Tag: windows
-
CISA, Microsoft warn of Windows zero-day used in attack on ‘major’ Turkish defense org
Check Point attributed the attack to a group known as Stealth Falcon, a hacking group with longstanding ties to the UAE that has been implicated in dozens of spyware cases and hacking incidents involving governments across the Middle East and Africa. First seen on therecord.media Jump to article: therecord.media/microsoft-cisa-zero-day-turkish-defense-org
-
Microsoft Security Update Summary (10. Juni 2025)
Microsoft hat am 10. Juni 2025 Sicherheitsupdates für Windows-Clients und -Server, für Office sowie für weitere Produkte veröffentlicht. Die Sicherheitsupdates beseitigen 65 Schwachstellen (CVEs), zwei davon wurden als 0-day klassifiziert. Eine Schwachstelle wurde bereits angegriffen. Nachfolgend findet sich … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/10/microsoft-security-update-summary-10-juni-2025/
-
Windows system takeovers enabled by new DuplexSpy RAT
First seen on scworld.com Jump to article: www.scworld.com/brief/windows-system-takeovers-enabled-by-new-duplexspy-rat
-
New Detection Tools Address Emerging Windows Server 2025 Flaw
First seen on scworld.com Jump to article: www.scworld.com/brief/new-detection-tools-address-emerging-windows-server-2025-flaw
-
Microsoft Windows WebDAV 0-Day RCE Vulnerability Actively Exploited in The Wild
A critical zero-day vulnerability in Microsoft Windows, designated CVE-2025-33053, has been actively exploited by the advanced persistent threat (APT) group Stealth Falcon. The flaw, enabling remote code execution (RCE) through manipulation of a system’s working directory, was addressed by Microsoft in its June 2025 Patch Tuesday updates following CPR’s responsible disclosure. Below is a technical…
-
Windows 10 KB5060533 cumulative update released with 7 changes, fixes
Microsoft has released the KB5060533 cumulative update for Windows 10 22H2 and Windows 10 21H2, with seven fixes or changes, including bringing seconds back to the time shown in the Calendar flyout. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-10-kb5060533-cumulative-update-released-with-7-changes-fixes/
-
Windows 11 KB5060842 and KB5060999 cumulative updates released
Microsoft has released Windows 11 KB5060842 and KB5060999 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues, including 66 flaws. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-11-kb5060842-and-kb5060999-cumulative-updates-released/
-
Microsoft Outlook to block more risky attachments used in attacks
Microsoft announced it will expand the list of blocked attachments in Outlook Web and the new Outlook for Windows starting next month. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-outlook-to-block-more-risky-attachments-used-in-attacks/
-
Juni 2025-Patchday soll Schwachstelle CVE-2025-33073 in Windows schließen
Zum 11. Juli 2025 wird Microsoft seinen regulären Patchday durchführen und Sicherheitsupdates für Windows veröffentlichen. Administratoren in Unternehmen sollten dieses Mal die Sicherheitsupdates zeitnah installieren, da eine Schwachstelle CVE-2025-33073 in Windows geschlossen werden soll. Zum Wochenende ging bereits eine Information … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/10/juni-2025-patchday-soll-schwachstelle-cve-2025-33073-in-windows-schliessen/
-
Inetpub-Ordner gelöscht: Angreifbare Windows-Systeme lassen sich per Skript absichern
Tags: windowsViele Windows-Nutzer haben den zum April-Patchday erzeugten Inetpub-Ordner gelöscht, obwohl er Teil eines wichtigen Patches ist. Ein Skript korrigiert das. First seen on golem.de Jump to article: www.golem.de/news/windows-skript-schliesst-luecke-durch-geloeschten-inetpub-ordner-2506-196968.html
-
Hotpatching für Windows 11 Updates ohne Neustart installieren
First seen on security-insider.de Jump to article: www.security-insider.de/hotpatching-in-windows-11–updates-ohne-neustart-a-510c435774d8fbf27dffc5997b84adab/
-
Acronis Cyber Protect Sicherheitslücken gefährden Windows-Systeme
Kurzer Hinweis für Nutzer, die Acronis Cyber Protect in einer Windows-Umgebung einsetzen. Es gibt eine aktuelle Sicherheitswarnung des Bundesamts für Sicherheit in der Informationstechnik (BSI). Demnach sind mehrere Schwachstellen im Produkt bekannt geworden, die die Sicherheit von Windows gefährden. Acronis … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/10/acronis-cyber-protect-sicherheitsluecken-gefaehrden-windows-systeme/
-
Windows-Lücke: Gelöschte Inetpub-Ordner jetzt per Skript wiederherstellbar
Tags: windowsViele Windows-Nutzer haben den zum April-Patchday erzeugten Inetpub-Ordner gelöscht, obwohl er Teil eines wichtigen Patches ist. Ein Skript korrigiert das. First seen on golem.de Jump to article: www.golem.de/news/windows-skript-schliesst-luecke-durch-geloeschten-inetpub-ordner-2506-196968.html
-
Skript schließt Lücke durch gelöschten Inetpub-Ordner
Tags: windowsViele Windows-Nutzer haben den zum April-Patchday erzeugten Inetpub-Ordner gelöscht, obwohl er Teil eines wichtigen Patches ist. Ein Skript korrigiert das. First seen on golem.de Jump to article: www.golem.de/news/windows-skript-schliesst-luecke-durch-geloeschten-inetpub-ordner-2506-196968.html
-
New Blitz Malware Targets Windows Servers to Deploy Monero Miner
A new Windows-based malware named Blitz has been identified in 2024, with an updated version detected in early 2025. This malware, actively developed and distributed through deceptive game cheats, poses a significant threat by deploying a Monero cryptocurrency miner alongside information-stealing and denial-of-service (DoS) capabilities. Detailed analysis by Palo Alto Networks’ Unit 42 reveals that…
-
Hackers Deploy FormBook Malware via Weaponized Excel Files to Target Windows Systems
A critical phishing campaign targeting Windows users has been uncovered by FortiGuard Labs, leveraging malicious Excel attachments to exploit a long-standing vulnerability in older versions of Microsoft Office. This sophisticated attack distributes FormBook, a notorious information-stealing malware designed to harvest sensitive data such as login credentials, keystrokes, and clipboard information. Phishing Campaign Exploits Old Microsoft…
-
New DuplexSpy RAT Gives Attackers Full Control Over Windows Machines
A new Remote Access Trojan (RAT) named DuplexSpy has surfaced, posing a significant threat to Windows-based systems worldwide. Developed in C# by GitHub user ISSAC/iss4cf0ng and released publicly on April 15, 2025, with a stated intent of >>educational purposes,
-
Designproblem erlaubt Aushebeln von Gruppenrichtlinien
In Windows schlummert ein Designproblem, das es normalen Nutzern und Malware erlaubt, von Admins gesetzte Gruppenrichtlinien außer Kraft zu setzen. First seen on golem.de Jump to article: www.golem.de/news/windows-designproblem-erlaubt-aushebeln-von-gruppenrichtlinien-2506-196925.html
-
14. Oktober 2025: Support-Ende für Windows 10 und weitere Software
Am 14. Oktober 2025 erhält Microsoft Windows 10 22H2 letztmalig Sicherheitsupdates und fällt dann aus dem Support. Aber es gibt Optionen, das Betriebssystem zumindest abzusichern. Abseits von diesem Sachverhalt erreichen weitere Microsoft Produkte wie die Universal Apps, OneNote für Windows … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/06/08/14-oktober-2025-support-ende-fuer-windows-10-und-weitere-software/
-
Microsoft shares script to restore inetpub folder you shouldn’t delete
Microsoft has released a PowerShell script to help restore an empty ‘inetpub’ folder created by the April 2025 Windows security updates if deleted. As Microsoft previously warned, this folder helps mitigate a high-severity Windows Process Activation privilege escalation vulnerability. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-shares-script-to-restore-inetpub-folder-you-shouldnt-delete/
-
Microsoft Unveils European Security Effort to Disrupt Cybercrime Networks
Tags: cve, cyber, cybercrime, exploit, flaw, microsoft, network, technology, threat, update, vulnerability, windows, zero-dayA critical heap-based buffer overflow vulnerability, tracked as CVE-2025-24993, has been discovered in the Windows New Technology File System (NTFS), posing a significant threat to millions of Windows users globally. The flaw, patched during Microsoft’s March 2025 Patch Tuesday, was actively exploited as a zero-day in the wild, prompting urgent advisories from both Microsoft and…
-
How to build a robust Windows service to block malware and ransomware
Designing a security-focused Windows Service? Learn more from ThreatLocker about the core components for real-time monitoring, threat detection, and system hardening to defend against malware and ransomware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-to-build-a-robust-windows-service-to-block-malware-and-ransomware/
-
Keine 150 Tage bis Support-Ende – Windows 10 legt bei Marktanteilen minimal zu
Tags: windowsDer Support für Windows 10 endet am 14. Oktober 2025, bei den Marktanteilen bleibt es aber stabil vor Windows 11. First seen on computerbase.de Jump to article: www.computerbase.de/news/betriebssysteme/keine-150-tage-bis-support-ende-windows-10-legt-bei-marktanteilen-minimal-zu.93011
-
OpenAI Report: 10 AI Threat Campaigns Revealed Including Windows-Based Malware, Fake Resumes
OpenAI’s June 2025 report, which details 10 threats from six countries, warns that AI is accelerating cyber threats, lowering barriers for attackers, and calling for collective detection efforts. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-openai-ai-threat-report/
-
New versions of Chaos RAT target Windows and Linux systems
Acronis researchers reported that new Chaos RAT variants were employed in 2025 attacks against Linux and Windows systems. Acronis TRU researchers discovered new Chaos RAT variants targeting Linux and Windows in recent attacks. Originally seen in 2022, Chaos RAT evolved in 2024, with fresh samples emerging in 2025. TRU also discovered a critical flaw in…
-
RSA Expands Passwordless Authentication with Windows Desktop Login and Entra ID Integration
First seen on scworld.com Jump to article: www.scworld.com/news/rsa-expands-passwordless-authentication-with-windows-desktop-login-and-entra-id-integration
-
New Chaos RAT Targets Linux and Windows Users to Steal Sensitive Data
A new wave of cyber threats has emerged with the discovery of updated variants of Chaos RAT, a notorious open-source remote administration tool (RAT) first identified in 2022. As reported by Acronis TRU researchers in their recent 2025 analysis, this malware continues to evolve, targeting both Linux and Windows environments with sophisticated capabilities for espionage…
-
KDE targets Windows 10 ‘exiles’ claiming ‘your computer is toast’
Encourages move to Linux but, for goodness sake, RTFM first First seen on theregister.com Jump to article: www.theregister.com/2025/06/04/kde_windows_10_exiles/
-
Designing a Windows Service for Security
Designing a security-focused Windows Service? Learn more from ThreatLocker about the core components for real-time monitoring, threat detection, and system hardening to defend against malware and ransomware. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/designing-a-windows-service-for-security/

