#Windows
40 stories taggedWindows.

A researcher keeps dropping Windows Defender zero-days, and Microsoft is losing patience
Abdelhamid Naceri's latest proof-of-concept, BigDiskBuster, stops Microsoft's built-in antivirus from updating. It is the eleventh unpatched flaw he has posted this year in a public feud with Redmond.

Malware Lets Four AI Models Vote on What to Steal Next
Cisco Talos found a Windows sample that hands its decisions to a small panel of AI models. The lab copy does not run, but the idea is the story.

Microsoft's Biggest-Ever Security Update Fixes 974 Flaws, Two Already Used in Attacks
A record-breaking September patch release plugs two security holes that criminals were actively exploiting, plus 20 vulnerabilities serious enough that a single infected machine could spread the attack to others automatically.

Nearly 1,000 Windows Fixes in One Month: Two Zero-Days Already Being Exploited
Microsoft's September 2026 Patch Tuesday lands 964 security fixes, two of them already in active use by criminals, plus roughly 20 bugs that could spread automatically across networks.

Iran's Spy Malware Runs on Telegram, Western Agencies Warn
US, UK and Dutch cyber agencies say Iranian intelligence uses a Windows tool controlled through Telegram to watch dissidents and activists abroad.

Researcher publishes FalconFlank zero-day targeting CrowdStrike Falcon Sensor
A privilege escalation flaw abuses Falcon's own Office macro cleanup routine to hand attackers SYSTEM-level access on Windows machines.

Microsoft: Ignore the 'Antivirus Is Off' Warnings in Defender, It's a False Alarm
A bad notification, not a broken product. Microsoft says Defender is running normally despite pop-ups claiming otherwise, and a fix is on the way.

Microsoft's August .NET patch broke printing in Windows apps. Here's what to do.
A security fix shipped this month is causing crashes when Windows Presentation Foundation apps try to print or export to PDF using common fonts like Calibri.

Windows Named Pipes: The Hidden Back Channel Attackers Keep Prying Open
A quiet feature that lets Windows programs talk to each other becomes a privilege-escalation problem when developers skip the access checks.

Microsoft's Own Antivirus Driver Can Be Turned Into a Weapon at Boot
Check Point researchers show how BTR.sys, the trusted cleanup tool inside Microsoft Defender, can be steered to wipe files and registry keys before Windows even finishes starting.

Hackers Hide Malware Instructions in FTP Server Greetings
A quiet trick spotted by SOCRadar uses FTP welcome messages to smuggle commands onto Windows machines, dropping two new remote-control tools called E4del and PINHOLE.

Malicious RubyGems Packages Impersonate Popular Libraries to Steal Windows Credentials
Researchers flagged seven typosquatted gems on August 15, 2026, part of a wider campaign delivering a Windows information stealer.

Researchers Show How Attackers Can Hijack Live Chrome and Edge Sessions on Windows
A post-exploitation trick flips on Chrome's built-in debugger inside a running browser, handing attackers cookies and logged-in sessions without touching the password vault.

Chinese Hacking Group Hides Backdoor Behind a Signed Windows Rootkit
Kaspersky researchers say the Mustang Panda crew paired an updated CoolClient backdoor with a kernel-level cloaking tool, striking targets in Myanmar and Pakistan.

$58 Certificate, Four Flaws: Researchers Show How SCCM Can Hand Attackers the Keys to an Entire Company
A security research team chained four weaknesses in Microsoft's enterprise device-management software to reach full system control, starting with nothing more than a standard company login.