Windows

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files 2026-09-21 at 17:00 By Mirko Zorz Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi […]

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files Read More »

DeepZero: Open-source hunting for vulnerable Windows drivers

DeepZero: Open-source hunting for vulnerable Windows drivers 2026-09-16 at 08:30 By Mirko Zorz DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether […]

DeepZero: Open-source hunting for vulnerable Windows drivers Read More »

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days 2026-09-12 at 14:10 By Ionut Arghire Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days Read More »

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor 2026-09-09 at 12:04 By Zeljka Zorz September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days. Another “new normal” is the anonymous security researcher Nightmare Eclipse publishing […]

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor Read More »

Microsoft’s Project Zenith puts large AI models directly on developer PCs

Microsoft’s Project Zenith puts large AI models directly on developer PCs 2026-09-08 at 07:30 By Anamarija Pogorelec Microsoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without relying on metered cloud tokens. Designed for systems with at least 64 GB […]

Microsoft’s Project Zenith puts large AI models directly on developer PCs Read More »

September 2026 Patch Tuesday forecast: All we need is more time

September 2026 Patch Tuesday forecast: All we need is more time 2026-09-04 at 09:00 By Help Net Security The Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was the second biggest in history with 398 resolved CVEs: […]

September 2026 Patch Tuesday forecast: All we need is more time Read More »

Windows memory integrity switches on automatically for eligible devices in October 2026

Windows memory integrity switches on automatically for eligible devices in October 2026 2026-09-03 at 07:30 By Anamarija Pogorelec Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too. Memory […]

Windows memory integrity switches on automatically for eligible devices in October 2026 Read More »

Windows 11’s strongest security defenses can be bypassed without a screwdriver

Windows 11’s strongest security defenses can be bypassed without a screwdriver 2026-08-17 at 08:30 By Sinisa Markovic Researchers from the University of Birmingham and Durham University have found a way to knock down some of the toughest protections in Windows 11 without physically opening or modifying the target machine. The attack assumes the attacker has […]

Windows 11’s strongest security defenses can be bypassed without a screwdriver Read More »

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks 2026-08-12 at 11:45 By Ionut Arghire The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor. The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fresh Windows Zero-Day Exploited in North Korean Cyberattacks Read More »

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? 2026-08-07 at 09:00 By Help Net Security July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs […]

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? Read More »

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove 2026-08-05 at 11:43 By Zeljka Zorz A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it difficult to uninstall it. Different traps for Mac and Windows users By […]

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove Read More »

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) 2026-07-27 at 15:04 By Zeljka Zorz Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS […]

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) Read More »

Microsoft tightens Windows enterprise activation security

Microsoft tightens Windows enterprise activation security 2026-07-24 at 12:52 By Anamarija Pogorelec Microsoft is making Trusted Platform Module (TPM)-backed attestation a requirement for Windows Key Management Service (KMS), the on-premises service used for Windows volume activation, replacing the software-only trust model with hardware-backed verification to strengthen enterprise activation security. Attestation will become mandatory with the […]

Microsoft tightens Windows enterprise activation security Read More »

The Windows 10 hangover is becoming a security problem

The Windows 10 hangover is becoming a security problem 2026-07-20 at 11:37 By Anamarija Pogorelec Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered […]

The Windows 10 hangover is becoming a security problem Read More »

Microsoft makes Windows SSO prompts easier to manage

Microsoft makes Windows SSO prompts easier to manage 2026-07-16 at 11:47 By Anamarija Pogorelec Microsoft is introducing a new registry-based policy that lets IT administrators automatically accept Windows SSO permissions on Windows 11 versions 24H2 and 25H2 devices managed with Microsoft Entra ID. Users with personal Microsoft accounts and devices outside policy-managed environments will continue […]

Microsoft makes Windows SSO prompts easier to manage Read More »

Windows Bind Link Attacks Can Hide Malware From EDR Tools

Windows Bind Link Attacks Can Hide Malware From EDR Tools 2026-07-15 at 16:00 By Kevin Townsend Bitdefender researchers show how Windows bind links can create conflicting filesystem views to hide malware from endpoint security products. The post Windows Bind Link Attacks Can Hide Malware From EDR Tools appeared first on SecurityWeek. This article is an […]

Windows Bind Link Attacks Can Hide Malware From EDR Tools Read More »

Microsoft demystifies how Windows updates work

Microsoft demystifies how Windows updates work 2026-07-13 at 08:30 By Anamarija Pogorelec Microsoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the mechanisms used to deliver new features throughout the year. “Most individuals and organizations regularly deploy monthly security updates, released […]

Microsoft demystifies how Windows updates work Read More »

Microsoft is rewriting Windows patch guidance because of AI

Microsoft is rewriting Windows patch guidance because of AI 2026-07-10 at 09:00 By Anamarija Pogorelec Microsoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess how quickly they […]

Microsoft is rewriting Windows patch guidance because of AI Read More »

20 open-source cybersecurity tools to keep your team ready for anything

20 open-source cybersecurity tools to keep your team ready for anything 2026-07-08 at 08:30 By Anamarija Pogorelec AI is changing how security teams find vulnerabilities, analyze code, test applications, and protect infrastructure. Developers are building tools to secure AI systems themselves, from coding agents and memory protection to model exposure discovery. This roundup covers recent […]

20 open-source cybersecurity tools to keep your team ready for anything Read More »

Microsoft wants to keep your AI agents from going rogue

Microsoft wants to keep your AI agents from going rogue 2026-07-07 at 07:45 By Anamarija Pogorelec Microsoft has introduced Microsoft Execution Containers (MXC), a cross-platform, policy-driven execution layer for AI agents on Windows and Windows Subsystem for Linux (WSL), now available in early preview. Updated Agent 365 platform (Source: Microsoft) Developers can define constraints for […]

Microsoft wants to keep your AI agents from going rogue Read More »

Scroll to Top