Security News

Qbot malware now uses Windows MSDT zero-day in phishing attacks
2022-06-07 22:03

A critical Windows zero-day vulnerability, known as Follina and still waiting for an official fix from Microsoft, is now being actively exploited in ongoing phishing attacks to infect recipients with Qbot malware. As Proofpoint security researchers shared today, the TA570 Qbot affiliate has now begun using malicious Microsoft Office.

Windows 11 22H2 closer to release, lands in the Release channel
2022-06-07 17:59

Microsoft has moved Windows 11, version 22H2, to the Windows Insider Release channel, indicating that it is in its final round of testing before it's likely released this fall. Last month, we reported that Windows 11 22H2 build 22621 was the Released to Manufacturing build, which is the product's final build before its release to OEMs and other partners for installation in new devices.

New ‘DogWalk’ Windows zero-day bug gets free unofficial patches
2022-06-07 16:59

Free unofficial patches for a new Windows zero-day vulnerability in the Microsoft Support Diagnostic Tool have been released today through the 0patch platform. Diagcab files are downloaded from the Internet and include a Mark-of-the-Web, Windows ignores it for this file type and allows the file to be opened without a warning.

Two-year-old Windows DIAGCAB zero-day gets unofficial patches
2022-06-07 16:59

Free unofficial patches for a new Windows zero-day vulnerability in the Microsoft Support Diagnostic Tool have been released today through the 0patch platform. Diagcab files are downloaded from the Internet and include a Mark-of-the-Web, Windows ignores it for this file type and allows the file to be opened without a warning.

Windows zero-day exploited in US local govt phishing attacks
2022-06-06 16:09

European governments and US local governments were the targets of a phishing campaign using malicious Rich Text Format documents designed to exploit a critical Windows zero-day vulnerability known as Follina. BleepingComputer is aware of local governments in at least two US states that were targeted by this phishing campaign.

Microsoft: Windows Autopatch now available for public preview
2022-06-05 14:00

Microsoft said this week that Windows Autopatch, a service to automatically keep Windows and Microsoft 365 software up to date in enterprise environments, has now reached public preview.Windows Autopatch automatically manages the deployment of Windows 10 and Windows 11 quality and feature updates, drivers, firmware, and Microsoft 365 Apps for enterprise updates.

Windows 11 'Restore Apps' feature will make it easier to set up new PCs
2022-06-04 17:53

Microsoft is working on a new 'Restore Apps' feature for Windows 11 that will allow users to quickly reinstall all of their previously installed apps from the Microsoft Store on a new or freshly installed PC. One of the most time-consuming tasks for setting up a new Windows installation is restoring all your previously installed applications. While desktop applications will still need to be installed manually, the new Windows 11 feature will allow you to install all the Microsoft Store apps tied to your account by clicking a single button.

Windows 10 KB5014023 update fixes slow copying, app crashes
2022-06-02 21:50

Microsoft has released optional cumulative update previews for Windows 10 versions 20H2, 21H1, and 21H2, fixing slow file copying and applications crashing due to Direct3D issues. Today's KB5014023 update is part of Microsoft's scheduled May 2022 monthly "C" updates which allow Windows customers to test bug fixes and performance improvements before the general release on June 15 during Patch Tuesday.

Yet another zero-day (sort of) in Windows “search URL” handling
2022-06-02 19:39

The Follina bug, now more properly known as CVE-2022-30190, hinges on a weird, non-standard URL supported by the Windows operating system. Windows includes a lengthy list of proprietary URL schemes, also known as protocol handlers, that can be used to trigger a range of non-standard activities simply by referencing the special URL. The Follina bug, for example, took devious advantage of the URL scheme ms-msdt:, which relates to system diagnostics.

New Windows Search zero-day added to Microsoft protocol nightmare
2022-06-01 22:06

A new Windows Search zero-day vulnerability can be used to automatically open a search window containing remotely-hosted malware executables simply by launching a Word document. While most Windows searches will look on the local device's index, it is also possible to force Windows Search to query file shares on remote hosts and use a custom title for the search window.