Tag: windows
264 articles

Iranian Hackers Deploy Cross-Platform Malware via Coding Tests
Iranian hackers are using clever tactics to deploy cross-platform malware, disguising it as coding challenges on LinkedIn and other job search platforms to trick developers into installing the threat. This malware, tracked as NodeRabbit and PollCat, can infect Windows, Linux, and macOS workstations, allowing hackers to gain remote access.

Microsoft Exposes TerminalFix Attacks Deploying Reverse Tunnels
Beware of TerminalFix attacks that use fake Cloudflare CAPTCHA prompts on compromised websites to trick you into executing malicious PowerShell commands in Windows Terminal. These sneaky attacks can lead to more complex threats, making it crucial to stay vigilant online.

Microsoft Warns of TerminalFix Malware Hiding in PNGs
Microsoft researchers have uncovered a sneaky malware campaign, dubbed TerminalFix, that hides in plain sight by masquerading as harmless PNG images - only to delete them after extraction, leaving behind a trail of PowerShell commands that can compromise your system. This fresh variant of the ClickFix social-engineering trick tricks victims into pasting malicious commands into Windows Terminal or PowerShell.

Microsoft Warns of TerminalFix Backdoor Deploying via Fake Cloudflare CAPTCHAs
Beware of fake Cloudflare CAPTCHAs that can lead to a sneaky backdoor invasion, giving attackers direct access to your organization's internal network. A new variant of malware, called TerminalFix, tricks victims into executing a malicious PowerShell command, allowing hackers to gain control.

Next.js Patches Flaws Enabling Unauthenticated Remote Code Execution
If your Next.js application is hosted on Windows, upgrade immediately to patch a critical vulnerability that allows unauthenticated remote code execution. This flaw, tracked as CVE-2026-75604, affects apps using both Pages Router and App Router without Cache Components.

Amazon Kiro Flaw Exposes Sensitive Data Through Prompt Injection
A security flaw in Kiro, known as a prompt injection vulnerability, allowed hackers to tap into sensitive data by manipulating the Kiro agent with malicious repository content. This issue, affecting Kiro IDE 0.7.45 on Windows, could send local information to an external endpoint, putting users at risk.

CISA Mandates Swift Patching for Oracle Flaw
Don't wait - patch now! A critical Oracle flaw, scored 10.0, requires immediate attention to prevent low-complexity attacks that could give hackers complete access to your critical data.

Researchers Expose Chrome DevTools Protocol Hijacking Technique
Google warns that attackers are exploiting Chrome Remote Debugging to steal cookies, and now researchers have developed a new technique to activate DevTools inside a live browser, allowing for even easier cookie extraction. This technique uses a Beacon Object File to tap into the Chrome DevTools Protocol, posing a new threat to users.

HoneyMyte APT Group Upgrades CoolClient Backdoor with Kernel-Level Rootkit
Meet the upgraded CoolClient Backdoor, now packing a kernel-level rootkit courtesy of the sneaky HoneyMyte APT Group - and it's hiding in plain sight with a legit digital signature. This clever malware uses a Windows service and a kernel-mode driver to evade detection.

Microsoft patches LegacyHive zero-day vulnerability
Microsoft just patched a nasty zero-day vulnerability, known as LegacyHive, that could let hackers gain administrator privileges on your Windows PC - but thankfully, it's now fixed in the August Patch Tuesday updates.

Windows Plug and Play Feature Exploited for SYSTEM Access via Fake USB Devices
Imagine a scenario where hackers can gain SYSTEM access to a Windows computer without needing a single click or logged-in user - and even exploit it remotely over RDP with no hardware involved. Researchers have just revealed a chilling new class of attacks, dubbed "Plug and Pwn", that takes advantage of Windows' Plug and Play feature to execute malicious software with alarming ease.

Lazarus Exploits Windows Zero-Day with Post-Quantum Key Exchange Tactics
Lazarus hackers have taken a cutting-edge approach, using a post-quantum key exchange to secure their command channel before exploiting a Windows zero-day vulnerability in a targeted campaign against defense and aerospace companies. They leveraged Kyber/ML-KEM, a key encapsulation scheme designed to withstand quantum computer attacks, to generate fresh key material and evade detection.

Microsoft Patch Tuesday Disrupts 400 Vulnerabilities, Zero-Day Exploits
Microsoft's August Patch Tuesday update is a doozy, tackling a whopping 400 vulnerabilities, including an actively exploited zero-day threat that demands immediate attention from sysadmins. With high-risk impacts on confidentiality, integrity, and availability, these fixes should be top priority.

Microsoft Disrupts Hundreds of Flaws in Massive Patch Update
Microsoft just dropped a massive patch update to fix a whopping 398 security flaws in Windows and its software, including a critical vulnerability that's already being exploited by hackers. This crucial update tackles a range of weaknesses, from a zero-day privilege-escalation flaw in a key Windows driver to other publicly known vulnerabilities.

Microsoft Patches Zero-Day Windows Driver Flaw Under Active Attack
Microsoft just patched a high-severity Windows driver flaw, known as CVE-2026-68820, that was already being exploited by hackers in the wild. This zero-day vulnerability, with a CVSS score of 7.0, could be triggered by a race condition, allowing attackers to gain a foothold in targeted systems.

Passkey Defenses Targeted in Novel Attacks
Researchers at Black Hat USA 2026 revealed a shocking vulnerability in passkey defenses, demonstrating how attackers can bypass FIDO2 cryptography and exploit a flaw in Windows Event Logging Service (CVE-2026-34348) to defeat passkey protections. This security gap was found to allow unauthorized users to access and replay sensitive YubiKey signatures.

Phishing Campaign Exploits COLDCARD Vulnerability to Install Remote Access Tool
Worried COLDCARD owners are being targeted by a sneaky phishing campaign that masquerades as a security audit, tricking them into installing remote-access software on their Windows machines. Scammers are sending fake emails from a spoofed address, claiming a hardware audit is underway to verify the integrity of COLDCARD devices.

Malware Exploits Google Passkey Sync Flaws
Google's passkeys, touted as a secure alternative to passwords, have been found to have flaws that can be exploited by malware, allowing hackers to access sensitive information. Researchers have discovered three techniques, dubbed Pass-ta-key, that let attackers abuse Google Password Manager's synced passkeys on compromised Windows devices.

Russian Loader Service Exploits Browser Cache to Deliver Malware
Meet DOUBLECUP, a sneaky Russian loader service that's been hiding in plain sight since June 2026, using browser cache tricks to deliver malware to unsuspecting victims. Its clever ClickFix campaigns conceal malicious code within innocent-looking PNG images, deploying nasty payloads like CountLoader and DeviceManager RAT on Windows and macOS devices.

Attackers Exploit, Then Manipulate: The Post-Breach Playbook
Attackers often find an open door in our defenses, exploiting weaknesses like SQL injection vulnerabilities to gain a foothold - and then manipulate systems to wreak havoc. A recent incident revealed how an unvalidated input field on a webpage led to a full-blown breach of a Microsoft SQL Server host.

Microsoft Secure Boot Vulnerability Exposed After 13 Years
A shocking security vulnerability in Microsoft's Secure Boot, a safeguard designed to protect Windows and Linux devices from firmware infections, has been easily exploitable for 13 of its 14 years of existence. Researchers uncovered 11 defective firmware images, some dating back to 2013, that were still publicly available and signed by Microsoft, making it alarmingly simple to bypass the security measure.

Chaos Ransomware Exploits Headless Browsers for Covert C2 Traffic
Cisco Talos uncovered a sneaky tactic used by Chaos Ransomware, where a Rust implant called msaRAT hijacks a victim's browser to disguise its communications, making it look like they're coming from a legitimate browser process. This clever trick lets the malware fly under the radar by using the Chrome DevTools Protocol to control the browser.

Zoom Patches Flaw That Could Enable Account Takeover
Zoom just patched a critical security flaw that could let hackers hijack your account - and you need to update your software ASAP to stay safe! This vulnerability, tracked as CVE-2026-53412, could allow anyone on your network to take over your Zoom account.

Zoom Discloses High-Severity Account Takeover Vulnerability
Zoom has warned users of a high-severity vulnerability in its Windows desktop client and software development kit that could let hackers hijack accounts without authentication. This critical flaw, tracked as CVE-2026-53412, has a severity score of 9.8 out of 10.