Tag: windows
-
Prometei Botnet Targets Linux Servers for Cryptocurrency Mining Operations
Unit 42 researchers from Palo Alto Networks have identified a renewed wave of attacks by the Prometei botnet, specifically targeting Linux servers, as of March 2025. Initially discovered in July 2020 with a focus on Windows systems, Prometei has since evolved, with its Linux variant gaining prominence since December 2020. Resurgence of a Persistent Threat…
-
Microsoft to remove legacy drivers from Windows Update for security boost
Microsoft has announced plans to periodically remove legacy drivers from the Windows Update catalog to mitigate security and compatibility risks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-to-remove-legacy-drivers-from-windows-update-for-security-boost/
-
Microsoft boosts default security of Windows 365 Cloud PCs
Windows 365 Cloud PCs now come with new default settings aimed at preventing / minimizing data exfiltration and malicious exploits, Microsoft has announced. Windows 365 Cloud … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/06/20/microsoft-boosts-default-security-of-windows-365-cloud-pcs/
-
Microsoft Introduces Enhanced Security Defaults for Windows 365 Cloud PCs
Microsoft has announced a significant update to the security posture of its Windows 365 Cloud PCs, introducing new secure-by-default capabilities designed to fortify virtual desktop environments against modern cyber threats. These changes, set to roll out in the second half of 2025, reflect Microsoft’s ongoing commitment to its Secure Future Initiative (SFI) and the evolving…
-
Refurbished Panasonic Toughpads FZ-G1(F) auf eBay/Priceholes mit Synaptics.Exe Wurm infiziert
Tags: windowsWarnung an IT-Dienstleister und Blog-Leser, die sich schon mal auf eBay einen gebrauchten Windows-Notebook, oder ein Tablet oder in Desktop-PC-System kaufen. Ein Leser wies mich die Woche darauf hin, dass er vom Anbieter Priceholes-com über eBay refurbished Panasonic Toughpads FZ-G1(F) … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/20/refurbished-panasonic-toughpads-fz-g1f-auf-ebay-priceholes-mit-synaptics-exe-wurm-infiziert/
-
Phishing campaign abuses Cloudflare Tunnels to sneak malware past firewalls
Why is Cloudflare Tunnel being abused?: The appeal of hosting attack infrastructure on Cloudflare Tunnel is that it is incredibly hard to detect or defend against.First, the tunnel is encrypted using HTTPS which means the only way to see what’s inside it is by using some form of TLS inspection. However, this would need to…
-
Microsoft unveils new security defaults for Windows 365 Cloud PCs
Microsoft has announced new Windows 365 security defaults starting in the second half of 2025 and affecting newly provisioned and reprovisioned Cloud PCs. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-unveils-new-security-defaults-for-windows-365-cloud-pcs/
-
Hackers Use VBScript Files to Deploy Masslogger Credential Stealer Malware
Seqrite Labs has uncovered a sophisticated variant of the Masslogger credential stealer malware being distributed through VBScript Encoded (.VBE) files. This advanced threat, which likely spreads via spam emails or drive-by downloads, operates as a multi-stage fileless malware, heavily exploiting the Windows Registry to store and execute its malicious payload without writing files to disk.…
-
Hackers Exploit Cloudflare Tunnels to Infect Windows Systems With Python Malware
A sophisticated malware campaign dubbed SERPENTINE#CLOUD has emerged, leveraging Cloudflare Tunnel infrastructure to deliver Python-based malware to Windows systems across Western nations, including the United States, United Kingdom, and Germany. This ongoing operation, characterized by its use of obfuscated scripts and memory-injected payloads, demonstrates an alarming evolution in threat actor tactics, exploiting trusted cloud services…
-
ASUS Armoury Crate-Schwachstelle CVE-2025-3464 ermöglicht Admin-Privilegien in Windows
Kurze Information für Leser, die ASUS Armoury Crate auf ihren Windows-Systemen einsetzen. Die Schwachstelle CVE-2025-3464 in der Software ermöglicht es einem Angreifer Administrator-Berechtigungen unter Windows zu erlangen. ASUS hat inzwischen die Software aktualisiert, um die Schwachstellen zu schließen. Armoury Crate … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/18/asus-armoury-crate-schwachstelle-cve-2025-3464-ermoeglicht-admin-privilegien-in-windows/
-
Veeam Backup Replication 12.3.2 schließt kritische Schwachstellen (CVE-2025-23121 etc.)
Nutzer von Veeam Backup & Replication müssen reagieren. Der Anbieter Veeam hat zum 17. Juni 2025 Veeam Backup & Replication 12.3.2 sowie Veeam Agent for Microsoft Windows 6.3.2 veröffentlicht. Veeam Backup & Replication 12.3.2 schließt unter anderem eine kritische Remote … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/17/veeam-backup-replication-12-3-2-schliesst-kritische-schwachstellen-cve-2025-23121-etc/
-
Windows privilege escalation possible with ASUS Armoury Crate flaw
First seen on scworld.com Jump to article: www.scworld.com/brief/windows-privilege-escalation-possible-with-asus-armoury-crate-flaw
-
New KimJongRAT Stealer Uses Weaponized LNK File to Deploy PowerShell-Based Dropper
The two new variants of the KimJongRAT stealer have emerged, showcasing the persistent and evolving nature of this malicious tool first identified in 2013. Detailed research by Palo Alto Networks’ Unit 42 reveals that these variants, one employing a Portable Executable (PE) file and the other a PowerShell implementation, leverage a weaponized Windows shortcut (LNK)…
-
New Chaos RAT Variants Targeting Windows and Linux Systems to Steal Sensitive Data
The Acronis Threat Research Unit has identified new variants of Chaos RAT, a remote administration tool (RAT) that has evolved from an open-source project first observed in 2022 into a formidable multi-platform malware. These latest iterations of Chaos RAT are now targeting both Windows and Linux systems, showcasing an alarming level of sophistication through phishing-driven…
-
XDSpy Threat Actors Exploit Windows LNK Zero-Day Vulnerability to Target Windows System Users
The XDSpy threat actor has been identified as exploiting a Windows LNK zero-day vulnerability, dubbed ZDI-CAN-25373, to target governmental entities in Eastern Europe and Russia. This ongoing campaign, active since March 2025, employs an intricate multi-stage infection chain to deploy the malicious XDigo implant, crafted in Go, as revealed by a detailed investigation stemming from…
-
Microsoft fixes Surface Hub boot issues with emergency update
Microsoft has released an emergency update to fix a known issue causing startup failures for some Surface Hub v1 devices running Windows 10. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-fixes-surface-hub-boot-issues-with-emergency-update/
-
Gesichtserkennung: Windowsin per Kamera schlägt fehl, wenn es dunkel ist
Tags: windowsSeit April können sich Anwender bei Dunkelheit nicht mehr per Gesichtsscan bei Windows anmelden. Das ist Teil eines Patches und offenbar so gewollt. First seen on golem.de Jump to article: www.golem.de/news/gesichtserkennung-windows-hello-verweigert-anmeldung-bei-dunkelheit-2506-197187.html
-
ASUS Armoury Crate Vulnerability Lets Hackers Gain System-Level Access on Windows
A critical vulnerability in ASUS’s popular Armoury Crate software has exposed millions of Windows users to the risk of system-level compromise, according to a recent disclosure by Cisco Talos and confirmed by ASUS. The flaw, tracked as CVE-2025-3464, allows attackers to bypass security controls and gain the highest level of privileges on affected systems, potentially…
-
Windows Hello: Anmeldung per Gesichtsscan schlägt fehl, wenn es dunkel ist
Tags: windowsSeit April können sich Anwender bei Dunkelheit nicht mehr per Gesichtsscan bei Windows anmelden. Das ist Teil eines Patches und offenbar so gewollt. First seen on golem.de Jump to article: www.golem.de/news/gesichtserkennung-windows-hello-verweigert-anmeldung-bei-dunkelheit-2506-197187.html
-
Durch Juni-Updates: Gravierende DHCP-Probleme bei Windows Server
Im Netz häufen sich Beschwerden von Admins, deren DHCP-Server nach dem Juni-Patchday nicht mehr funktionieren. Einen offiziellen Fix gibt es noch nicht. First seen on golem.de Jump to article: www.golem.de/news/durch-juni-updates-gravierende-dhcp-probleme-bei-windows-server-2506-197195.html
-
Gesichtserkennung: Windows Hello verweigert Anmeldung bei Dunkelheit
Tags: windowsSeit April können sich Anwender nicht mehr per Gesichtsscan bei Windows anmelden, wenn es dunkel ist. Das ist Teil eines Patches und offenbar so gewollt. First seen on golem.de Jump to article: www.golem.de/news/gesichtserkennung-windows-hello-verweigert-anmeldung-bei-dunkelheit-2506-197187.html
-
DeerStealer Malware Deployed Through Exploitation of Windows Run Prompt by Threat Actors
The eSentire’s Threat Response Unit (TRU) has uncovered a series of malicious campaigns throughout May 2025, where threat actors have been deploying the DeerStealer malware, also known as XFiles Spyware, using the HijackLoader malware loader. This sophisticated information stealer, peddled on dark-web forums by a user named “LuciferXfiles,” is designed to harvest a wide array…
-
ASUS Armoury Crate bug lets attackers get Windows admin privileges
A high-severity vulnerability in ASUS Armoury Crate software could allow threat actors to escalate their privileges to SYSTEM level on Windows machines. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/asus-armoury-crate-bug-lets-attackers-get-windows-admin-privileges/
-
Microsoft adds export option to Windows Recall in Europe
But lose your code and it’s gone for good First seen on theregister.com Jump to article: www.theregister.com/2025/06/16/microsoft_snapshot_export_recall/
-
Windows 95 testing almost stalled due to cash register overflow
Microsoft veteran on breaking down numbers at the computer store First seen on theregister.com Jump to article: www.theregister.com/2025/06/15/windows_95_testing_almost_stalled/
-
BERT Ransomware Escalates Attacks on Linux Machines with Weaponized ELF Files
The BERT ransomware group, first detected in April 2025 but active since mid-March, has expanded its reach from targeting Windows environments to launching sophisticated attacks on Linux machines as of May 2025. Initially spotted through phishing campaigns, BERT has evolved into a formidable adversary by deploying weaponized ELF (Executable and Linkable Format) files tailored for…
-
June Windows Server security updates cause DHCP issues
Microsoft acknowledged a new issue caused by the June 2025 security updates, causing the DHCP service to freeze on some Windows Server systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-june-windows-server-security-updates-cause-dhcp-issues/
-
Juni-Patchday: Windows-Update macht Fujitsu-Rechner kaputt
Betroffene Systeme zeigen nach Installation des Juni-Updates für Windows nur noch das Fujitsu-Logo und reagieren nicht mehr. Die Rettung ist aufwendig. First seen on golem.de Jump to article: www.golem.de/news/juni-patchday-windows-update-macht-fujitsu-rechner-kaputt-2506-197156.html
-
Microsoft-Signed Firmware Module Bypasses Secure Boot
UEFI Vulnerability Threatens Systems with Silent Compromise. Hackers could circumvent the protections of Secure Boot by silently disabling it through an attack that potentially affects a wide swath of Windows laptops and servers. Microsoft issued a patch this month and hackers would already need admin access and physical access to a target machine. First seen…

