Tag

#Windows

40 stories taggedWindows.

Illustration: a darkened office workstation
Vulnerabilities

A researcher keeps dropping Windows Defender zero-days, and Microsoft is losing patience

Abdelhamid Naceri's latest proof-of-concept, BigDiskBuster, stops Microsoft's built-in antivirus from updating. It is the eleventh unpatched flaw he has posted this year in a public feud with Redmond.

4 min read
Illustration: a dark workshop desk with a single unlit Windows laptop screen glowing pale blue
Threat Intelligence

Malware Lets Four AI Models Vote on What to Steal Next

Cisco Talos found a Windows sample that hands its decisions to a small panel of AI models. The lab copy does not run, but the idea is the story.

4 min read
A Windows Update completion screen showing 974 security patches installed, with active exploit alerts visible in background security center notifications
Vulnerabilities

Microsoft's Biggest-Ever Security Update Fixes 974 Flaws, Two Already Used in Attacks

A record-breaking September patch release plugs two security holes that criminals were actively exploiting, plus 20 vulnerabilities serious enough that a single infected machine could spread the attack to others automatically.

3 min read
A Windows update installation screen showing a progress bar at completion, with security patch notification badges and version numbers visible in the background
Vulnerabilities

Nearly 1,000 Windows Fixes in One Month: Two Zero-Days Already Being Exploited

Microsoft's September 2026 Patch Tuesday lands 964 security fixes, two of them already in active use by criminals, plus roughly 20 bugs that could spread automatically across networks.

4 min read
A smartphone screen displaying the Telegram messaging app interface, with surveillance camera icons and technical monitoring overlays visible in the background,
Threat Intelligence

Iran's Spy Malware Runs on Telegram, Western Agencies Warn

US, UK and Dutch cyber agencies say Iranian intelligence uses a Windows tool controlled through Telegram to watch dissidents and activists abroad.

3 min read
A Windows system command prompt displaying privilege escalation exploit code executing, CrowdStrike Falcon Sensor components visible in the process list, the Of
Vulnerabilities

Researcher publishes FalconFlank zero-day targeting CrowdStrike Falcon Sensor

A privilege escalation flaw abuses Falcon's own Office macro cleanup routine to hand attackers SYSTEM-level access on Windows machines.

3 min read
A Windows Defender notification panel displayed prominently with false 'Antivirus is Off' warning, background showing actual active protection running, confusio
Vulnerabilities

Microsoft: Ignore the 'Antivirus Is Off' Warnings in Defender, It's a False Alarm

A bad notification, not a broken product. Microsoft says Defender is running normally despite pop-ups claiming otherwise, and a fix is on the way.

3 min read
A Windows desktop showing a print dialog box frozen or displaying an error state, with application windows in the background showing failed operations
Vulnerabilities

Microsoft's August .NET patch broke printing in Windows apps. Here's what to do.

A security fix shipped this month is causing crashes when Windows Presentation Foundation apps try to print or export to PDF using common fonts like Calibri.

4 min read
A computer terminal showing Windows system processes and network connections in a technical monitoring interface, with code visible in adjacent windows
Vulnerabilities

Windows Named Pipes: The Hidden Back Channel Attackers Keep Prying Open

A quiet feature that lets Windows programs talk to each other becomes a privilege-escalation problem when developers skip the access checks.

4 min read
A computer booting up with system files and registry entries visible in technical monitoring software, with security software components displayed on screen
Vulnerabilities

Microsoft's Own Antivirus Driver Can Be Turned Into a Weapon at Boot

Check Point researchers show how BTR.sys, the trusted cleanup tool inside Microsoft Defender, can be steered to wipe files and registry keys before Windows even finishes starting.

4 min read
An FTP server welcome screen with disguised command instructions hidden within greeting text, with malicious payloads downloading to a Windows system in the bac
Threat Intelligence

Hackers Hide Malware Instructions in FTP Server Greetings

A quiet trick spotted by SOCRadar uses FTP welcome messages to smuggle commands onto Windows machines, dropping two new remote-control tools called E4del and PINHOLE.

3 min read
A software repository package listing showing nearly identical library names with subtle misspellings, with one package highlighted as malicious and credential-
Threat Intelligence

Malicious RubyGems Packages Impersonate Popular Libraries to Steal Windows Credentials

Researchers flagged seven typosquatted gems on August 15, 2026, part of a wider campaign delivering a Windows information stealer.

3 min read
A Windows desktop with Chrome browser window open, and a developer tools panel glowing with active debugging information in the lower portion of the screen
Threat Intelligence

Researchers Show How Attackers Can Hijack Live Chrome and Edge Sessions on Windows

A post-exploitation trick flips on Chrome's built-in debugger inside a running browser, handing attackers cookies and logged-in sessions without touching the password vault.

3 min read
A Windows system registry editor window displayed on a monitor, with kernel-level entries highlighted in red, while a map in the background shows target regions
Threat Intelligence

Chinese Hacking Group Hides Backdoor Behind a Signed Windows Rootkit

Kaspersky researchers say the Mustang Panda crew paired an updated CoolClient backdoor with a kernel-level cloaking tool, striking targets in Myanmar and Pakistan.

4 min read
A corporate IT dashboard on multiple monitors showing enterprise device management software interface with highlighted security warning indicators and system co
Vulnerabilities

$58 Certificate, Four Flaws: Researchers Show How SCCM Can Hand Attackers the Keys to an Entire Company

A security research team chained four weaknesses in Microsoft's enterprise device-management software to reach full system control, starting with nothing more than a standard company login.

5 min read
© 2026 Threat Vectr