27 Jan Microsoft fixes Windows 11 issue behind Remote Desktop freezes Microsoft has addressed a known issue causing Remote Desktop app freezes on Windows 11 systems after installing the Windows 11 2022 Update. […]
27 Jan PlugX malware hides on USB devices to infect new Windows hosts Security researchers have analyzed a variant of the PlugX malware that can hide malicious files on removable USB devices and then infect the Windows hosts they connect to. […]
26 Jan Microsoft starts force upgrading Windows 11 21H2 devices Microsoft has started the forced rollout of Windows 11 22H2 to systems running Windows 11 21H2 that are approaching their end-of-support (EOS) date on October 10, 2023. […]
26 Jan Windows 11 KB5022360 preview update released with 15 improvements Microsoft has released the Windows 11 22H2 KB5022360 preview cumulative update with fifteen fixes or improvements. […]
26 Jan Microsoft urges admins to patch on-premises Exchange servers Microsoft urged customers today to keep their on-premises Exchange servers patched by applying the latest supported Cumulative Update (CU) to have them always ready to deploy an emergency security update. […]
26 Jan Bitwarden password vaults targeted in Google ads phishing attack Bitwarden and other password managers are being targeted in Google ads phishing campaigns to steal users’ password vault credentials. […]
26 Jan US offers $10M bounty for Hive ransomware links to foreign governments The U.S. Department of State today offered up to $10 million for information that could help link the Hive ransomware group (or other threat actors) with foreign governments. […]
26 Jan New Mimic ransomware abuses ‘Everything’ Windows search tool A new ransomware family named ‘Mimic’ has been spotted in the wild abusing the APIs of a legitimate Windows file search tool called ‘Everything’ to achieve file enumeration. […]
25 Jan Exploit released for critical Windows CryptoAPI spoofing bug Proof of concept exploit code has been released by Akamai researchers for a critical Windows CryptoAPI vulnerability discovered by the NSA and U.K.’s NCSC allowing MD5-collision certificate spoofing. […]
25 Jan CISA: Federal agencies hacked using legitimate remote desktop tools CISA, the NSA, and MS-ISAC warned today in a joint advisory that attackers are increasingly using legitimate remote monitoring and management (RMM) software for malicious purposes. […]