CuraSec

tag: Endpoint · 3 items

2026-09-02 · BleepingComputer · source ↗ #remote-access#phishing#endpoint
  • Engineer — Learn: No CVE or patch involved — attackers are abusing a legitimate admin tool’s functionality. Review whether Faronics Deploy is in your environment and whether its deployment permissions are appropriately scoped.
  • SOC/IR — Act: Hunt for unexpected ScreenConnect installations originating from Faronics Deploy processes; build detections for remote-management tool deployments not initiated by IT change management workflows.
  • Leader — Skip
2026-08-19 · BleepingComputer · source ↗ #windows-defender#patch#endpoint
  • Engineer — Plan: If Windows Defender crashes were affecting endpoint coverage in your environment, apply the follow-on fix via Windows Update to restore stable antivirus operation.
  • SOC/IR — Plan: Verify that EDR/Defender telemetry gaps didn’t occur during the crash window; confirm detection coverage was restored after the fix is applied.
  • Leader — Skip
2026-07-19 · BleepingComputer · source ↗ #infostealer#credential-theft#endpoint
  • Engineer — Learn: ACR Stealer targets browser-stored credentials and tokens — review whether your CI/CD pipelines or developer workstations enforce short-lived tokens and MFA to limit blast radius if credentials are harvested.
  • SOC/IR — Act: Microsoft is actively observing this campaign; hunt for ACR Stealer IOCs across EDR telemetry and SIEM, and tune detections for credential-access behaviors (browser credential dumping, token theft) across enterprise endpoints.
  • Leader — Plan: A confirmed surge targeting enterprise customers elevates infostealer risk on your risk register; consider briefing on phishing-resistant MFA adoption and reviewing credential hygiene posture this quarter.