-
The financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications….
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A recently released proof-of-concept, named FalconFlank, claims to reveal a local privilege escalation vulnerability in the CrowdStrike Falcon Sensor on Windows. CrowdStrike is actively investigating these claims and has advised customers to turn off t…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A malicious ScreenConnect campaign in which rogue remote-access clients do more than provide attackers with hands-on control: modified clients can automatically push a multi-stage VBScript malware chain to newly connected Windows endpoints. Once deploy…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted ke…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Anthropic has enhanced Claude’s desktop automation capabilities, enabling the AI assistant to operate directly on macOS and Windows computers through Claude Cowork and Claude Code. When this feature is enabled, Claude can navigate a visible scree…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An active malware campaign that abuses counterfeit download pages for trusted software brands including Microsoft Edge, Kaspersky and Razer to compromise Windows devices. Victims span healthcare, manufacturing, gaming, technology, logistics, government…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybersecurity firm Morphisec has uncovered a new Windows infostealer called RevStealer, which is being distributed through a fake…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This vulnerability allows a local user to control a privileged component. The code was published by a GitHub use…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TerminalFix uses fake Cloudflare CAPTCHA pages to trick users into running PowerShell malware, creating reverse tunnels that provide access to internal systems.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft has confirmed an issue with Microsoft Defender Antivirus that generates false notifications on Windows systems, claiming “Microsoft Defender Antivirus is turned off,” even though the protection is still operational. These alerts m…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


