Tag: windows
-
Microsoft’s Project Zenith puts large AI models directly on developer PCs
Microsoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/08/microsoft-project-zenith-windows-11-experience/
-
Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day
Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode…
-
Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day
Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode…
-
Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day
Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode…
-
Xopero erweitert <> und <> mit Image-basiertes Linux-Backup, FIPS-konforme Verschlüsselung und Active-Directory-Integration
Der Backup-Experte Xopero hat eine neue Version von <> und <> vorgestellt. Ab der Version 2.4.0 ermöglicht Xopero-ONE-vollständige, imagebasierte Backups von Linux-Systemen. Bei Windows-Umgebungen ist die Unterstützung der AES-Verschlüsselung gemäß den strengen US-FIPS-Standards das wichtigste neue Feature. Die Active-Directory-Integration via LDAP erleichtert nun die Aufgaben von Backup-Administratoren, unabhängig von den geschützten Workloads. Die Lösung […]…
-
BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations
A newly documented Windows attack pattern, dubbed Bring Your Own Trusted Caller (BYOTC), shows how attackers can bypass driver-level authorization controls without exploiting a traditional memory-corruption flaw. Instead of attacking a privileged kernel driver directly, an adversary compromises or abuses the legitimate user-mode application that the driver already trusts. The technique expands on the well-known…
-
Windows XP: Die wahre Geschichte hinter dem berühmtesten Gratis-Code der 2000er
Tags: windowsFirst seen on t3n.de Jump to article: t3n.de/news/fckgw-windows-xp-product-key-geschichte-microsoft-entwickler-1759839/
-
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself.One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.The company named the four programs ProManager, WinUpdate, SoftManager, and First seen on thehackernews.com…
-
Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe
Russian state-sponsored threat actor BlueDelta, also tracked as APT28, Fancy Bear, and Forest Blizzard, has deployed a lightweight Windows backdoor named HOOKEDGE in espionage operations targeting government, diplomatic, and defense-manufacturing organizations across Europe. The activity, documented by PolySwarm, targeted entities in Romania, Spain, and Turkey between late September 2025 and early April 2026. New variants…
-
Microsoft says some users can’t open the Teams desktop client
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-says-some-users-cant-open-the-teams-desktop-client/
-
„FCKGW”: Ex-Entwickler enthüllt die Wahrheit hinter dem berühmtesten Windows-Product-Key aller Zeiten
Tags: windowsFirst seen on t3n.de Jump to article: t3n.de/news/fckgw-entwickler-windows-xp-product-key-1759839/
-
„FCKGW”: Ex-Entwickler enthüllt die Wahrheit hinter dem berühmtesten Windows-Product-Key aller Zeiten
Tags: windowsFirst seen on t3n.de Jump to article: t3n.de/news/fckgw-entwickler-windows-xp-product-key-1759839/
-
„FCKGW”: Ex-Entwickler enthüllt die Wahrheit hinter dem berühmtesten Windows-Product-Key aller Zeiten
Tags: windowsFirst seen on t3n.de Jump to article: t3n.de/news/fckgw-entwickler-windows-xp-product-key-1759839/
-
„FCKGW”: Ex-Entwickler enthüllt die Wahrheit hinter dem berühmtesten Windows-Product-Key aller Zeiten
Tags: windowsFirst seen on t3n.de Jump to article: t3n.de/news/fckgw-entwickler-windows-xp-product-key-1759839/
-
„FCKGW”: Ex-Entwickler enthüllt die Wahrheit hinter dem berühmtesten Windows-Product-Key aller Zeiten
Tags: windowsFirst seen on t3n.de Jump to article: t3n.de/news/fckgw-entwickler-windows-xp-product-key-1759839/
-
Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
Tags: backdoor, control, cyber, data-breach, group, hacker, infrastructure, malware, ransomware, threat, tool, windowsThe financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its…
-
Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors
Tags: backdoor, control, cyber, data-breach, group, hacker, infrastructure, malware, ransomware, threat, tool, windowsThe financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its…
-
New CrowdStrike ‘FalconFlank’ zero-day grants SYSTEM privileges
An anonymous security researcher who uses the “Nightmare Eclipse” handle released a CrowdStrike Falcon zero-day exploit named “FalconFlank” that lets attackers escalate privileges on up-to-date Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
MECCHA CHAMELEON Flaw Lets Malicious Custom Maps Achieve Remote Code Execution
A recently patched vulnerability in MECCHA CHAMELEON allowed attacker-controlled Steam Workshop maps to write files to arbitrary locations on Windows systems, potentially resulting in remote code execution once the victim restarted their device. Security researchers at Aikido Security disclosed a delayed remote code execution (RCE) vulnerability affecting the online hide-and-seek game MECCHA CHAMELEON, which reportedly…
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Detecting livingthe-land binaries with Sysmon process events
Living-off-the-land binaries, often shortened to LOLBins, are legitimate Windows executables that attackers abuse to carry out malicious activity while blending in with normal administration. The binaries themselves are not the problem. The issue is that tools such as PowerShell, cmd.exe,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-living-off-the-land-binaries-with-sysmon-process-events/
-
Imaging und Klonen mit nativem ARM64-Support – Hasleo Backup Suite Free für Windows
First seen on security-insider.de Jump to article: www.security-insider.de/hasleo-backup-suite-free-fuer-windows-a-cf62f57f0130f32d5a797f348cdd2b80/
-
Microsoft gesteht Update-Panne: Windows-11-Update macht den Desktop schwarz
Auch Mauszeigereinstellungen werden durch das Update auf vielen Windows-11-Systemen zurückgesetzt. Microsoft arbeitet an Korrekturen. First seen on golem.de Jump to article: www.golem.de/news/microsoft-gesteht-windows-11-update-laesst-wallpaper-verschwinden-2609-212638.html

