threat-intel And the Winner in Dominant Malware Delivery? ClickFix ClickFix, a social engineering technique where attackers trick users into executing malicious commands via error messages, has become the dominant method for malware delivery, according to a recent ReliaQuest analysis. T… Dark Reading · Jul 1, 2026 High USsocial engineeringmalware deliveryobfuscation
threat-intel Introduction to COM usage by Windows threats This Cisco Talos report details the increasing use of the Component Object Model (COM) by malware actors for malicious activities within Windows environments. COM's capabilities for inter-process communication, automatio… Cisco Talos · Jun 25, 2026 Medium comwindowslateral movement
malware Malicious npm Packages Pose as PostCSS Tools to Deliver Windows RAT A series of malicious npm packages, disguised as PostCSS tools, have been discovered delivering a Windows-based remote access trojan (RAT). These packages, published by 'abdrizak', leveraged legitimate build tooling to d… The Hacker News · Jun 23, 2026 High USnpmsupply-chainrat
threat-intel China-Linked SprySOCKS Backdoor Expands to Windows with Driver-Based Stealth Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and W… The Hacker News · Jun 16, 2026 High CVE-2023-24932CNTWHUbackdoorwindowsstealth
threat-intel FishMonger’s arsenal upgraded: SprySOCKS for Windows ESET researchers have discovered two new, undocumented Windows variants of FishMonger's SprySOCKS backdoor, operated by the Chinese threat actor I-SOON (believed to be part of the Winnti Group). These variants, WIN_DRV a… WeLiveSecurity · Jun 16, 2026 High CHHOTAwindowsbackdoorkernel driver
threat-intel Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet A disgruntled researcher known as Nightmare-Eclipse has released another proof-of-concept (PoC) exploit, dubbed RoguePlanet, targeting a Windows Defender vulnerability. This follows a series of similar disclosures aimed… Dark Reading · Jun 10, 2026 High CVE-2026-33825USzero-dayexploitwindows
threat-intel Microsoft: Some Windows PCs fail to install latest monthly updates Microsoft has identified an issue causing some Windows 11 devices upgraded to 24H2 or 25H2 to fail to install the latest monthly updates. The problem manifests as 0x80073712 or 0x800f0993 errors, linked to corrupted XSX… BleepingComputer · Jun 10, 2026 Medium windowsupdateserror
other Hands on with Intelligent Terminal, an AI-powered Windows Terminal Microsoft has released Intelligent Terminal, an open-source extension for Windows Terminal that integrates AI assistance directly into the terminal environment. The tool leverages various AI models, such as GitHub Copilo… BleepingComputer · Jun 7, 2026 Low aiwindowsterminal
threat-intel Microsoft's Coreutils project brings Linux commands to Windows Microsoft has released Coreutils for Windows, a project bringing commonly used Linux command-line utilities to Windows as native applications. Based on the uutils open-source project, this aims to simplify development wo… BleepingComputer · Jun 2, 2026 Low linuxwindowscommand-line
threat-intel Critical Windows Netlogon RCE flaw now exploited in attacks A critical Remote Code Execution (RCE) vulnerability (CVE-2026-41089) in Windows Netlogon is now being actively exploited in attacks, according to Belgium's national cybersecurity authority, the Centre for Cybersecurity… BleepingComputer · Jun 1, 2026 Critical CVE-2026-41089CVE-2026-45585CVE-2026-33825BErcenetlogonwindows
malware Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th) This report details the discovery of a fake Claude webpage distributing the ACR Stealer malware, targeting macOS and Windows users. The initial infection vector involves malicious ads leading to the deceptive site, which… SANS Internet Storm Center · May 26, 2026 High USstealermacoswindows
threat-intel Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective This article details a technique for evaluating the exploitability of Windows kernel mode drivers, focusing on the potential for BYOVD (Bring Your Own Vulnerability Driver) attacks. It highlights how vulnerabilities in d… The Hacker News · May 22, 2026 Medium USdriverbyovdkernel mode
threat-intel Chinese hackers target telcos with new Linux, Windows malware A Chinese cyber-espionage group, known as Calypso (Red Lamassu), has been targeting telecommunications providers globally since mid-2022 with a dual-pronged malware campaign utilizing Showboat (Linux) and JMFBackdoor (Wi… BleepingComputer · May 21, 2026 High CHMIASlinuxwindowsespionage
vulnerability Microsoft warns of new Defender zero-days exploited in attacks Microsoft has released security patches for two zero-day vulnerabilities, CVE-2026-41091 (RedSun) and CVE-2026-45498 (UnDefend), that are being actively exploited in attacks. These flaws, affecting Microsoft Defender and… BleepingComputer · May 21, 2026 High CVE-2026-41091CVE-2026-45498USzero-dayprivilege escalationdefender
threat-intel Exploits and vulnerabilities in Q1 2026 This Securelist report analyzes vulnerability trends and exploitation activity during Q1 2026, focusing on the expansion of exploit kits targeting Microsoft Office, Windows, and Linux operating systems. The report highli… Securelist · May 7, 2026 High CVE-2018-0802CVE-2017-11882CVE-2017-0199USvulnerabilityexploitationrce
vulnerability Welcome to the new Project Zero Blog Project Zero has revived older research to highlight the ongoing need for zero-day defenses. The blog post focuses on past exploitation techniques, specifically a 2016 article detailing race conditions in Windows path lo… Google Project Zero · Dec 16, 2025 Medium vulnerabilitywindowsexploitation