FILTERING BY: CLEAR FILTER

Microsoft Windows 'Plug and Pwn': Hardware-Driven SYSTEM Privilege Escalation

Researchers Alejandro Hernando and Borja Martinez have identified a "Plug and Pwn" exploit chain targeting the Microsoft Windows Plug and Play (PnP) subsystem to achieve SYSTEM-level privileges on updated Windows 11 systems. The attack utilizes emulated USB device descriptors to trigger the installation of legitimate, signed third-party vendor software, which is then coerced into executing arbitrary code. This vulnerability extends beyond physical access via Remote Desktop Protocol (RDP) USB redirection, allowing for remote privilege escalation. The exploit effectively bypasses Driver Signature Enforcement (DSE) and Virtualization-Based Security (VBS) by leveraging the inherent trust placed in signed vendor binaries.

Lazarus Group Exploits Windows CVE-2026-68820 in 'Operation Dream Job' Campaign

The Lazarus Group is utilizing a Windows zero-day vulnerability, CVE-2026-68820, to target the global defense and aerospace sectors via "Operation Dream Job." Attackers deliver weaponized PDF files through sophisticated social engineering lures impersonating defense contractors like Lockheed Martin. The exploit triggers via modified PDF viewers, facilitating the deployment of a novel, stealthy backdoor for full system access and data exfiltration. CISA has issued an urgent mandate requiring federal agencies to patch this vulnerability within a two-week window due to the critical risk to national security infrastructure in the US, France, Germany, Brazil, and India.

Mirage Kitten Deploys NightLedger Backdoor and WebSocket Tunneling Tools

The Iranian state-sponsored actor Mirage Kitten (also tracked as Nimbus Manticore and UNC1549) is conducting a cyber-espionage campaign targeting organizations across the Middle East, Africa, and South Asia. The group utilizes a previously undocumented Windows backdoor named NightLedger to establish persistent access. To evade network security controls, the actor employs two custom WebSocket-based tunneling tools, ArcBridge and BridgeHead, which encapsulate C2 traffic to bypass traditional firewall restrictions and network detection systems.

Microsoft Windows LegacyHive ProfSvc Zero-Day LPE

The LegacyHive vulnerability is a critical Local Privilege Escalation (LPE) flaw within the Windows User Profile Service (ProfSvc) affecting fully patched Windows desktop and server environments. Disclosed by researcher Nightmare Eclipse shortly after the July 2026 Patch Tuesday, the exploit enables attackers with local access to bypass security controls by unauthorizedly loading and unloading other users' registry hives. This mechanism allows for the extraction of sensitive application data and Windows Explorer history, providing a direct path to escalate privileges to the administrative level.

Emergency Security Patching for Microsoft Windows Netlogon and Defender Zero-Days

Microsoft has released emergency security patches to address several critical vulnerabilities, most notably CVE-2026-41089, a Windows Netlogon Remote Code Execution (RCE) flaw currently under active exploitation. The threat, associated with the "BlueHammer" campaign, leverages this flaw to achieve total domain compromise through "domain-killing" mechanics. Additionally, at least three zero-day vulnerabilities in Microsoft Defender have been identified, compromising endpoint security integrity. These vulnerabilities affect the Windows kernel and core network services, providing attackers with high-privilege access and the ability to bypass standard security controls. Organizations must remediate these flaws before the June 2026 deadline to prevent widespread enterprise infiltration and potential loss of Active Directory integrity.

SmartApeSG Campaign Targets Windows Hosts via ClickFix Social Engineering

The SmartApeSG threat actor group is executing a high-severity social engineering campaign leveraging "ClickFix" scripts to compromise Windows environments. By deploying deceptive browser error messages, fake CAPTCHA prompts, and fraudulent verification pages, the actors manipulate users into executing malicious scripts through manual interaction. These scripts facilitate the deployment of diverse high-impact payloads, specifically Remcos RAT, NetSupport RAT, and the Stealc v2 information stealer. Successful infection provides attackers with persistent remote system control, capabilities for large-scale credential harvesting, and a critical foothold for lateral movement within enterprise networks.

FishMonger Espionage Group Porting SprySOCKS Backdoor to Windows

The China-aligned threat actor FishMonger has significantly expanded its operational reach by porting its SprySOCKS backdoor from Linux to Windows. This evolution introduces two specialized Windows-native variants: WIN_DRV, which utilizes a kernel-level rootkit for advanced activity concealment, and WIN_PLUS, which implements Windows-native persistence mechanisms. By leveraging kernel-mode drivers, the group aims to bypass traditional Endpoint Detection and Response (EDR) and Antivirus (AV) software. The malware employs hard-coded Command and Control (C2) configurations over TCP and UDP protocols, facilitating long-term, stealthy espionage and persistent access within targeted enterprise Windows infrastructures.


LINK COPIED TO CLIPBOARD