Security News

HelloXD Ransomware Installing Backdoor on Targeted Windows and Linux Systems
2022-06-13 05:37

Windows and Linux systems are being targeted by a ransomware variant called HelloXD, with the infections also involving the deployment of a backdoor to facilitate persistent remote access to infected hosts. "Unlike other ransomware groups, this ransomware family doesn't have an active leak site; instead it prefers to direct the impacted victim to negotiations through Tox chat and onion-based messenger instances," Daniel Bunce and Doel Santos, security researchers from Palo Alto Networks Unit 42, said in a new write-up.

Microsoft starts rolling out Windows 11 File Explorer tabs
2022-06-09 21:43

Microsoft is finally rolling out the new File Explorer tabbed interface with the release of Windows 11 Insider Preview Build 25136 to the Dev Channel. "To help you work across multiple locations at the same time, the title bar of File Explorer now has tabs. We'd love your feedback on which tabs features you'd like to see next," the Windows Insider team said.

New Notepad, Media Player updates out for Windows 11 Insiders
2022-06-09 18:09

Microsoft has announced that the Windows 11 Notepad and Media Player applications are getting new updates for Windows Insiders. Microsoft started rolling out the new and completely redesigned Notepad for Windows 11 to all Windows Insiders in the Dev Channel in December.

Microsoft Defender now isolates hacked, unmanaged Windows devices
2022-06-09 16:35

Microsoft has announced a new feature for Microsoft Defender for Endpoint to help organizations prevent attackers and malware from using compromised unmanaged devices to move laterally through the network.There's a catch: the new MDE capability works only with onboarded devices running Windows 10 and later or Windows Server 2019 and later.

Now Windows Follina zero-day exploited to infect PCs with Qbot
2022-06-09 00:29

Miscreants are reportedly exploiting the recently disclosed critical Windows Follina zero-day flaw to infect PCs with Qbot, thus aggressively expanding their reach. Threat Insight, part of cybersecurity vendor Proofpoint, noted on Twitter this week that miscreants have been seen exploiting the Follina flaw, tracked as CVE-2022-30190, in the Windows Support Diagnostic Tool to deliver Qbot, also known as QakBot, QuakBot and Pinkslipbot, onto victims' computers.

Researchers Warn of Unpatched "DogWalk" Microsoft Windows Vulnerability
2022-06-08 22:26

An unofficial security patch has been made available for a new Windows zero-day vulnerability in the Microsoft Support Diagnostic Tool, even as the Follina flaw continues to be exploited in the wild. The issue - referenced as DogWalk - relates to a path traversal flaw that can be exploited to stash a malicious executable file to the Windows Startup folder when a potential target opens a specially crafted ".

Qbot malware now uses Windows MSDT zero-day in phishing attacks
2022-06-07 22:03

A critical Windows zero-day vulnerability, known as Follina and still waiting for an official fix from Microsoft, is now being actively exploited in ongoing phishing attacks to infect recipients with Qbot malware. As Proofpoint security researchers shared today, the TA570 Qbot affiliate has now begun using malicious Microsoft Office.

Windows 11 22H2 closer to release, lands in the Release channel
2022-06-07 17:59

Microsoft has moved Windows 11, version 22H2, to the Windows Insider Release channel, indicating that it is in its final round of testing before it's likely released this fall. Last month, we reported that Windows 11 22H2 build 22621 was the Released to Manufacturing build, which is the product's final build before its release to OEMs and other partners for installation in new devices.

New ‘DogWalk’ Windows zero-day bug gets free unofficial patches
2022-06-07 16:59

Free unofficial patches for a new Windows zero-day vulnerability in the Microsoft Support Diagnostic Tool have been released today through the 0patch platform. Diagcab files are downloaded from the Internet and include a Mark-of-the-Web, Windows ignores it for this file type and allows the file to be opened without a warning.

Two-year-old Windows DIAGCAB zero-day gets unofficial patches
2022-06-07 16:59

Free unofficial patches for a new Windows zero-day vulnerability in the Microsoft Support Diagnostic Tool have been released today through the 0patch platform. Diagcab files are downloaded from the Internet and include a Mark-of-the-Web, Windows ignores it for this file type and allows the file to be opened without a warning.