Topic: microsoft defender

  • Microsoft Races to Fix ‘RoguePlanet’ Zero-Day Flaw

    Microsoft Races to Fix ‘RoguePlanet’ Zero-Day Flaw

    Microsoft is developing a fix for a zero-day vulnerability called 'RoguePlanet' in its Defender antivirus, which uses a race condition to let attackers gain full System-level privileges. The public exploit requires no user interaction and allows complete system control, enabling malware installat...

    Read More »
  • Microsoft Defender RedSun Zero-Day Exploit Gains SYSTEM Access

    Microsoft Defender RedSun Zero-Day Exploit Gains SYSTEM Access

    A researcher named "Chaotic Eclipse" has released a second exploit, called RedSun, targeting Microsoft Defender to gain SYSTEM-level access on Windows, protesting Microsoft's security community engagement policies. The exploit works by corrupting a core Defender component, allowing an attacker to...

    Read More »
  • GhostTree Attack Used Windows Junctions to Stealthily Hide Malware

    GhostTree Attack Used Windows Junctions to Stealthily Hide Malware

    The GhostTree attack exploits recursive NTFS junctions to create an exponentially expanding number of legitimate Windows file paths, overwhelming Microsoft Defender's folder scans and causing them to time out or be abandoned. This technique allows malware to remain hidden in plain sight while the...

    Read More »
  • New Windows Zero-Day ‘RoguePlanet’ Exploit Goes Live

    New Windows Zero-Day ‘RoguePlanet’ Exploit Goes Live

    A newly disclosed Windows zero-day exploit called ‘RoguePlanet’ targets a race condition in Microsoft Defender, enabling local privilege escalation to SYSTEM-level access. The exploit allows an attacker with limited privileges to execute code with elevated permissions, bypassing security boundari...

    Read More »
  • Microsoft Nukes 200+ Fake Certificates in Teams Malware Attack

    Microsoft Nukes 200+ Fake Certificates in Teams Malware Attack

    Microsoft revoked over 200 fraudulent certificates used by cybercriminals to distribute malware via fake Microsoft Teams installation files, a campaign linked to the Vanilla Tempest group. The attackers employed SEO poisoning and malvertising to trick users into downloading malicious files, which...

    Read More »
  • New ClickFix Attack Uses nslookup to Steal Data via DNS

    New ClickFix Attack Uses nslookup to Steal Data via DNS

    Attackers have evolved ClickFix campaigns to weaponize DNS queries as a primary, stealthy delivery channel, tricking users into running a command that fetches and executes a malicious script from a rogue server. The attack chain involves a malicious nslookup command that retrieves a PowerShell sc...

    Read More »
  • Microsoft's New AI Security Agents Outsmart Hackers

    Microsoft's New AI Security Agents Outsmart Hackers

    Microsoft has launched advanced AI security agents that proactively identify and neutralize cyber threats, available at no extra cost for Security Copilot users on Microsoft 365 E5 plans. These AI agents are integrated into platforms like Defender, Entra, and Intune to shift security from reactiv...

    Read More »
  • DigiCert Breached After Malicious Screensaver File Used

    DigiCert Breached After Malicious Screensaver File Used

    A social engineering attack on DigiCert's customer support channel, using a malicious ZIP file disguised as a screenshot, allowed an attacker to access initialization codes and fraudulently issue EV Code Signing certificates. DigiCert revoked 60 certificates,27 directly linked to the attacker and...

    Read More »
  • Protect Your Windows 10 From Hackers With This One Step

    Protect Your Windows 10 From Hackers With This One Step

    Windows 10's official security support ended in October 2025, leaving systems without critical patches and creating a significant, growing vulnerability risk. Users can temporarily mitigate this risk by enrolling in a paid Extended Security Updates program or by relying on Microsoft Defender upda...

    Read More »
  • Microsoft Launches a Cybersecurity App Store

    Microsoft Launches a Cybersecurity App Store

    Microsoft has launched a Security Store, an online marketplace featuring security SaaS solutions and AI agents to support its Sentinel platform and corporate security strategy. The store offers cybersecurity tools from partners like Darktrace and Tanium, covering threat protection and identity ma...

    Read More »
  • 8 Ransomware Groups Now Using This EDR-Bypassing Tool

    8 Ransomware Groups Now Using This EDR-Bypassing Tool

    A new advanced tool is being used by multiple ransomware groups to bypass endpoint security by exploiting vulnerable drivers and disabling critical defenses before launching attacks. The tool employs heavy obfuscation and BYOVD attacks to target security products from major vendors, allowing rans...

    Read More »
  • Microsoft Teams Adds Feature to Report Suspicious Calls

    Microsoft Teams Adds Feature to Report Suspicious Calls

    Microsoft Teams is launching a "Report a Call" feature in mid-March to let users directly flag suspicious voice calls, providing organizations with visibility into phishing and scam attempts. The feature will be enabled by default and accessible from call history, with reported metadata sent to t...

    Read More »
  • Microsoft fixes critical Office zero-day under active attack

    Microsoft fixes critical Office zero-day under active attack

    Microsoft has urgently patched a critical, actively exploited zero-day vulnerability (CVE-2026-21509) in Office, which allows attackers to bypass security features by tricking users into opening malicious files. While patches are available for Office 2021, LTSC 2021/2024, and Microsoft 365, secur...

    Read More »
  • Unity Uncovers Major 2017 Security Flaw in Dev Tool

    Unity Uncovers Major 2017 Security Flaw in Dev Tool

    Unity has identified a significant security flaw in its development platform since 2017, allowing attackers to execute unauthorized code and steal data across Android, Windows, Linux, and macOS systems. The company has released comprehensive fixes for all affected Unity Editor versions and a bina...

    Read More »