-
Iran-linked threat actors associated with MuddyWater are using a newly tracked Windows backdoor dubbed Dindoor that hijacks the legitimate Deno runtime to execute malicious JavaScript and TypeScript payloads. The campaign demonstrates how trusted devel…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors behind ClearFake campaigns are using a newly identified loader, WordlistLoader, to deliver the Amatera Stealer to Windows systems. The loader disguises executable shellcode as sequences of ordinary English words, helping malware evade sta…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft is currently investigating a compatibility issue with Windows 11, in which certain games crash, freeze, or cause unexpected system restarts on devices equipped with RGB lighting hardware and related low-level drivers. This problem was reporte…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researcher Jiří Vinopal has published a detailed analysis of BTR.sys, the Microsoft Defender Boot-Time Removal driver. His research reveals how this legitimate, Microsoft-signed component can be exploited to perform file and registry operation…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft Defender has been aborting Quick, Full, and Offline virus scans on Windows systems following a series of Security Intelligence updates released on August 18, 2026. This issue has affected both consumer devices and Microsoft Defender for Endpo…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft has issued a 60-day reminder that the Windows 11 version 24H2 Home and Pro editions will reach the end of updates on October 13, 2026. This date also marks the end of servicing for Windows 10 Enterprise LTSB 2016. As a result, both organizati…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
HoneyMyte, the China-aligned espionage group also tracked as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode rootkit that can conceal malware artifacts and command-and-control infrastructure from security tools. Th…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A targeted cryptocurrency intrusion has exposed how Google-hosted Apps Script pages can be weaponized to profile prospective victims before delivering signed Windows malware. The campaign used a fake Web3 recruitment process to deploy a three-payload s…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A compact, custom-built Windows backdoor that impersonates Realtek software, persists through WMI, and conceals its command-and-control address inside what appears to be an almost empty desktop.ini file. At just 12,288 bytes, the x64 implant was observ…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Security researchers have introduced a new technique called “Bring Your Own EDR” (BYOEDR) that exploits legitimate SentinelOne components to bypass Windows Protected Process Light (PPL) protections, allowing the execution of unsigned code within highly…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


