windows

  1. Man

    Zero-Day on Windows: Microsoft releases emergency update

    Security updates affect Windows 10, 11 and server versions. Microsoft has released updates for a number of Windows products, eliminating the CVE-2024-43629 vulnerability identified by a specialist from the Positive Technologies Security Expert Center. The updates cover Windows 10, Windows 11...
  2. Man

    VBS Bypass: A Hacker Cracked Windows' Last Line of Defense

    The bundle of functions requires special configuration to prevent an update rollback attack. SafeBreach specialist Alon Leviev found that attackers can use outdated components of the Windows kernel to bypass key protections, such as Driver Signature Enforcement, which allows rootkits to be...
  3. Man

    A bug in CLFS turns ordinary Windows users into administrators

    Kernel protection turned out to be powerless against the new PoC exploit. A critical vulnerability in the Common Log File System (CLFS) driver has been discovered in the Windows 11 operating system, which allows local users to escalate their privileges. CLFS is responsible for efficiently...
  4. Man

    WinReg: Switching from SMB Gives Opportunities to Hack Windows

    How a backup protocol has become a major security threat. Akamai has discovered a vulnerability in the MS-RPC client that could allow an NTLM Relay attack. RPC is an important element of Windows, supporting a variety of services. Despite the security measures in place, some components remain...
  5. Man

    EDRSilencer: Built-in Windows Tool Disables EDR Solutions

    Hackers have learned how to "blind" protection systems with just one tool. Trend Micro found that in a number of attacks, attackers used the EDRSilencer tool to disable EDR system alerts. Cybercriminals integrate the tool into their attacks to hide the traces of attacks and evade detection...
  6. Man

    CoreWarrior: A Trojan Horse on Steroids in the Windows World

    The elusive virus changes its appearance over 600 times per hour. SonicWall specialists have discovered new activity of CoreWarrior malware, a persistent Trojan that spreads at high speed. The virus creates dozens of copies of itself and connects to multiple IP addresses, creating access...
  7. Man

    PrintNightmare is back: a hacker was able to bypass Windows protection

    A new round in the confrontation between attackers and Microsoft. A recently published guide to the PrintNightmare group of vulnerabilities has sparked discussions about how to bypass the Point and Print (PnP) restrictions proposed in the article. The author decided not just to update the post...
  8. Friend

    One-click VPN: Windows Defender on public Wi-Fi

    Microsoft is expanding Defender options to all platforms. Microsoft has introduced updated Defender features to help protect users when connecting to public Wi-Fi networks. Defender VPN has been added to Defender to protect your data from eavesdropping. Defender now automatically detects...
  9. Friend

    A bundle of exploits allows you to bypass UAC and gain admin rights in Windows

    Experts warn of a vulnerability in Windows that allows bypassing User Account Control (UAC) and escalating privileges in the system to the SYSTEM level. The issue, which is being tracked under the identifier CVE-2024-6769, received a CVSS score of 6.7. A demo exploit is currently available...
  10. Friend

    How to enable ransomware protection in Windows

    Simple steps to protect files from ransomware. Ransomware-type malware is a serious threat. It encrypts files on the computer, blocking access to them until the victim pays the demanded ransom. Files become hostages, and if it is not possible to cope with the attack by other methods, the user...
  11. Friend

    ESET fixes vulnerabilities in Windows and macOS products

    The problems affected both home and corporate solutions. ESET has fixed two privilege escalation vulnerabilities in its products for Windows and macOS operating systems. These vulnerabilities allowed attackers to gain unauthorized access to system resources. The first vulnerability, with the...
  12. Friend

    Click-to-Virus Hacks: Hackers Hack Windows via CAPTCHA

    The robot test has become a nightmare for users. Information security experts warn of a new fraudulent scheme: attackers have begun to use fake CAPTCHA tests to install malware on Windows computers. This is a signal that users should pay more attention to protecting their data and be careful...
  13. Friend

    CVE-2024-38217: Why could 0day not be detected in Windows for 6 years?

    Elastic Security Labs has revealed the details of the "LNK Stomping" attack. As part of its recent Patch Tuesday update, which we have already published a separate article about, Microsoft has fixed a zero-day vulnerability in the Windows Smart App Control and SmartScreen functions, which has...
  14. Friend

    50 servers and full system management: KTLVdoor backdoor attacks Windows and Linux systems

    A poorly studied malware leaves no chance for specialists to study. Trend Micro specialists have discovered a new multi-platform backdoor KTLVdoor from the Chinese group Earth Lusca. KTLVdoor is developed in Golang and has versions for Windows and Linux. The previously unknown malware is...
  15. Friend

    CVE-2024-30051: A new attack vector on Windows via DirectComposition

    One wrong step and the system comes under the full control of intruders. Chinese security researchers recently discovered real-world attacks exploiting the CVE-2024-30051 vulnerability (CVSS scale score: 7.8), which was used in cyberattacks related to QakBot, a known banking Trojan. The...
  16. Friend

    Windows Killer: CVE-2024-38106 Gives Hackers Direct Access to System Kernel

    The dangerous Zero-day was used long before the patch appeared. On September 2, security researcher Sergey Kornienko of PixiePoint published an analysis and demonstration of the exploitation of a critical zero-day vulnerability in the Windows kernel known as CVE-2024-38106. This privilege...
  17. Friend

    Mekotio Trojan: Another Nightmare for Windows Users

    Why is your antivirus powerless against a new Trojan? CYFIRMA has discovered a new malicious program called Mekotio Trojan, which is actively distributed among users around the world. This sophisticated Trojan uses PowerShell technology to infiltrate computers and steal sensitive information...
  18. Friend

    Kaspersky found a Trojan running on macOS, which until now existed only for Windows

    Researchers from Kaspersky Lab report the discovery of a macOS version of the HZ Rat backdoor targeting users of the Chinese applications DingTalk and WeChat. At the same time, the observed artifacts almost exactly repeat the functionality of the Windows version of the backdoor and differ only...
  19. Friend

    Windows Downdate: New Tool Reverses All Windows Updates

    Alon Leviev created a tool to return old vulnerabilities to the system. Alon Leviev, a specialist from SafeBreach, has released the Windows Downdate tool, which allows you to return old vulnerabilities on updated Windows 10, Windows 11, and Windows Server systems. A downgrade attack allows...
  20. Friend

    Windows helped hackers hack into the industrial giant of the Russian Federation

    How one account led to the collapse of the IT infrastructure. A group of pro-Ukrainian cybercriminals successfully attacked the IT infrastructure of a Russian industrial organization, exploiting a vulnerability in the Windows operating system. The vulnerability, known since 2022, is related to...
Top