Tag: windows
-
CrowdStrike Falcon Zero-Day Lets Attackers Escalate Privileges on Windows Systems
A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on Windows. CrowdStrike is actively investigating these claims and has advised customers to turn off the Microsoft Office File Suspicious Macro Removal policy while the assessment is ongoing. CrowdStrike Falcon Zero-Day The project was published on…
-
Microsoft gesteht: Windows-11-Update lässt Wallpaper verschwinden
Auch Mauszeigereinstellungen werden durch das Update auf vielen Windows-11-Systemen zurückgesetzt. Microsoft arbeitet an Korrekturen. First seen on golem.de Jump to article: www.golem.de/news/microsoft-gesteht-windows-11-update-laesst-wallpaper-verschwinden-2609-212638.html
-
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.”Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial First seen on thehackernews.com Jump to article:…
-
KB5120998 mouse reset bug affects only non-English PCs
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/
-
Microsoft says KB5120998 Windows update resets desktop settings
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-says-kb5120998-windows-update-resets-desktop-settings/
-
Rogue ScreenConnect Clients Spread Worm-Like Malware Across Connected Windows Systems
A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can automatically push a multi-stage VBScript malware chain to newly connected Windows endpoints. Once deployed, the clients repeatedly spawned wscript.exe to execute four scripts 1.vbs, 2.vbs, 3.vbs, and 4.vbs from ScreenConnect-related temporary locations. The behavior is…
-
Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted kernel-mode code and drivers can run on supported systems. Memory Integrity is a security feature built on Virtualization-based Security (VBS), a Windows…
-
Avast Antivirus Zero-Day PoC Lets Attackers Dump SAM Database and Gain SYSTEM Shell
A public proof-of-concept (PoC) repository has revealed a local privilege escalation zero-day vulnerability in GenDigital’s Avast Antivirus. This vulnerability allows an attacker to dump the Windows Security Account Manager (SAM) database and launch a shell running as NT AUTHORITY\SYSTEM. The researcher behind the repository, known as MSNightmare, claims that the issue affects fully patched installations…
-
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/
-
Windows memory integrity switches on automatically for eligible devices in October 2026
Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/03/windows-memory-integrity-update/
-
Claude AI Can Now Control macOS and Windows Computers to Click, Type and Open Apps
Anthropic has enhanced Claude’s desktop automation capabilities, enabling the AI assistant to operate directly on macOS and Windows computers through Claude Cowork and Claude Code. When this feature is enabled, Claude can navigate a visible screen, click controls, type text, launch applications, open files, and work within browser-based or local tools if no dedicated connector…
-
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.”The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft First seen on thehackernews.com Jump to article: thehackernews.com/2026/09/fake-software-installers-disable.html
-
Google Patches 26 Chrome Vulnerabilities, Including Critical WebGL and Shared Tab Groups Flaws
Google has released a new update for the Chrome Stable Channel on desktop platforms, addressing 26 security vulnerabilities. This includes two critical use-after-free flaws affecting WebGL and Shared Tab Groups. The update upgrades Chrome to version 152.0.7977.75 on Windows and macOS, while Linux users receive version 152.0.7977.76. Google stated that the update will be rolled…
-
Fake Microsoft Edge, Kaspersky and Razer Installers Used to Compromise Windows Systems
Tags: cyber, government, healthcare, infrastructure, kaspersky, malware, microsoft, software, technology, windowsAn active malware campaign that abuses counterfeit download pages for trusted software brands including Microsoft Edge, Kaspersky and Razer to compromise Windows devices. Victims span healthcare, manufacturing, gaming, technology, logistics, government and education, highlighting the broad appeal of software-download lures. Microsoft has not attributed the activity to a nation-state actor, but the campaign’s infrastructure, payload…
-
Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira
Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/sift-open-source-secret-scanning/
-
CrowdStrike Adds Platform to Secure AI Agents Running on Endpoints
CrowdStrike today at its Fal.Con 2026 conference launched the Falcon Guardian platform that leverages a sensor to provide a live inventory of every active and dormant artificial intelligence (AI) agent running on a Windows or macOS endpoint. At the same time, CrowdStrike is launching Falcon Complete for Guardian, a managed service based on Guardian that..…
-
Mirage Kitten Hackers Use Fake Coding Challenges to Deploy NodeRabbit and PollCat RATs
Iran-linked threat actor Mirage Kitten is targeting software developers with fake recruitment assessments that hide two newly identified cross-platform remote access trojans: NodeRabbit and PollCat. The campaign uses recruiter impersonation on LinkedIn and other job-search platforms, weaponized Node.js projects, and cloud-hosted ZIP archives to gain covert access to developer endpoints across Windows, Linux, and macOS.…
-
Fake Claude Opus 5 app delivers malware and wipes its own tracks
A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/revstealer-malware-claude-opus-5-github/
-
AI-Enhanced BraZetsu Malware Powers Underground Market Selling Access to Corporate Networks
BraZetsu, a Python-based Windows malware framework allegedly operated by the Brazilian threat actor Exilware to identify, profile, and monetize compromised corporate systems. Rather than behaving like a conventional infostealer, BraZetsu appears designed to support an Initial Access Broker operation, converting infected endpoints into cataloged access offerings for an underground marketplace. The framework is reportedly the…
-
SLEEPWALKER Malware Uses Raw Packets, DNS and VMware VMCI for Covert Communications
A newly analyzed Windows backdoor named SLEEPWALKER uses a passive command-and-control model designed to evade conventional beaconing-based detections. Raw-packet activation, DNS-based tasking support, VMware VMCI communications, named-pipe capabilities, and in-memory payload execution. No threat actor, victim, delivery chain, or live campaign has yet been attributed to the malware. SLEEPWALKER is an unsigned 64-bit Windows DLL…
-
Fake Claude Opus 5 App Deploys RevStealer to Steal Passwords, Crypto Wallets and Sessions
Threat actors are exploiting demand for generative AI tools to distribute RevStealer, a Windows-focused information stealer hidden inside a trojanized Electron application that impersonates a free desktop version of Anthropic’s Claude Opus 5. Instead a stealthy credential theft tool engineered to evade sandboxes, endpoint monitoring, and post-infection investigation. The primary lure, branded “Claude Opus 5…
-
Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/
-
HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This vulnerability allows a local user to control a privileged component. The code was published by a GitHub user named MSNightmare and is being presented as a zero-day vulnerability. However, the vendor has not confirmed it.…
-
Microsoft says Windows 11 KB5120998 update resets mouse settings
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-says-windows-11-kb5120998-update-resets-mouse-settings/
-
Microsoft Defender Bug Triggers False “Antivirus Turned Off” Alerts on Windows
Microsoft has confirmed an issue with Microsoft Defender Antivirus that generates false notifications on Windows systems, claiming >>Microsoft Defender Antivirus is turned off,<< even though the protection is still operational. These alerts may appear after installing the latest Defender updates, potentially causing unnecessary concern for administrators who observe that Defender settings are healthy and security…
-
New Gryxa Toolkit Uses AI-Built Persistence to Fight Back Against Security Teams
A financially motivated threat actor using a new Windows toolkit named Gryxa that combines remote monitoring and management abuse, AI-assisted development, browser credential theft, and aggressive persistence designed to survive incomplete remediation. The toolkit’s most unusual feature is its ability to collect evidence of how defenders removed its visible access and send that information back…
-
Virenschutz angeblich aus: Microsoft Defender spielt falsche Warnmeldung aus
Einige Windows-Nutzer erhalten seit Wochen Warnmeldungen vom Microsoft Defender, dass der Virenschutz inaktiv sei. Das ist jedoch ein Anzeigefehler. First seen on golem.de Jump to article: www.golem.de/news/virenschutz-angeblich-aus-microsoft-defender-spielt-falsche-warnmeldung-aus-2608-212431.html
-
TerminalFix Uses Fake CAPTCHA, DLL Sideloading and Steganography to Breach Networks
A sophisticated ClickFix variant dubbed TerminalFix that uses fake Cloudflare CAPTCHA prompts to trick users into executing attacker-controlled PowerShell commands. Rather than delivering a conventional infostealer, the campaign builds persistent access and deploys a reverse-tunnel implant capable of turning an infected Windows endpoint into a proxy for reaching internal network resources The intrusion begins on…
-
Windows XP gratis: Wie ein einziger geleakter Firmenschlüssel Microsofts Schutz aushebelte
First seen on t3n.de Jump to article: t3n.de/news/windows-xp-key-kein-hack-1759839/
-
Windows XP gratis: Wie ein einziger geleakter Firmenschlüssel Microsofts Schutz aushebelte
First seen on t3n.de Jump to article: t3n.de/news/windows-xp-key-kein-hack-1759839/

