Articles tagged "Windows"

Found 95 articles

Vercel has issued security patches for two serious vulnerabilities in the Next.js framework that could allow attackers to execute code remotely without authentication. The first vulnerability arises from the handling of AVIF image files, which can be manipulated to exploit the system. The second flaw is a path traversal issue that affects installations on Windows filesystems, enabling unauthorized access to files. These vulnerabilities are particularly concerning because they can be exploited without any user interaction, putting many applications at risk if they use Next.js. Developers using this framework should prioritize updating to the latest version to mitigate these risks.

Read Original

A new Windows backdoor known as SLEEPWALKER has been discovered by an independent malware researcher. This backdoor remains inactive until it receives a specifically crafted network packet, at which point it executes commands written in a unique 23-instruction language. The malicious software is an unsigned 64-bit dynamic-link library (DLL) totaling nearly 60,000 bytes, designed for side-loading. This means that it could potentially be used to infiltrate systems quietly and execute commands without detection. The implications are serious, as it poses a risk to Windows users who may unknowingly execute this backdoor, allowing attackers to take control of affected machines.

Read Original

Windows named pipes, a method for fast communication between processes, have been identified as a potential security risk due to weak access controls. This vulnerability allows untrusted processes to potentially access privileged services, posing a threat to system integrity. Security experts from ThreatLocker recommend several strategies to mitigate these risks, including endpoint verification, command authorization, strict input validation, and limiting privileges to what is necessary. These measures can help secure named-pipe communications and protect against unauthorized access. Organizations using Windows systems should take these recommendations seriously to safeguard their environments from potential exploitation.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a serious remote code execution (RCE) vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions. This flaw is currently being exploited by attackers, which raises significant concerns for organizations using affected systems. The vulnerability could allow hackers to execute arbitrary code on compromised devices, potentially leading to data breaches or system control. Windows users and administrators are urged to take immediate action to protect their systems. This situation highlights the ongoing risks associated with software vulnerabilities and the importance of timely updates and security measures.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog, specifically targeting flaws in Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE. One notable vulnerability, CVE-2026-33824, relates to the Windows Internet Key Exchange (IKE) Service Extensions and poses a risk of remote code execution. These vulnerabilities could allow attackers to exploit systems running the affected software, potentially leading to unauthorized access or data breaches. It's crucial for users and organizations utilizing these platforms to take immediate action to mitigate the risks associated with these vulnerabilities. Keeping software updated and applying any available patches is essential to protect against potential exploitation.

Read Original
Actively Exploited

Mustang Panda, also known as HoneyMyte, has enhanced its CoolClient backdoor by deploying a signed kernel-mode driver that can conceal processes, files, and network activity. This upgrade makes it significantly harder for security software to detect and remove the malware from infected Windows systems. Kaspersky's recent analysis indicates that this new variant of CoolClient deepens the malware's integration into the operating system, raising concerns for users and organizations relying on Windows. The implications are serious, as this could allow attackers to maintain prolonged access to compromised systems while evading detection. Users and organizations need to remain vigilant and implement security measures to protect against this evolving threat.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its catalog of exploited vulnerabilities. These include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898). These flaws could allow attackers to exploit systems running affected software, potentially leading to unauthorized access or data breaches. Organizations using these products need to take immediate action to protect their systems. Awareness and prompt updates are essential to mitigate the risks associated with these vulnerabilities.

Read Original

Wireshark has released version 4.6.8 to address 28 security vulnerabilities, with nine of these affecting file parsers that process saved capture files. These vulnerabilities could be exploited simply by opening a maliciously crafted capture file, which means an attacker does not need direct access to the network. The affected file parsers include formats like pcapng, Endace ERF, and several others, specifically on Windows systems. This update is critical for users of Wireshark, as it helps prevent potential exploitation that could compromise sensitive data or system integrity. Users are urged to update to the latest version to mitigate these risks.

Read Original

In August 2026, Microsoft released patches addressing over 400 vulnerabilities, including a serious zero-day exploit identified as CVE-2026-68820. This particular flaw is a use-after-free vulnerability affecting the Windows Ancillary Function Driver for WinSock (AFD.sys), which could allow a low-privileged local attacker to gain elevated privileges to the SYSTEM level. This means that attackers with local access could potentially execute malicious applications to take control of affected systems. The urgency of this update is underscored by the fact that the vulnerability is already being exploited in the wild. Users and organizations relying on Windows systems should prioritize applying these updates to mitigate potential risks.

+1 more
Read Original

A security researcher known as Chaotic Eclipse has released a proof of concept (PoC) for a new zero-day vulnerability named ShieldBreak, affecting Microsoft Defender. This vulnerability successfully bypasses the previously issued patch for CVE-2026-50656, known as RoguePlanet, which was intended to address a race condition. If exploited, ShieldBreak could allow attackers to execute code with SYSTEM-level privileges on affected systems. This presents a serious risk to users of Microsoft Defender, as the flaw can potentially compromise the security of their devices. Companies using Microsoft Defender should take immediate action to assess their systems and apply necessary security measures to mitigate this risk.

Read Original

A security researcher known as Chaotic Eclipse has released a proof-of-concept (PoC) for a serious zero-day vulnerability dubbed ShieldBreak, affecting Microsoft Defender for Windows. This vulnerability allows attackers to bypass the existing patch for CVE-2026-50656, also known as RoguePlanet, which has a CVSS score of 7.8, indicating a significant security risk. The flaw could enable unauthorized access with SYSTEM privileges, putting users' systems at risk. This discovery is crucial as it highlights the weaknesses in Microsoft Defender's security measures, potentially exposing millions of users to exploitation. Companies using Microsoft Defender should remain vigilant and apply any available patches while monitoring for any signs of exploitation.

Read Original

Microsoft's August Patch Tuesday updates address several vulnerabilities, with CVE-2026-62878 standing out due to its severity. This remote code execution vulnerability in Windows DNS Server has a high CVSS score of 9.8 and can be exploited without user interaction. This means attackers could potentially take control of affected systems easily, posing a significant risk to organizations relying on Windows DNS servers for their operations. It’s crucial for system administrators to prioritize applying this patch to protect their networks from potential exploitation. The updates are part of Microsoft's ongoing efforts to enhance security across its products, but this particular flaw underscores the importance of timely patch management.

Read Original

Microsoft has released its monthly security updates, addressing a total of 398 vulnerabilities, including a serious zero-day flaw that is currently being exploited in attacks. This particular vulnerability, tracked as CVE-2026-68820, affects a core Windows kernel driver responsible for network socket operations. Attackers who already have code running on a targeted machine can exploit this flaw to gain elevated privileges, potentially allowing them to execute commands with SYSTEM-level access. Given the active exploitation, users and organizations should prioritize applying the patch to mitigate the risk of unauthorized access. The patch is crucial for maintaining system security and preventing further attacks.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are actively exploited in the wild. The vulnerabilities include a heap inspection flaw in Cisco Secure Firewall Adaptive Security Appliance (CVE-2026-20349), a use-after-free vulnerability in Microsoft Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a SQL injection vulnerability in Metabase (CVE-2026-72898). These vulnerabilities pose significant risks, especially to federal agencies, prompting CISA to emphasize the need for rapid remediation of high-risk vulnerabilities. While the Binding Operational Directive 26-04 applies specifically to federal agencies, CISA encourages all organizations to adopt similar risk-based approaches to vulnerability management. Organizations aware of other exploited vulnerabilities can submit them for potential inclusion in the KEV Catalog.

Read Original

Recent research has shown vulnerabilities in passkey systems designed to enhance online security by replacing traditional passwords and resisting phishing attacks. Three separate studies demonstrated methods for bypassing these protections without breaking the underlying cryptography. For instance, attackers were able to exploit signed authentication data exposed by Windows, leverage a cloud-synced passkey system compromised by existing malware on a victim's device, and other techniques. This is concerning for users and organizations relying on passkeys for secure authentication, as it suggests that even advanced security measures can be undermined. As these attacks become more sophisticated, it raises questions about the reliability of passkeys and the need for ongoing vigilance in security practices.

Read Original
Page 1 of 7Next