Tag: windows
-
Chosen Brick, Iran’s Surveillance Malware
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the…
-
BambooToken: The Malware That Speaks MQTT to Stay Under the Radar
Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control…
-
Windows 11 KB5124008 update breaks domain trust for some users
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-kb5124008-update-breaks-domain-trust-for-some-users/
-
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
-
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
-
Microsoft Issues OutBand Windows Update After September Patch Breaks Remote Desktop, Hyper-V
Microsoft released an out-of-band Windows update to fix Remote Desktop, Hyper-V Linux sharing, and USB audio issues caused by its September patch. The post Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-windows-update-remote-desktop-hyper-v-fix/
-
Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems
Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to compromised Windows workstations and Linux servers. Also tracked as ANGRYREBEL and Nood RAT, the malware has been active since at least mid-2016 but was long mistaken for variants of Gh0st RAT, Rekoobe, and other…
-
HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware
Attackers reportedly hijacked HBO Max’s verified Reddit account to run 108 malicious ads delivering ClickFix malware to Windows and Mac users. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-hbo-max-reddit-clickfix-malware-ads/
-
Microsoft Issues OutBand Windows Update After September Patch Breaks Remote Desktop, Hyper-V
Microsoft released an out-of-band Windows update to fix Remote Desktop, Hyper-V Linux sharing, and USB audio issues caused by its September patch. The post Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-windows-update-remote-desktop-hyper-v-fix/
-
Microsoft Issues OutBand Windows Update After September Patch Breaks Remote Desktop, Hyper-V
Microsoft released an out-of-band Windows update to fix Remote Desktop, Hyper-V Linux sharing, and USB audio issues caused by its September patch. The post Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-windows-update-remote-desktop-hyper-v-fix/
-
Microsoft Issues OutBand Windows Update After September Patch Breaks Remote Desktop, Hyper-V
Microsoft released an out-of-band Windows update to fix Remote Desktop, Hyper-V Linux sharing, and USB audio issues caused by its September patch. The post Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-windows-update-remote-desktop-hyper-v-fix/
-
Microsoft Issues OutBand Windows Update After September Patch Breaks Remote Desktop, Hyper-V
Microsoft released an out-of-band Windows update to fix Remote Desktop, Hyper-V Linux sharing, and USB audio issues caused by its September patch. The post Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-windows-update-remote-desktop-hyper-v-fix/
-
Microsoft says Copilot buttons still missing in classic Outlook
Microsoft says it’s still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-shares-workaround-for-missing-outlook-copilot-buttons/
-
PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the available evidence does not support definitive attribution…
-
PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the available evidence does not support definitive attribution…
-
PAPERMILL Malware Campaign Abuses Signed Notepad++ to Deliver VenomRAT to Windows Users
A newly identified phishing operation tracked as PAPERMILL is abusing a legitimately signed Notepad++ executable, DLL sideloading, and layered in-memory loaders to install VenomRAT on Windows systems. The campaign uses tax-audit lures aimed at Indian recipients and reflects a broader China-nexus pattern of tax-themed malware activity, although the available evidence does not support definitive attribution…
-
UK, US and Netherlands warn of Iranian state spyware campaign
Cyber attackers linked to Iran’s Ministry of Intelligence and Security are targeting opponents and opposition groups with Windows spyware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650300/UK-US-and-Netherlands-warn-over-Iranian-state-spyware-campaign
-
Windows Server 2022 reaches end of mainstream support next month
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-next-month/
-
Hackers Disguise CHOSEN BRICK Malware as AI Apps, Antivirus Software and MRI Results
Iranian state-linked cyber actors are using fake AI applications, antivirus tools and even fabricated MRI scan results to deliver CHOSEN BRICK, a Windows-focused spyware family designed to surveil dissidents, activists and journalists. A joint advisory from the UK National Cyber Security Centre (NCSC), the FBI and the Netherlands’ AIVD warns that the campaign has targeted…
-
DeepZero: Open-source hunting for vulnerable Windows drivers
DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/
-
Google Chrome 153 Released With Fixes for 42 Security Vulnerabilities
Google has released Chrome version 153 to the Stable channel for desktop, addressing 42 security vulnerabilities, including three critical-severity flaws affecting WebGL, Chrome internals, and Workers. This update is being rolled out as version 153.0.8010.47/48 for Windows and macOS, and as version 153.0.8010.47 for Linux. The release includes a wide range of memory-safety, authorization, race-condition,…
-
UK, US and Netherlands warn over Iranian state spyware campaign
Cyber attackers linked to Iran’s Ministry of Intelligence and Security are targeting opponents and opposition groups with Windows spyware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650300/UK-US-and-Netherlands-warn-over-Iranian-state-spyware-campaign
-
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and activists around the world.The malware is controlled via the Telegram messaging app and can copy a target’s emails and chat messages, take screenshots, and activate…
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
VectraRAT Can Hack Windows Enterprises for $250 per Month
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. First seen on darkreading.com Jump to article: www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises
-
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems.The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South…
-
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/
-
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several…

