taiwan firm’s network, suggesting a stealthy intrusion dating back to 2013. Symantec’s Threat Hunter Team found Daxin running on a compromised host at a Taiwan-based subsidiary of a multinational high-tech manufacturer in 2026. Daxin is a Windows kernel-mode rootkit that Symantec first documented…
-
LegacyHive: Neuer WindowsDay hebelt selbst vollständig gepatchte Systeme aus
LegacyHive ist ein neuer Windows-Zero-Day, der selbst vollständig gepatchte Systeme betrifft. Microsoft untersucht die Schwachstelle. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/legacyhive-windows-zero-day-gepatchte-systeme-331579.html
-
Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges
Cloud Software Group has issued a High-severity security bulletin (CTX696734) disclosing two vulnerabilities in the Citrix Secure Access Client for Windows and the Citrix Endpoint Analysis Client for Windows. The more serious of the two, tracked as CVE-2026-53565, allows a standard, low-privileged user on a local system to escalate privileges and gain full SYSTEM access,…
-
Critical Zoom Flaw Could Let Attackers Take Over Windows Accounts
Zoom patched a critical Windows flaw that could enable remote account takeover, along with three high-severity privilege-escalation vulnerabilities. The post Critical Zoom Flaw Could Let Attackers Take Over Windows Accounts appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-zoom-windows-account-takeover-vulnerability/
-
“TTF Trap” Phishing Emails Use Fake Font Files to Deliver Windows Malware
An email that appears to contain a shipping document, payment request, or business proposal can infect a Windows… First seen on hackread.com Jump to article: hackread.com/ttf-trap-phishing-fake-font-files-windows-malware/
-
LegacyHive Windows Zero-Day Lets Attackers Hijack Administrator Registry Hives
A newly disclosed Windows local privilege-escalation vulnerability, dubbed LegacyHive, could allow a standard user to load and modify the per-user registry classes hive of an administrator account. The proof-of-concept (PoC), published by researcher NightmareEclipse under the MSNightmare/LegacyHive GitHub repository, abuses Windows’ User Profile Service to mount a target user’s UsrClass.dat hive into a registry location…
-
New Windows LegacyHive zero-day gives hackers admin privileges
A security researcher using the “Nightmare Eclipse” handle has released a Windows zero-day exploit dubbed LegacyHive that allows attackers to escalate privileges on up-to-date Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-windows-legacyhive-zero-day-exploit-grants-hackers-admin-access/
-
Windows Server 2022 reach end of mainstream support in 90 days
Microsoft announced that Windows Server 2022 will reach the mainstream end date in October 2026, but will switch to extended support and continue receiving security updates for five more years. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-server-2022-reach-end-of-mainstream-support-in-90-days/
-
Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available
The latest Notepad++ vulnerabilities addressed in version 8.9.7 include several high-impact security flaws that could expose Windows systems to arbitrary code execution, file overwrite attacks, memory corruption, and authentication bypass. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/notepad-vulnerabilities-v897/
-
Zoom Patches Critical Windows Flaw Enabling Account Takeover
Zoom has released security updates to fix CVE-2026-53412, a critical Improper Input Validation vulnerability affecting its Windows software, which could allow attackers to take over user accounts via network access. The flaw primarily impacts the Zoom Desktop Client and other Windows-based Zoom products, prompting the company to urge users to install the latest updates. First…
-
Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload
An active phishing campaign using a five-layer, fileless malware loader to evade Microsoft’s Antimalware Scan Interface (AMSI), static detection controls, and disk-based forensic analysis. The campaign delivers a Windows Script Host JScript payload inside a TAR archive disguised as a purchase order, ultimately loading a .NET assembly directly into memory. The activity was first observed…
-
Zoom Patches Critical Account Takeover Vulnerability for Windows
Zoom patched a critical Windows vulnerability that could enable unauthenticated account takeover. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/zoom-patches-critical-account-takeover-vulnerability-for-windows/

