[local] Windows Defender (MsMpEng.exe) - Race Condition
Windows Defender (MsMpEng.
20 articles
Windows Defender (MsMpEng.
It's Time to Upgrade Your SMB Session This week, Metasploit contributor Dean Welch has added an SMB to Meterpreter session upgrade module. It uses PsExec to ...
A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebA...
Microsoft has brought forward its timelines for transitioning to post-quantum cryptography (PQC)
ReliaQuest report warns of a surge in ClickFix social engineering attacks against Windows and macOS users
JFrog found an npm package impersonating postcss-selector-parser to drop a multi-stage Windows RAT
North Korean threat actor Sapphire Sleet has been linked to a supply chain attack targeting Mastra, according to Microsoft security researchers
Azure AD Graph Activity Logs land in Elastic with full ECS parsing. Detect ROADrecon and AADInternals enumeration with ready-to-use detection rules.
What if your AI coding assistant could be tricked into stealing your own company's secrets - by reading a single booby-trapped bug report? No phishing email.
China-linked SprySOCKS backdoor gains stealthy Windows variants and 30-plus C2 commands
Command and control traffic exploited a Teams visitor token to make malicious activity look legitimate to defenders
ESET researchers have discovered SprySOCKS for Windows, FishMonger’s backdoor weaponizing a kernel driver for advanced stealthiness
A phishing kit subverting Microsoft’s legitimate authentication flow lets attackers break into accounts without stealing passwords or creating fake login pages
Microsoft has patched 200 vulnerabilities including three zero-days
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of f...
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to...
Microsoft Detection and Response Team (DART) details how it has uncovered malicious AI applications as cyber criminals manipulate organizations adopting AI t...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Edge. User interaction is required to exploit thi...
This vulnerability allows remote attackers to execute arbitrary cross-origin script on affected installations of Microsoft Edge. User interaction is required...
This vulnerability allows remote attackers to access restricted functionality on affected installations of Microsoft Edge. User interaction is required to ex...