Security News

Miscreants exploit five Microsoft bugs as Windows giant addresses 130 flaws
2023-07-11 23:26

Patch Tuesday Microsoft today addressed 130 CVE-listed vulnerabilities in its products - and five of those bugs have already been exploited in the wild. A full list of security updates and advisories in this month's Patch Tuesday batch can be found here from the IT giant, or here from the ZDI. In summary, there are fixes for Windows, Office,.

What's new in the Windows 11 22H2 Moment 3 update, now available
2023-07-11 21:08

Microsoft has begun the forced rollout of its Windows 11 22H2 'Moment 3' update, which introduces several new features and improvements to the operating system. In contrast to the two major feature updates that Windows 10 receives annually, Windows 11 will only receive one update yearly.

Cisco Talos Reports Microsoft Windows Policy Loophole Being Exploited by Threat Actor
2023-07-11 19:09

Learn how a malicious driver exploits a loophole in the Windows operating system to run at kernel level. Cisco Talos discovered a new Microsoft Windows policy loophole that allows a threat actor to sign malicious kernel-mode drivers executed by the operating system.

Windows 11 KB5028185 cumulative update released with Moment 3 features
2023-07-11 18:10

Microsoft has released the mandatory Windows 11 22H2 KB5028185 cumulative update to fix security vulnerabilities, enable the new Moment 3 features, and make over 30 improvements. KB5028185 is a mandatory Windows 11 cumulative update containing the July 2023 Patch Tuesday security updates that fix 78 vulnerabilities and thirty-eight remote code execution flaws in various Microsoft products.

Windows 10 KB5028168 and KB5028166 updates released
2023-07-11 18:07

Microsoft has released Windows 10 KB5028166 and KB5028168 cumulative updates for versions 22H2, version 21H2, and 1809 to fix problems and add new features to the operating system. As these updates contain security updates released as part of the July 2023 Patch Tuesday, Microsoft will automatically install the update over the next couple of days.

Hackers exploit Windows policy to load malicious kernel drivers
2023-07-11 17:00

Microsoft blocked code signing certificates predominantly used by Chinese hackers and developers to sign and load malicious kernel mode drivers on breached systems by exploiting a Windows policy loophole. With Windows Vista, Microsoft introduced policy changes restricting how Windows kernel-mode drivers could be loaded into the operating system, requiring developers to submit their drivers for review and sign them through Microsoft's developer portal.

Hackers Exploit Windows Policy Loophole to Forge Kernel-Mode Driver Signatures
2023-07-11 16:59

A Microsoft Windows policy loophole has been observed being exploited primarily by native Chinese-speaking threat actors to forge signatures on kernel-mode drivers. "Actors are leveraging multiple open-source tools that alter the signing date of kernel mode drivers to load malicious and unverified drivers signed with expired certificates," Cisco Talos said in an exhaustive two-part report shared with The Hacker News.

Beware of Big Head Ransomware: Spreading Through Fake Windows Updates
2023-07-11 08:45

A developing piece of ransomware called Big Head is being distributed as part of a malvertising campaign that takes the form of bogus Microsoft Windows updates and Word installers. Big Head was first documented by Fortinet FortiGuard Labs last month, when it discovered multiple variants of the ransomware that are designed to encrypt files on victims' machines in exchange for a cryptocurrency payment.

Amazon's AppStore is getting more apps and games on Windows 11
2023-07-10 19:46

In collaboration with Microsoft, Amazon has announced the general availability of its AppStore on Windows 11 for all developers. This means more apps and games are coming to Windows 11 as Amazon developers can now easily access the AppStore for Windows and bring their Amazon Store apps to Microsoft's platform.

Microsoft: Windows 11 21H2 reaching end of service in October
2023-07-10 18:52

Microsoft warned customers today that multiple editions of Windows 11, version 21H2, will reach the end-of-service in three months, on October 10, 2023. Windows 11 22H2 has entered widespread availability for Windows devices meeting the eligibility criteria since October.