#Windows
40 stories taggedWindows · page 2 of 3.

North Korea's Lazarus Group Used a Secret Windows Flaw to Break Into Defence Companies
Hackers posing as recruiters sent fake job offers to aerospace and aviation workers in Europe and India, then used a previously unknown Windows vulnerability to seize full control of their computers.

Researcher publishes 'ShieldBreak' code that claims to defeat a recent Microsoft Defender fix
A proof-of-concept from a researcher known as Chaotic Eclipse says the patch for CVE-2026-50656 can still be bypassed to gain full control of Windows machines.

Some of the Bugs That Hid Inside Everyday Software for Decades
From a print-spooler flaw that Stuxnet quietly exploited to a 30-year-old graphics library hole, a handful of the most stubborn software vulnerabilities ever found show how long danger can lurk unnoticed.

Windows kernel bug already under attack as Microsoft ships nearly 400 fixes
A flaw in a core Windows networking component is being used in real attacks to hand attackers full control of a machine.

Microsoft's August Patch Tuesday: 400 fixes, three zero-days, and Lazarus back in the frame
Microsoft ships fixes for 400 flaws, including one AFD.sys hole North Korean hackers were already using to plant a kernel rootkit.

Passkeys Aren't Bulletproof: Three New Attacks Sidestep the 'Phishing-Proof' Login
Researchers show how signed login material, malware on synced devices, and clever redirection can defeat passkeys without cracking a single key.

Hackers Are Using a Legitimate Remote-Access Tool to Spy on Companies, and Your Antivirus Won't Notice
The Smoke#Screen campaign tricks employees into installing ScreenConnect, a genuine remote-support program, which then hands criminals full control of the victim's computer while looking completely normal to security software.

Microsoft Wants You to Patch in Three Days. Security Teams Say That's Not How It Works.
Microsoft is telling IT administrators to apply security fixes within 72 hours, citing AI tools that find and exploit software flaws faster than ever. Experts agree on the threat. They disagree, sharply, on whether three days is workable.

Windows 'LegacyHive' zero-day hands ordinary users admin power on fully patched PCs
A researcher published working attack code hours after Microsoft's July 2026 patches, and it still works. Microsoft has no fix yet, and no CVE has been assigned.

Malware Disguised as Font Files Targets Windows Users
A global phishing campaign active since March 2026 is hiding credential-stealing malware inside fake font files, and the evasion chain is getting harder to catch.

Splunk and Zoom Fix Security Flaws That Could Let Hackers Take Over Accounts
Both companies pushed out patches this week. One Zoom flaw scores a near-perfect danger rating and could let a criminal break into accounts without knowing a password.

Nightmare Eclipse Releases 'LegacyHive' Windows Zero-Day on Patch Tuesday
A prolific anonymous researcher drops another unpatched Windows flaw, this time one that lets ordinary users quietly read administrator account data.

Zoom patches critical Windows flaw that could hand attackers your account
A 9.8-severity bug in Zoom's Windows client lets remote attackers take over accounts with no login required.

OkoBot Malware Hijacks Ledger and Trezor Apps to Steal Crypto Recovery Phrases
A Windows malware framework active since April 2025 waits for victims to open their hardware wallet software, then fakes a prompt for the seed words that unlock everything.

A Hidden Door in Windows: How Attackers Can Blind Security Software to Malware
Bitdefender researchers have shown how a little-known Windows feature called bind links can be twisted to make malicious files invisible to the tools companies rely on to catch intrusions.