CuraSec

tag: Windows · 35 items

2026-08-25 · BleepingComputer · source ↗ #windows#dotnet#patch-tuesday
  • Engineer — Plan: If you run WPF-based applications, hold or test the August .NET Framework update before deploying; monitor Microsoft’s known-issue tracker for a fix or workaround before pushing to production.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-23 · BleepingComputer · source ↗ #windows#ipc-security#hardening
  • Engineer — Learn: Good conceptual reminder that named-pipe ACLs are an exploitable surface in Windows services, but no CVE, no KEV, and no exploitation signal means no immediate patching or configuration change is required — file this as design guidance for future Windows service work.
  • SOC/IR — Learn: Named-pipe abuse for lateral movement and C2 tunneling is already a documented ATT&CK technique (T1559.001); this article adds no new IOCs, campaigns, or detection angles beyond what existing Sigma rules and EDR behavioral detections already cover.
  • Leader — Skip
2026-08-21 · BleepingComputer · source ↗ #malware#ftp#windows
  • Engineer — Learn: Novel delivery technique hiding commands inside FTP server banners is worth understanding for FTP-exposed environments, but no KEV/PoC/EPSS signals exist to force immediate action — review whether any internal FTP services expose banners to untrusted clients.
  • SOC/IR — Plan: Two undocumented RATs with an unusual delivery vector warrant new detection logic; build rules to flag anomalous FTP banner content and hunt for E4del/PINHOLE behavioral patterns (process spawning from FTP client sessions) once IOCs are published.
  • Leader — Skip
2026-08-19 · BleepingComputer · source ↗ #windows#end-of-life#patch-management
  • Engineer — Plan: Audit endpoints for Windows 11 Home/Pro 24H2 and schedule upgrades to a supported build before the deadline; unpatched systems will stop receiving security updates, creating compounding exposure.
  • SOC/IR — Skip
  • Leader — Plan: Confirm whether any managed devices (dev machines, contractor endpoints) run Home/Pro 24H2 and ensure IT has an upgrade plan in place; unsupported devices become a compliance and vendor-attestation liability.
2026-08-19 · BleepingComputer · source ↗ #windows#rce#active-exploitation
  • Engineer — Act: CISA confirmed active exploitation of this critical Windows IKE RCE — patch all Windows systems running IPsec/VPN services immediately; treat as emergency patch given KEV-level signal from CISA warning.
  • SOC/IR — Act: Active exploitation confirmed by CISA — hunt for anomalous IKE/IPsec traffic and suspicious activity originating from VPN-adjacent or edge Windows systems since the campaign began; assume-breach sweep warranted for internet-exposed IKE endpoints.
  • Leader — Plan: Confirm with infrastructure teams that Windows IPsec/VPN systems are prioritized in the current patch cycle; active exploitation elevates this above routine cadence but it falls short of board-level disclosure unless a breach is discovered.
2026-08-18 · BleepingComputer · source ↗ #windows#ransomware#cisa-kev
  • Engineer — Act: CISA-confirmed active exploitation by ransomware operators means patch immediately — apply the Microsoft Windows Task Host security update to all Windows endpoints and servers; prioritize internet-facing and domain-joined systems.
  • SOC/IR — Act: Assume ransomware precursor activity may already be present — hunt for anomalous Task Host (taskhostw.exe) process behavior and lateral movement since April when exploitation was first flagged; tune EDR detections for suspicious task scheduler abuse.
  • Leader — Act: Ransomware exploitation of a CISA-flagged Windows flaw is a board-question-level event — confirm patching status with your engineering team this week and brief leadership on exposure and remediation timeline before an incident forces the conversation.
2026-08-14 · BleepingComputer · source ↗ #windows#zero-day#patch-management
  • Engineer — Plan: A Windows zero-day now has a patch, so apply the out-of-band update as soon as your change window allows; no KEV listing or public PoC signals suggest immediate active exploitation pressure, but the zero-day classification warrants prioritizing this above routine patches.
  • SOC/IR — Learn: The zero-day label is worth tracking in case exploitation evidence surfaces, but the item provides no IOCs, TTPs, or affected-behavior details to build or tune detections against right now.
  • Leader — Skip
2026-08-13 · BleepingComputer · source ↗ #windows#privilege-escalation#usb
  • Engineer — Plan: No active exploitation or PoC pressure yet, but physical-access USB attacks leading to SYSTEM are a real hardening target — audit Group Policy and MDM settings to restrict unsigned driver installation and limit who can install devices on managed endpoints.
  • SOC/IR — Learn: No IOCs or active campaign to hunt; worth understanding the PnP abuse technique to anticipate detection opportunities (e.g., monitoring for unexpected driver installs or PnP device events on sensitive hosts) if exploitation becomes active.
  • Leader — Skip
2026-08-13 · BleepingComputer · source ↗ #apt#windows#zero-day
  • Engineer — Act: CISA KEV-listed Windows zero-day with a public PoC now on GitHub — opportunistic exploitation beyond Lazarus is likely imminent. Apply the Microsoft patch for CVE-2026-68820 immediately and verify patch propagation across all Windows endpoints.
  • SOC/IR — Act: Lazarus Operation Dream Job campaign is actively exploiting this CVE; hunt for Dream Job spearphishing lures (fake job offer documents) and post-exploitation behaviors in Windows event logs and EDR telemetry since the campaign’s known activity window, and load current Lazarus IOCs into your SIEM for retroactive sweep.
  • Leader — Act: A nation-state (North Korea/Lazarus) is actively exploiting a KEV-listed Windows zero-day against defense-sector firms; if your organization is defense or defense-adjacent, brief leadership this week and confirm with IT that emergency patching is underway before the public PoC drives broader exploitation.
  • Signals: CVE-2026-68820 — CISA KEV: listed, EPSS 0.00, public PoC on GitHub, reported by 2 collected sources
2026-08-12 · BleepingComputer · source ↗ #windows#patch-tuesday#cumulative-update
  • Engineer — Plan: Schedule deployment of KB5121003 (25H2/24H2) and KB5120240 (23H2) through your standard Windows update pipeline; no KEV or PoC signals elevate this to emergency patching.
  • SOC/IR — Skip
  • Leader — Skip
2026-08-12 · BleepingComputer · source ↗ #windows#patch#end-of-life
  • Engineer — Plan: Windows 10 ESU patch KB5120249 is available for 22H2/21H2; if you still run Win10 endpoints, apply this update and accelerate migration to Windows 11 before ESU costs escalate.
  • SOC/IR — Skip
  • Leader — Plan: If your organization is on Windows 10 ESU, factor this recurring patch cost into budget planning and set a Windows 11 migration deadline to avoid ongoing ESU licensing exposure.
2026-08-12 · BleepingComputer · source ↗ #zero-day#privilege-escalation#windows
  • Engineer — Act: A public LPE exploit targeting Microsoft Defender—present on virtually every Windows endpoint—warrants immediate triage: verify whether August Patch Tuesday covered this CVE, and if not, apply any Microsoft-issued workaround and restrict local execution paths that the exploit chain requires.
  • SOC/IR — Plan: No active campaign IOCs or ATT&CK-mapped TTPs are reported yet, but a publicly available SYSTEM-privilege exploit via Defender will attract rapid weaponization; build and stage a detection for anomalous SYSTEM-level child processes spawning from Defender service components (e.g., MsMpEng.exe) before confirmed in-the-wild use.
  • Leader — Plan: A public unpatched exploit in Microsoft’s own security product is a credible board-question risk; direct the team to confirm patch status and monitor for an out-of-band release, and prepare a brief stakeholder statement in case exploitation at scale is confirmed.
  • Engineer — Act: Apply August 2026 Patch Tuesday updates now, prioritizing the one actively exploited vulnerability and the two publicly disclosed issues first, then triage the remaining 395 by severity and exposure surface.
  • SOC/IR — Plan: Once Microsoft releases specifics on the actively exploited CVE, build or tune detections for exploitation attempts; the two pre-patched public disclosures may already have known TTPs worth hunting against Windows endpoint telemetry.
  • Leader — Learn: A cycle of nearly 400 patches with confirmed in-the-wild exploitation is useful board-level context on Microsoft platform risk, but your engineering team owns the response — no leadership action required unless the exploited CVE turns out to be systemic.
2026-08-11 · The Hacker News · source ↗ #windows#privilege-escalation#rdp
  • Engineer — Plan: The RDP USB-redirection vector means physical access is not required, making this relevant to any enterprise RDP deployment on Windows 11. No patch or KEV yet, but audit Group Policy now to restrict or disable PnP/USB redirection over Remote Desktop where it isn’t operationally required.
  • SOC/IR — Plan: No IOCs or active exploitation are confirmed, but the technique produces detectable PnP driver installation events tied to RDP sessions; queue a detection rule for unexpected signed-driver installs initiated from RDP-redirected device paths as a hunting lead.
  • Leader — Learn: Research-stage local privilege escalation against fully patched Windows 11; no active exploitation or regulatory trigger yet — file for awareness and revisit if Microsoft issues a patch or exploitation reports emerge.
2026-08-04 · The Hacker News · source ↗ #passkeys#credential-theft#windows
  • Engineer — Learn: Unit 42’s three attack paths show that malware with ordinary user privileges can silently sign into passkey-protected accounts via Chrome’s Google Password Manager cloud authenticator, undermining the assumption that passkeys are malware-resistant. No patch is available; understand this changes the trust model for GPM-backed passkeys as a control and evaluate whether hardware-bound keys or platform authenticators offer stronger guarantees for high-value accounts.
  • SOC/IR — Plan: The three named techniques (Pass-ta-key variants) targeting Chrome’s credential store represent detectable post-exploitation behaviors; build detections around suspicious process access to Chrome’s local password/passkey storage and anomalous silent authentication events originating from endpoints, even without prior IOCs.
  • Leader — Learn: Research demonstrates that passkeys stored in Google Password Manager do not provide the malware-resistance often assumed in enterprise migration pitches; factor this into any planned passkey rollout strategy and update risk narratives shared with leadership or customers around phishing-resistant MFA claims.
2026-07-28 · BleepingComputer · source ↗ #active-directory#public-poc#windows
  • Engineer — Act: A public PoC now exists for a domain-hijack flaw in AD Certificate Services; audit your PKI templates for misconfigured enrollment permissions and apply any available patch or Microsoft-recommended mitigation immediately.
  • SOC/IR — Plan: Build detections for anomalous certificate enrollment requests and CA template abuse (e.g., unusual Enrollee Supplies Subject flag usage); no confirmed active exploitation reported yet, but PoC availability shortens the runway.
  • Leader — Learn: A PoC for a Windows domain-compromise vulnerability is now public; no board-level action needed yet, but monitor for escalation to active exploitation that could affect enterprise AD environments.
2026-07-24 · BleepingComputer · source ↗ #malware#windows#threat-actor
  • Engineer — Learn: No patch exists for this — it’s a social-engineering delivery using a legitimate app bundled with a malicious plugin for persistence. Worth understanding the plugin-directory persistence technique when hardening developer workstations.
  • SOC/IR — Plan: UAC-0099 is now deploying MatchBoil v2 and LunchPoke via fake Notepad++ archives; build or tune detections for unauthorized writes to Notepad++ plugin directories and hunt for these malware family names in EDR telemetry.
  • Leader — Skip
2026-07-24 · GitHub Trending · source ↗ #windows#hardening#knowledge-base
  • Engineer — Learn: A reference collection for Windows Server defensive hardening; worth bookmarking if you need structured guidance on configuration baselines, but no immediate action required.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-24 · The Hacker News · source ↗ #malware#threat-actor#windows
  • Engineer — Learn: Social engineering via trojanized software plugins is a recurring delivery vector; audit Notepad++ plugin directories on developer and admin workstations for unexpected DLLs, but no patch exists and no KEV or PoC signals elevate this to urgent action.
  • SOC/IR — Plan: UAC-0099 is an active Russia-aligned actor with evolving delivery chains; build or tune detections for anomalous files dropped into Notepad++ plugin directories and monitor for MATCHBOIL.V2 indicators once CERT-UA publishes full IOC sets.
  • Leader — Learn: Russia-aligned UAC-0099 campaign primarily flagged by CERT-UA; relevant context for organizations with Ukraine exposure or in sectors targeted by Russian threat actors, but no board-level event or vendor-breach action required.
2026-07-21 · BleepingComputer · source ↗ #windows#privilege-escalation#zero-day
  • Engineer — Plan: A privilege escalation zero-day on fully patched Windows with no official fix warrants tracking; evaluate applying the 0patch micropatch on critical or high-exposure Windows hosts while awaiting Microsoft’s official release, and audit privileged-access paths on Windows servers you own.
  • SOC/IR — Learn: No active exploitation, IOCs, or mapped TTPs are reported, so there is no immediate detection to write; note the vulnerability class for future hunt queries if exploitation evidence emerges.
  • Leader — Skip
2026-07-20 · BleepingComputer · source ↗ #windows#patch#dell
  • Engineer — Plan: If your estate includes Dell PCs running Windows 11 that received July 2026 updates, apply KB5121767 to resolve unexpected shutdowns; no security exploitation involved.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-20 · BleepingComputer · source ↗ #windows#patch-management#wsus
  • Engineer — Plan: If your patch pipeline depends on WSUS, validate that downstream clients are still receiving updates; consider a temporary alternative sync source or manual approval workflow until Microsoft resolves the issue.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-17 · BleepingComputer · source ↗ #windows#privilege-escalation#zero-day
  • Engineer — Plan: A public exploit for this Windows local privilege escalation zero-day exists with no patch available; monitor Microsoft advisories closely and apply the fix immediately on release, meanwhile audit privileged-access paths and restrict unnecessary local user capabilities as interim hardening.
  • SOC/IR — Plan: With a public exploit now circulating, build or tune detections for anomalous registry/hive access patterns leading to unexpected privilege escalation on Windows endpoints, and set a hunt for LPE activity on sensitive hosts since exploit release.
  • Leader — Learn: An unpatched Windows privilege escalation with a public exploit warrants watching; no confirmed widespread exploitation yet, but be ready to brief leadership if Microsoft delays patching or active campaigns emerge.
2026-07-16 · The Hacker News · source ↗ #zoom#windows#account-takeover
  • Engineer — Act: A public PoC on GitHub for a CVSS 9.8 improper-input-validation flaw in Zoom Desktop Client, VDI Client, and Meeting SDK for Windows raises exploitation risk significantly even without KEV listing; update all three Zoom Windows products to the patched versions immediately.
  • SOC/IR — Act: With a public PoC in circulation for a critical Zoom account-takeover vulnerability, exploitation attempts against unpatched Windows endpoints are plausible now; hunt for anomalous Zoom process behavior and unexpected authentication events since the patch cycle may lag exposure.
  • Leader — Plan: Zoom is near-universal in enterprise environments, and a CVSS 9.8 flaw with a public PoC in the Windows client warrants confirming with engineering that patching is tracked and on a days-not-weeks timeline before this surfaces in customer security questionnaires.
  • Signals: CVE-2026-53412 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
2026-07-16 · BleepingComputer · source ↗ #zoom#account-takeover#windows
  • Engineer — Plan: Zoom’s Windows desktop client and SDK carry a critical unauthenticated account-takeover flaw — high severity but no KEV listing or public PoC moves this to Plan rather than Act. Update Zoom Windows clients and any SDK integrations to the patched version as soon as your next patch window allows.
  • SOC/IR — Learn: No IOCs, active exploitation evidence, or mapped TTPs accompany this advisory, so there is no immediate detection or hunt work. File awareness of the attack vector (unauthenticated ATO on Zoom Windows) so detection rules can be prioritized if exploitation begins appearing in the wild.
  • Leader — Plan: Zoom is standard enterprise communication infrastructure, and a critical unauthenticated account-takeover flaw warrants confirming that endpoint and IT teams are deploying the patched client org-wide. Without reported exploitation this does not require leadership escalation yet, but track it for the next risk review.
2026-07-16 · HN (vulnerability) · source ↗ #bitlocker#windows#disk-encryption
  • Engineer — Plan: A public GitHub tool for bypassing BitLocker is now available, representing a concrete threat to Windows disk-encryption posture; audit your BitLocker configurations (TPM-only vs PIN/network unlock) and track whether a CVE and patch follow from Microsoft.
  • SOC/IR — Learn: No IOCs, TTPs, or active exploitation evidence are provided; monitor for threat actor adoption of this bypass technique, but insufficient detail here to build or tune detections yet.
  • Leader — Plan: A public BitLocker bypass tool could undermine encryption-at-rest compliance claims under PCI DSS, HIPAA, or SOC 2; ask your endpoint team this quarter to assess which device configurations are affected and whether audit narratives need updating.
2026-07-16 · BleepingComputer · source ↗ #windows#end-of-support#patch-lifecycle
  • Engineer — Plan: Inventory endpoints and servers running Windows 11 24H2 Home/Pro or Windows 10 Enterprise LTSB 2016 and schedule in-place upgrades before the 90-day deadline; unpatched systems post-EOS become unmitigated CVE targets.
  • SOC/IR — Skip
  • Leader — Plan: Confirm that asset inventory and upgrade plans exist for affected OS versions before deadline; running unsupported Windows in an audited environment (SOC 2, ISO 27001) creates a documented compliance gap that auditors and customers will flag.
2026-07-15 · BleepingComputer · source ↗ #windows#patch-tuesday#microsoft
  • Engineer — Plan: Schedule deployment of KB5101650/KB5099414 through your standard patch pipeline; 570+ fixes is a large surface but no KEV or PoC signals elevate this to emergency patching.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-15 · BleepingComputer · source ↗ #windows#patch-tuesday#esu
  • Engineer — Plan: Windows 10 is in ESU territory; if you still run Win10 endpoints or golden images, deploy KB5099539 to stay covered under the extended support contract — schedule within your normal patch window.
  • SOC/IR — Skip
  • Leader — Plan: If your organization is paying for Windows 10 ESU, confirm KB5099539 is being deployed; if not, this is a prompt to assess Win10 fleet size and budget for ESU licensing or migration costs before end-of-extended-support.
2026-07-15 · BleepingComputer · source ↗ #windows#patch-management#dell
  • Engineer — Plan: If you manage Dell endpoints running Windows 11, verify whether the update block applies to your hardware models and plan an alternate patching path once Microsoft lifts the safeguard hold.
  • SOC/IR — Skip
  • Leader — Skip
2026-07-15 · The Hacker News · source ↗ #malware#rat#windows
  • Engineer — Learn: New Rust-based RAT using NVIDIA software impersonation is worth understanding for software allowlisting and process integrity controls, but no exploitation signals (no KEV, PoC, or EPSS) warrant immediate action.
  • SOC/IR — Plan: Build detections targeting processes or binaries impersonating NVIDIA software — unusual parent/child process chains, unsigned executables in NVIDIA paths, or Rust binary fingerprints — to catch this foothold technique before it gains adoption.
  • Leader — Skip
2026-07-13 · HN (security) · source ↗ #bitlocker#windows#encryption
  • Engineer — Plan: BitLocker underpins disk encryption across most enterprise Windows fleets; if the released exploit is validated, audit any system where BitLocker is the sole data-protection control and evaluate layering additional encryption. Monitor Microsoft’s official response before treating this as confirmed.
  • SOC/IR — Learn: A credible BitLocker bypass would change IR assumptions about the confidentiality of encrypted drives seized or imaged during investigations, but the item provides no IOCs or detectable TTPs to act on now — track for technical follow-up.
  • Leader — Plan: If substantiated, a deliberate backdoor in BitLocker would materially weaken encryption-based controls cited in SOC 2 / ISO audits and customer data-protection attestations; prepare a Microsoft vendor inquiry and brief your risk committee on potential impact before this surfaces in the news cycle.
  • Engineer — Learn: No patch or PoC details are provided in this item, but the episode highlights the risks of coordinated vs. full disclosure and how platform policy can affect access to exploit research; no immediate action required on running systems.
  • SOC/IR — Skip
  • Leader — Learn: This dispute surfaces tension between Microsoft’s disclosure policy and independent researchers, relevant context for vendor risk assessments and your own organization’s vulnerability disclosure policy posture.
2026-07-11 · CrowdStrike Blog · source ↗ #clickonce#initial-access#windows
  • Engineer — Learn: Part 1 is foundational research on how ClickOnce deployment can be weaponized as an initial-access vector; no patch or config action today, but engineers supporting Windows app delivery should understand the attack surface before Part 2 drops with exploitation specifics.
  • SOC/IR — Learn: Builds triage context for ClickOnce-based delivery chains; hold detection engineering work until Part 2, which is expected to cover observable behaviors and threat-actor abuse patterns.
  • Leader — Skip
2026-07-11 · CrowdStrike Blog · source ↗ #windows#persistence#ttp
  • Engineer — Learn: Describes how attackers abuse the ClickOnce deployment mechanism for persistence in Windows environments — no patch or config change indicated, but worth understanding if you deploy .NET apps or manage Windows estates.
  • SOC/IR — Plan: New ClickOnce-based persistence TTP with public CrowdStrike analysis — build or tune detections around ClickOnce application installations and associated scheduled tasks or registry run keys in your SIEM/EDR.
  • Leader — Skip