Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control ...
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into ...
Attackers chain two PaperCut NG and MF flaws for unauthenticated remote code execution, with limited exploitation seen in two ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
SOCRadar details E4del and PINHOLE RAT campaigns using FTP banners as dead drop resolvers to fetch commands and C2 details.
Kerberos unconstrained delegation is one of those Active Directory configurations that can sit quietly for years and still create a disproportionate amount of risk. It is often introduced to make a ...
Kimsuky uses phishing and a malicious Chrome extension to steal Gmail messages, attachments, and control infected computers.
Rogue remote-support clients spread malware across Windows systems, using social engineering and trusted tools to expand ...
Hackers are exploiting FTP server banners to infect Windows systems with new malware. The campaign has been ongoing since ...
Cybersecurity researchers have uncovered a feature-rich malware strain called Shadow hVNC that gives attackers control of a hidden Windows ...
Upgrade unsupported PCs to Windows 11 version 26H2 with a powerful paid app that unlocks Microsoft's system requirements.