<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Endpoint on CuraSec</title><link>https://curasec.metacog.co.kr/tags/endpoint/</link><description>Recent content in Endpoint on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/endpoint/index.xml" rel="self" type="application/rss+xml"/><item><title>Hackers abuse Faronics Deploy to silently install ScreenConnect RAT</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-hackers-abuse-faronics-deploy-admin-tool-to-install-screenco/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-hackers-abuse-faronics-deploy-admin-tool-to-install-screenco/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No CVE or patch involved — attackers are abusing a legitimate admin tool&amp;rsquo;s functionality. Review whether Faronics Deploy is in your environment and whether its deployment permissions are appropriately scoped.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Hunt for unexpected ScreenConnect installations originating from Faronics Deploy processes; build detections for remote-management tool deployments not initiated by IT change management workflows.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Microsoft fixes Windows Defender crash bug from recent update</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-microsoft-fixes-known-issue-causing-windows-defender-crashes/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-microsoft-fixes-known-issue-causing-windows-defender-crashes/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If Windows Defender crashes were affecting endpoint coverage in your environment, apply the follow-on fix via Windows Update to restore stable antivirus operation.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Verify that EDR/Defender telemetry gaps didn&amp;rsquo;t occur during the crash window; confirm detection coverage was restored after the fix is applied.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Microsoft warns of surge in ACR Stealer attacks on customers</title><link>https://curasec.metacog.co.kr/insights/2026-07-19-microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/</link><pubDate>Sun, 19 Jul 2026 12:05:51 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-19-microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> ACR Stealer targets browser-stored credentials and tokens — review whether your CI/CD pipelines or developer workstations enforce short-lived tokens and MFA to limit blast radius if credentials are harvested.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Microsoft is actively observing this campaign; hunt for ACR Stealer IOCs across EDR telemetry and SIEM, and tune detections for credential-access behaviors (browser credential dumping, token theft) across enterprise endpoints.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A confirmed surge targeting enterprise customers elevates infostealer risk on your risk register; consider briefing on phishing-resistant MFA adoption and reviewing credential hygiene posture this quarter.&lt;/li>
&lt;/ul></description></item></channel></rss>