Tag: windows
-
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems.The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South…
-
BambooToken malware controls Windows and Linux systems via MQTT
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/
-
One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-day against NGOs starting September 1, 2026, Volexity’s new report lays out the whole chain in detail. On September 1, Volexity detected a spear-phishing campaign by UTA0560 targeting several…
-
Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz
Attackers compromised the verified official HBO Max Reddit account, u/hbomax, and used its trusted advertising status to launch a ClickFix campaign targeting macOS and Windows … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/hbo-max-reddit-account-clickfix-infostealer-malware/
-
Mehrere Bugs beseitigt: Microsoft verteilt Notfallupdates für Windows
Die neuen Windows-Updates beheben mehrere seit dem September-Patchday bestehende Bugs. Zudem adressiert Microsoft eine vergessene Schwachstelle. First seen on golem.de Jump to article: www.golem.de/news/mehrere-bugs-beseitigt-microsoft-verteilt-notfallupdates-fuer-windows-2609-213014.html
-
Mehrere Bugs beseitigt: Microsoft verteilt Notfallupdates für Windows
Die neuen Windows-Updates beheben mehrere seit dem September-Patchday bestehende Bugs. Zudem adressiert Microsoft eine vergessene Schwachstelle. First seen on golem.de Jump to article: www.golem.de/news/mehrere-bugs-beseitigt-microsoft-verteilt-notfallupdates-fuer-windows-2609-213014.html
-
Product showcase: mSecure makes one vault do more than remember passwords
mSecure is a password manager and data vault for storing credentials and other sensitive information. It is available for iOS, Android, macOS, and Windows, with data … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/product-showcase-msecure-password-manager/
-
Product showcase: mSecure makes one vault do more than remember passwords
mSecure is a password manager and data vault for storing credentials and other sensitive information. It is available for iOS, Android, macOS, and Windows, with data … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/15/product-showcase-msecure-password-manager/
-
Hackers Turn Windows Shadow Copies Into a Tool for Credential Theft and Ransomware
Threat actors are increasingly weaponizing Microsoft’s Volume Shadow Copy Service (VSS) for two distinct objectives: removing recovery options before ransomware deployment and extracting credential material from protected Windows files. The shift means VSS telemetry should no longer be treated as a simple backup or disk-maintenance event, but as behavior requiring process, identity, and endpoint context.…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.”The First seen…
-
Mehrere Bugs beseitigt: Microsoft verteilt Notfallupdates für Windows
Die neuen Windows-Updates beheben mehrere seit dem September-Patchday bestehende Bugs. Zudem adressiert Microsoft eine vergessene Schwachstelle. First seen on golem.de Jump to article: www.golem.de/news/mehrere-bugs-beseitigt-microsoft-verteilt-notfallupdates-fuer-windows-2609-213014.html
-
Microsoft releases emergency Windows updates to fix RDS failures
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month’s security updates, along with Hyper-V and USB audio problems on some Windows versions. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-windows-updates-to-fix-rds-failures/
-
ClickFix attacks are tricking Mac and Windows users into hacking themselves
If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising “ClickFix” security threat. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/14/clickfix-attacks-are-tricking-mac-and-windows-users-into-hacking-themselves/
-
Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max’s official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/
-
Microsoft’s Patching
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record: Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/microsofts-patching/
-
RDP, Sound und mehr: Windows-Updates bereiten Nutzern allerhand Probleme
Laut Microsoft lösen die neuen Windows-Updates Probleme mit Linux-VMs, USB-Audio und RDP-Verbindungen aus. Doch da scheint noch mehr kaputt zu sein. First seen on golem.de Jump to article: www.golem.de/news/rdp-sound-und-mehr-windows-updates-bereiten-nutzern-allerhand-probleme-2609-212982.html
-
September updates cause RDS failures on Windows Server
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-cause-rds-failures-on-windows-server/
-
September updates break audio on some Windows PCs
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-break-audio-on-some-windows-pcs/
-
China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-51990, the vulnerability chains an insecure custom protocol handler, unrestricted embedded-browser navigation, and an obsolete Chromium build running without sandbox protections. Tencent addressed…
-
AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process
A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NET remote-access trojan inside Microsoft’s legitimate charmap.exe process. The infection begins with a lure named “Right-click to open Invoice Details.bat”, which relies on user interaction to trigger execution. While the precise delivery method…
-
Why isn’t my process terminating on Windows on ARM?
Tags: windowsA hung process, a live kernel dump and a Windows on ARM emulation bug that only some of our binaries seem to hit.This is the first post in a series from MIND’s R&D team in Tel Aviv, where we write… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/why-isnt-my-process-terminating-on-windows-on-arm/
-
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/
-
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on September 1, 2026, as using identical browser-to-kernel exploit components but ultimately installing separate espionage payloads: the GRIMWEDGE JScript backdoor and the LONGTALE credential-stealing Chrome…
-
New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system reconnaissance, and potentially deploy payloads designed to steal credentials and local secrets. Fortra’s Intelligence and Research Experts (FIRE) said the activity began in June and remains active, with operators regularly recompiling malware samples to…
-
Exploit-Kit Bluemoon: Chinesische Hacker attackieren Windows-Nutzer
Ein neues Exploit-Kit nutzt gefährliche Sicherheitslücken in Windows und Google Chrome aus. Mehrere Cybergruppierungen machen davon Gebrauch. First seen on golem.de Jump to article: www.golem.de/news/exploit-kit-bluemoon-chinesische-hacker-bei-angriffen-auf-windows-nutzer-erwischt-2609-212919.html
-
Exploit-Kit Bluemoon: Chinesische Hacker bei Angriffen auf Windows-Nutzer erwischt
Ein neues Exploit-Kit nutzt gefährliche Sicherheitslücken in Windows und Google Chrome aus. Mehrere Cybergruppierungen machen davon Gebrauch. First seen on golem.de Jump to article: www.golem.de/news/exploit-kit-bluemoon-chinesische-hacker-bei-angriffen-auf-windows-nutzer-erwischt-2609-212919.html
-
Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-teams-outlook-launch-failures-on-arm-windows-pcs/
-
11 Best Device Control USB Security Tools Compared (2026): Features Pricing
Quick Answer: CoSoSys Endpoint Protector leads cross-platform (Windows/macOS/Linux) device control; Safetica and ManageEngine win mid-market value; Symantec (Broadcom), Forcepoint, and Digital Guardian (Fortra) anchor enterprise content-aware DLP; Ivanti DeviceLock offers the deepest Windows peripheral granularity. Pricing is almost always per endpoint. One rogue USB stick can import ransomware or export your customer database which is…

