Tagged: Microsoft Defender
Attackers can force Microsoft Defender to delete its own security components using a native Windows driver. This technique affects systems from Windows 7 through Windows 11 25H2. It requires neither a software vulnerability exploit...
A Microsoft Defender vulnerability patched just one month ago appears to be exploitable once again. A researcher operating under the alias MSNightmare has published ShieldBreak – a new proof-of-concept that claims to bypass Microsoft’s...
A browser search bar often looks safe. A bad Chrome extension, though, can turn it into a data trap before any results even show up. Microsoft recently found an extension called “Search for perplexity...
The Chinese cyber-espionage collective Dragon Breath, also recognized by the designation APT-Q-27, has purportedly acquired a formidable new instrument for infiltrating corporate infrastructures. According to a report by Ransom-ISAC, investigators identified a vulnerable driver,...
A novel method to acquire total systemic hegemony over Windows has surfaced, and remarkably, it eschews complex kernel vulnerabilities in favor of exploiting the erratic behavior of the integrated antivirus suite. A researcher operating...
In the waning days of February 2026, cyber adversaries inaugurated a nascent campaign characterized by an unorthodox stratagem: the dissemination of malignant Windows artifacts via the ubiquitous channels of WhatsApp. The calculus was elegantly...
Artificial intelligence extensions have seamlessly woven themselves into the fabric of everyday browser utility. Multitudes of users routinely summon the sidebar, interrogating chatbots and injecting proprietary corporate documents or intricate code snippets into the...
An electronic missive imploring the recipient to “sign a document” or “authenticate an account” may not invariably lead to a fabricated domain, but rather to an entirely legitimate Microsoft or Google address. It is...
The Microsoft Defender threat intelligence team has documented a series of substantiated offensives targeting internet-facing SolarWinds Web Help Desk instances. Adversaries weaponized these vulnerable help desk servers as a primary point of ingress, subsequently...
Microsoft has disclosed a sophisticated sequence of multi-stage incursions leveraging Adversary-in-the-Middle (AiTM) session hijacking in tandem with Business Email Compromise (BEC) methodologies. The offensive specifically targeted entities within the energy sector, with adversaries weaponizing...
Cyber-espionage attributed to the Chinese group HoneyMyte—also known as Mustang Panda and Bronze President—has reached a new level. Researchers have observed the deployment of an advanced version of the ToneShell malware, concealed by a...
A new commodity has surfaced on underground forums for those seeking to operate more quietly—and for longer. An actor using the alias AlphaGhoul has begun promoting a utility called NtKiller, which, according to its...