product · 15 records
Windows

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A researcher has released a proof-of-concept tool named BigDiskBuster that prevents Microsoft Defender from updating by exhausting system disk space.

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Researchers discovered a new PowerShell-based malware campaign called TASK#STOMP that uses native Windows tools to harvest sensitive data and establish redundant persistence.

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw
Microsoft has patched several critical vulnerabilities across its products, including a maximum-severity flaw in Azure AI Foundry.

Google releases Chrome security update for actively exploited V8 vulnerability
Google has patched a high-severity V8 type confusion vulnerability in Chrome that is currently being exploited in the wild.

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft warns about the TerminalFix campaign using fake Cloudflare CAPTCHAs to execute malicious PowerShell scripts and install a reverse-tunnel backdoor.

Russian hackers distribute malware through compromised hotel Wi-Fi networks
A fake browser update distributed via hijacked hotel Wi-Fi networks delivers the CornFlake remote access trojan, an operation attributed to the Russian-linked Storm-2945 group.

Security researchers identify spear phishing attack targeting law firm
Security researchers at Blackpoint Cyber disclosed details of a spear-phishing campaign deploying the HollowFrame loader and Matryoshka backdoor against an unspecified law firm.

OpenWrt releases security patches to address critical DHCPv6 vulnerabilities
OpenWrt released version 24.10.8 and 25.12.5 to patch a critical DHCPv6 stack overflow flaw allowing arbitrary code execution as root, alongside other network service vulnerabilities.

Iranian hacking group deploys new malware against targets in South Asia
The Iranian state-backed hacking group Nimbus Manticore deployed the new NightLedger backdoor and tunneling tools against targets across the Middle East, Africa, and South Asia.

Hackers compromise hotel Wi-Fi to redirect users to fake login pages
Hackers hijack hotel Wi-Fi DNS settings to redirect users to fake Microsoft 365 login pages.

Chaos ransomware group uses msaRAT to route traffic through headless browsers
Researchers at Cisco Talos detailed msaRAT, a post-compromise Rust implant used by the Chaos ransomware group to route command-and-control traffic through headless Chrome and Edge browsers.

New exploit allows users to impersonate domain controllers in Active Directory
Researchers published an exploit for a vulnerability in Microsoft's Active Directory Certificate Services that enables low-privileged users to impersonate Domain Controllers.

China linked cybercrime group uses Cruciferra service to target Indian organizations
Security researchers have detected a China-linked cybercrime group and others using the Cruciferra crypter service to deploy malware via phishing campaigns targeting Indian and U.S. organizations.

Cybersecurity researchers identify malicious malware campaign targeting Middle East government entities
Cybersecurity researchers have identified a malicious campaign using TELESHIM, MIXEDKEY, and BINDCLOAK targeting government entities in the Middle East via Telegram C2.

ACROS Security releases unofficial patches for Windows LegacyHive zero-day vulnerability
Free unofficial micropatches have been released by ACROS Security for the Windows LegacyHive zero-day privilege escalation flaw after researcher Nightmare Eclipse disclosed it alongside a proof-of-concept exploit.