Articles tagged "Windows"

Found 97 articles

Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are actively exploited in the wild. The vulnerabilities include a heap inspection flaw in Cisco Secure Firewall Adaptive Security Appliance (CVE-2026-20349), a use-after-free vulnerability in Microsoft Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a SQL injection vulnerability in Metabase (CVE-2026-72898). These vulnerabilities pose significant risks, especially to federal agencies, prompting CISA to emphasize the need for rapid remediation of high-risk vulnerabilities. While the Binding Operational Directive 26-04 applies specifically to federal agencies, CISA encourages all organizations to adopt similar risk-based approaches to vulnerability management. Organizations aware of other exploited vulnerabilities can submit them for potential inclusion in the KEV Catalog.

Read Original

Recent research has shown vulnerabilities in passkey systems designed to enhance online security by replacing traditional passwords and resisting phishing attacks. Three separate studies demonstrated methods for bypassing these protections without breaking the underlying cryptography. For instance, attackers were able to exploit signed authentication data exposed by Windows, leverage a cloud-synced passkey system compromised by existing malware on a victim's device, and other techniques. This is concerning for users and organizations relying on passkeys for secure authentication, as it suggests that even advanced security measures can be undermined. As these attacks become more sophisticated, it raises questions about the reliability of passkeys and the need for ongoing vigilance in security practices.

Read Original
Critical
ABB Ability Zenon

All CISA Advisories

ABB Ability Zenon is facing significant vulnerabilities that could allow attackers to bypass security measures, crash systems, and compromise data. The issues primarily affect the IIoT services bundled with MongoDB version 4.2 across all versions of ABB Ability Zenon. Notably, vulnerabilities such as improper handling of length parameters and exploitation of uninitialized memory could lead to unauthorized actions. ABB has recommended urgent remediation steps, including replacing the bundled MongoDB with a supported version and uninstalling IIoT services if they are not needed. Given that these vulnerabilities impact critical infrastructure sectors like energy and healthcare, organizations using ABB Ability Zenon must act quickly to secure their systems.

Read Original

Cybersecurity researchers have identified a supply chain attack targeting QuickFox, a VPN tool favored by overseas Chinese users. The attack has reportedly been active since at least August 2025, involving a compromised version of the application that delivers the FDMTP backdoor. This backdoor allows attackers to gain unauthorized access to affected systems, posing significant risks to user privacy and data security. This incident raises concerns about the security of software supply chains, particularly for tools that are essential for users in sensitive environments. Users of QuickFox should be vigilant and consider alternative solutions while the situation is investigated further.

Read Original

The latest Malware newsletter from Security Affairs covers several significant developments in malware tactics. Notably, the DPRK's BlueNoroff group has upgraded its MaaS (Malware as a Service) ecosystem, introducing modular tools that enhance its capabilities. Additionally, a new threat called SourTrade has emerged, leveraging malvertising to deliver browser-assembled malware. Another concerning development is MedusaHVNC, which functions as a hidden desktop tool designed to capture live Windows sessions, potentially exposing sensitive information. The newsletter also includes an analysis of a malware strain named 'Cruciferra', though details on its specific impact are not provided. These findings underscore the evolving nature of cyber threats and the need for users and companies to stay informed and vigilant against such attacks.

Read Original

A vulnerability has been identified in the Mitsubishi Electric CC-Link IE TSN Communication Protocol that could allow attackers on the same network segment to manipulate communication data. This vulnerability, tracked as CVE-2026-13584, can lead to denial-of-service (DoS) conditions by disrupting the control functions of affected products. A wide range of Mitsubishi Electric MELSEC MX controllers, motion modules, and various remote and safety modules are affected, including models MX-R300, MX-R500, and several others. Users of these devices should be aware of the potential risks, as the exploitation of this flaw could significantly impair operational capabilities. Addressing this vulnerability is crucial for maintaining the integrity and reliability of systems relying on this communication protocol.

Read Original
Actively Exploited

Kaspersky researchers have identified a new strain of ransomware called GenieLocker, which targets Windows, Linux, and ESXi systems. This ransomware is associated with a group known as Toy Ghouls, which is primarily focused on financial extortion. The emergence of GenieLocker is concerning because it indicates a growing trend of customized ransomware that can impact multiple operating systems, making it a versatile threat for various organizations. Companies using affected systems should be vigilant and implement strong security measures to protect their data. With ransomware incidents on the rise, understanding the capabilities of threats like GenieLocker is crucial for effective defense strategies.

Read Original

Researchers have identified a significant vulnerability in Active Directory Certificate Services (AD CS), designated as CVE-2026-54121, also known as 'Certighost.' This flaw allows attackers to elevate privileges, potentially leading to a complete domain takeover. AD CS is a critical component of Microsoft Windows Server that organizations use to manage their Public Key Infrastructure (PKI). The release of a proof-of-concept exploit means that attackers may quickly learn how to exploit this vulnerability. Organizations using AD CS should be particularly vigilant as the risk of exploitation increases with the availability of this exploit.

Read Original

A cybercrime group linked to China has been using a sophisticated crypter service named Cruciferra to hide malware in attacks targeting Indian taxpayers, tax professionals, and corporate finance teams. Recent analysis from Proofpoint reveals that this service allows various cybercriminals to deliver different forms of remote access malware while evading detection. Cruciferra employs techniques such as Bring Your Own Vulnerable Driver (BYOVD) and process ghosting, which help the malware operate stealthily on victim systems. The implications of these tactics are significant, as they enable attackers to compromise sensitive financial data and potentially cause substantial financial harm to individuals and organizations. This development is a reminder for users and companies to remain vigilant against evolving cyber threats and to implement strong security measures.

Read Original

A recent security flaw in Bing's image processing system allowed crafted SVG files to execute commands with elevated privileges, specifically as NT AUTHORITY\SYSTEM on Windows servers and as root on Linux machines. This vulnerability was identified through testing by security researchers at XBOW, who found that the issue was not isolated to a single machine but was present across multiple hosts and network ranges within Bing’s infrastructure. Microsoft responded by issuing two critical CVEs, CVE-2026-32194 and another unnamed one, to address the vulnerabilities. This incident raises significant concerns about the security of cloud-based services and the potential for attackers to exploit similar flaws to gain unauthorized access to sensitive systems. Companies relying on these services should prioritize patching and review their security protocols to mitigate risks from this kind of vulnerability.

Read Original

A China-based cyber operation known as JadeProx has been identified targeting government, healthcare, and education sectors in Asia and Latin America. Researchers from Group-IB discovered an exposed server on Alibaba Cloud in Singapore that was linked to these attacks. The operation utilizes a new Windows loader called TriBack Loader, which had not been documented before. Although the server was offline by the time of the report in mid-April 2026, the implications of these attacks are significant, as they threaten sensitive information and operations within critical public services. Organizations in the affected regions need to bolster their security measures to defend against such sophisticated threats.

Read Original

Microsoft has issued an out-of-band update, KB5121767, to address a shutdown issue affecting certain Dell PCs that arose after the installation of July 2026 Windows 11 security updates. Users reported that their devices were unexpectedly shutting down, which raised concerns about system stability and user productivity. This fix specifically targets Dell systems, indicating that the problem may be linked to specific hardware configurations. Users of affected Dell PCs are encouraged to install this update to prevent further shutdowns and ensure their systems operate correctly. This incident serves as a reminder of the complexities involved in software updates, especially when they interact with various hardware.

Read Original
Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug

Security Affairs

Zoom has identified and patched a serious vulnerability in its Windows applications, labeled CVE-2026-53412, which carries a CVSS score of 9.8. This flaw allows attackers to take control of user accounts without needing any authentication, posing a significant risk to users of older versions of the Workplace and Windows VDI Client. The vulnerability primarily affects organizations using these outdated versions, making it essential for them to update promptly. The potential for account takeover could lead to unauthorized access to sensitive information, making this a critical security issue for affected users. Zoom's quick response to fix this vulnerability is crucial to protect its user base from potential exploitation.

Read Original

Zoom has addressed a serious security flaw in its Windows applications that could allow attackers to take over user accounts. This vulnerability, identified as CVE-2026-53412, has a high severity score of 9.8, indicating its potential impact. The flaw affects several Zoom products, including the Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. Users of these applications are at risk, making it crucial for them to apply the necessary updates. By patching this vulnerability, Zoom aims to protect its users from unauthorized access and potential misuse of their accounts.

Read Original

A new zero-day vulnerability in Windows, dubbed 'LegacyHive', has been disclosed by a researcher known as Nightmare Eclipse. To mitigate the risk of immediate exploitation, the researcher has stripped the proof-of-concept exploit from public access. This vulnerability could potentially allow attackers to execute arbitrary code on affected systems, putting users and organizations at risk. Windows users and administrators should be particularly vigilant as they await further details and patches. The situation is evolving, and users are advised to stay updated on any security advisories related to this vulnerability.

Read Original
PreviousPage 2 of 7Next