Skip to main content

Tag: endpoint security

36 articles

Windows desktop screen with a blurred notification alert and warning icon.

Microsoft Disregards Defender Alerts as False Positives

If you've recently updated Microsoft Defender Antivirus, you might be seeing annoying false alarms claiming it's turned off - but don't worry, it's still working hard to protect you. These pesky alerts are affecting all supported Windows versions, including Windows 11 26H1 and Windows Server 2025.

Analyst 207
Empty workstation area in a cybersecurity operations center with laptops and network equipment.

AI-Enabled Malware Detected but Not Dominant

The surprising truth about AI-enabled malware: despite collecting 405 samples, only 12 actually appeared on customer endpoints, revealing a significant gap in detection. This finding highlights the limited presence of AI-powered threats in the wild.

Analyst 207
Laptop screen shows a WordPress backend dashboard with a compromised website's source code on a messy desk.

MaaS Operators Combine ErrTraffic, ClickFix to Evade Endpoint Security

Cyber attackers have launched a sneaky campaign that combines ErrTraffic and ClickFix to outsmart endpoint security, starting with compromised WordPress sites that inject obfuscated JavaScript to evade detection. This clever tactic uses the Ethereum blockchain to stay one step ahead of security tools.

Analyst 207
Windows Defender error message on laptop screen in cluttered home office setting.

Microsoft Fixes Bug Disrupting Windows Defender Scans

Windows Defender was acting up, causing scans to fail and crashes with annoying error messages - but thankfully, Microsoft has swooped in to fix the problem. The update resolves issues with 0xc0000005 access violation errors and pesky "Threat service has stopped" messages on Windows 10 and 11 devices.

Analyst 207
Cluttered office desk with laptop showing Windows login or blue screen, surrounded by papers and supplies near a window.

Akira Ransomware Gang Foiled by Safe Mode Reboot

In a surprising twist, an Akira ransomware affiliate inadvertently sabotaged its own attack by rebooting a victim's system into Safe Mode, thwarting the mass-encryption step but not before exfiltrating sensitive credentials and files. This unexpected turn of events highlights the unpredictable nature of cyber attacks.

Analyst 207
System administrator inspects Linux servers in a server room with one server displaying a maintenance screen.

Microsoft Defender for Endpoint update cripples Linux protection

A recent update to Microsoft Defender for Endpoint has caused a major hiccup, crippling Linux protection and potentially leaving some devices vulnerable. The issue affects specific Linux versions, and a simple upgrade or reinstall followed by a reboot could be the culprit behind a disabled Defender service.

Analyst 207
Developer workstation with laptop and coding tools, subtle security presence hinted at with blurred software interface and…

AI Coding Agents Trigger Endpoint Security Rules Meant for Attackers

In a surprising twist, over half of the blocked activity detected by Sophos in June 2026 came from developer coding assistants, not hackers, triggering endpoint security rules meant to catch malicious actors. This unexpected behavior highlights the need for a closer look at the intersection of AI-powered coding tools and cybersecurity protocols.

Analyst 207
Cluttered home office desk with Mac laptop, coffee cup, and papers, conveying everyday use and vulnerability.

macOS Flaw Enables Users to Disable EDR, MDM Tools

A security flaw in macOS has been discovered that allows users to quietly disable crucial enterprise security tools, including EDR and MDM, without needing administrator privileges. This gap in endpoint security models could leave businesses vulnerable to attacks.

Analyst 207
Disrupted city transit platform with security router amid anxious bystanders.

Gentlemen Ransomware Targets EDR Defenses With Suite of Killers

Meet GentleKiller, a powerful tool used by Gentlemen ransomware to disable EDR defenses by targeting over 400 processes from 48 security vendors, allowing for smooth data theft and encryption. This sneaky utility relies on the bring your own vulnerable driver (BYOVD) technique to outsmart security engines.

Analyst 207
Security staff member holding a PC near exit as Head of Security intervenes with concern.

Security Insider Exposes New Hire's Chaotic Tactics

A security insider recounts a tense confrontation with a new colleague over a departing workstation, revealing a chaotic approach to security protocols. The staffer's casual exit with a PC under their arm sparks a heated debate about data safety and responsibility.

Analyst 207
Laboratory setting with computer workstations, coding terminals, and testing equipment.

Threat Actor Leverages AI to Craft EDR Evasion Tools

Sophos X-Ops stumbled upon a secret laboratory while investigating a routine endpoint alert, uncovering a trove of AI-powered tools designed to sneak past modern EDR agents. The surprising discovery revealed a sophisticated operation using partly AI-generated Python scripts to craft evasive tools.

Analyst 207
Network device sits prominently in a server room with management console blurred in background.

Hackers Exploit FortiClient Flaw to Deliver Infostealer Malware

Hackers are exploiting a vulnerability in FortiClient Enterprise Management Server to deliver infostealer malware, cleverly disguising the payload as a legitimate Fortinet endpoint update. This sneaky tactic uses FortiClient-managed VPN scripting workflows to execute the malicious code, putting security teams on high alert.

Analyst 207
Office workstation with laptop, desk, chair, and papers in a calm, neutral-colored setting.

Microsoft Defender Automatically Isolates Hacked Endpoints

Microsoft Defender for Endpoint just got a major boost with its new automatic isolation feature, which swiftly isolates compromised devices to prevent attackers from wreaking havoc on your organization. This cutting-edge capability is part of Microsoft's automatic attack disruption feature, designed to contain threats and give security teams more time to respond.

Analyst 207
Windows computer screen displays system update information in a clean workspace setting.

Microsoft Introduces Automated Windows Driver Rollback Feature

Microsoft's new Cloud-Initiated Driver Recovery feature lets them swiftly roll back faulty Windows drivers, so you don't have to - no more manual uninstalls or waiting for an updated driver from the hardware partner. This means your device can quickly get back on track with a reliable driver.

Analyst 207
Rows of equipment racks and patch panels in a brightly-lit server room or network closet.

CISA Mandates Patching of Ivanti Flaw Exploited in Zero-Day Attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) is requiring immediate patching of a high-risk Ivanti flaw, CVE-2026-6973, that allows attackers with admin privileges to remotely execute code on vulnerable systems. This critical vulnerability affects Ivanti Endpoint Manager Mobile (EPMM) version 12.8.0.0 and earlier.

Analyst 207
Security analysts work at desks with laptops and monitors displaying code and system maps in a brightly-lit operations…

MacOS Attacks Evolve, Exploiting Native Tools for Stealth

As macOS use surges in enterprise environments, accounting for over 45% of organizations, attackers are getting creative - exploiting native tools like Remote Application Scripting, Terminal, and AppleScript to stealthily run code, move undetected, and evade security measures. Cisco Talos warns that these tactics allow hackers to issue malicious instructions across processes and systems without triggering conventional monitoring.

Analyst 207
Shadowy figure in a hoodie sits in front of laptop with distorted cityscape on screen, hands near keyboard and phone nearby.

Ransomware Exploits QEMU VMs to Evade Endpoint Security

Malicious software can now secretly launch a virtual machine inside your computer, allowing it to evade detection and phone home to its operator - a chilling new tactic that exposes weaknesses in traditional endpoint defenses. This stealthy approach, recently spotted in the Payouts King ransomware, uses the QEMU emulator to create a hidden virtual machine and bypass security measures.

Analyst 207
A lone figure in a hoodie works on a laptop surrounded by tech, with a robotic arm emerging from shadows.

Artemis Secures $70M to Deploy AI Agents Against Cyber Threats

Meet Artemis, a game-changing startup that's using AI agents to revolutionize the way organizations detect and investigate cyber threats - and they've just secured $70 million in funding to make it happen. By ditching outdated security systems, Artemis is pioneering a bold new approach to threat detection with AI-driven agents that span cloud, identity, and endpoints.

Analyst 207
A broken padlock lies amidst shattered glass and torn wires in front of a laptop screen displaying a ghostly cityscape at…

Malware Abuses Signed Software to Disable Antivirus Protections

Thousands of vulnerable endpoints across schools, utilities, governments, and hospitals have fallen prey to a sneaky malware that masquerades as legitimate software, only to disable antivirus protections and wreak havoc with SYSTEM-level privileges. This stealthy attack has left countless organizations defenseless against further threats.

Analyst 207
Dimly lit room with spotlight on laptop screen displaying warning, surrounded by shattered shield fragments and disabled…

Adware Operation Neutralizes Antivirus on 23,000 Hosts via Signed Updates

Imagine receiving a routine software update that secretly disables your antivirus protection, leaving you vulnerable to cyber threats - that's exactly what happened to 23,000 hosts in a shocking adware operation. Hackers cleverly used signed updates to deliver payloads that neutralized antivirus defenses, putting thousands of systems at risk.

Analyst 207
Cracked digital lock with laptop glow and scattered puzzle pieces, symbolizing exploited vulnerability.

CISA Mandates Emergency Patch for Exploited Ivanti EPMM Flaw

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a high-priority alert, ordering US government agencies to patch a critical vulnerability in Ivanti Endpoint Manager Mobile (EPMM) within just four days, as the flaw has been under active exploitation since January. With a Sunday deadline looming, federal IT teams are racing against the clock to secure systems and prevent further attacks.

Analyst 207
Fortinet Rushes Patch for Exploited FortiClient EMS Vulnerability

Fortinet Rushes Patch for Exploited FortiClient EMS Vulnerability

Fortinet has rushed out an emergency patch for a zero-day vulnerability in its FortiClient EMS product, which was being exploited by attackers before the fix was even available. This swift response aims to protect businesses from potential security breaches through its endpoint security clients.

Analyst 207
Ransomware Actors Exploit Vulnerable Drivers to Evade EDR Tools

Ransomware Actors Exploit Vulnerable Drivers to Evade EDR Tools

Ransomware operators are outsmarting defenders by exploiting vulnerable drivers to evade detection by endpoint security tools, with recent attacks disabling over 300 security products. This clever tactic allows hackers to silence security defenses and wreak havoc on networks.

Analyst 207
Fortinet Rushes Patch for Exploited EMS Flaw

Fortinet Rushes Patch for Exploited EMS Flaw

When the very tool designed to safeguard your network becomes a vulnerability, swift action is crucial - and that's exactly what Fortinet took by issuing an emergency security update over a weekend to patch a critical flaw in FortiClient Enterprise Management Server (EMS) that's being actively exploited by attackers. This out-of-the-usual-cycle patch underscores the urgency to protect your organization from prolonged exposure to potential threats.

Analyst 207