Visualização de leitura

BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations

A newly documented Windows attack pattern, dubbed Bring Your Own Trusted Caller (BYOTC), shows how attackers can bypass driver-level authorization controls without exploiting a traditional memory-corruption flaw. Instead of attacking a privileged kernel driver directly, an adversary compromises or abuses the legitimate user-mode application that the driver already trusts. The technique expands on the well-known […]

The post BYOTC Attack Abuses Trusted Windows Clients to Access Privileged Kernel Driver Operations appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded its custom malware arsenal with two Windows backdoors that abuse HiveMQ’s public MQTT infrastructure and the Matrix-based Element messaging ecosystem for command-and-control communications. The development marks a notable evolution for the group, which previously leaned on publicly available tools and leaked ransomware builders before introducing its […]

The post Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks

Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted kernel-mode code and drivers can run on supported systems. Memory Integrity is a security feature built on Virtualization-based Security (VBS), a Windows […]

The post Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Defender Bug Triggers False “Antivirus Turned Off” Alerts on Windows

Microsoft has confirmed an issue with Microsoft Defender Antivirus that generates false notifications on Windows systems, claiming “Microsoft Defender Antivirus is turned off,” even though the protection is still operational. These alerts may appear after installing the latest Defender updates, potentially causing unnecessary concern for administrators who observe that Defender settings are healthy and security […]

The post Microsoft Defender Bug Triggers False “Antivirus Turned Off” Alerts on Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems

Iran-linked threat actors associated with MuddyWater are using a newly tracked Windows backdoor dubbed Dindoor that hijacks the legitimate Deno runtime to execute malicious JavaScript and TypeScript payloads. The campaign demonstrates how trusted developer tooling can be turned into an effective execution layer for malware while reducing the value of file-signature and hash-based detection. The […]

The post Iran-Linked Hackers Abuse Legitimate Deno Runtime to Hide Dindoor Backdoor on Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows 11 Update Triggers Game Crashes on Systems With RGB Lighting Drivers

Microsoft is currently investigating a compatibility issue with Windows 11, in which certain games crash, freeze, or cause unexpected system restarts on devices equipped with RGB lighting hardware and related low-level drivers. This problem was reported following the release of Windows updates on August 11, 2026, including the KB5121003 update for OS Build 26100.9168. Microsoft […]

The post Windows 11 Update Triggers Game Crashes on Systems With RGB Lighting Drivers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows 11 24H2 Home and Pro Support Ends in October 2026

Microsoft has issued a 60-day reminder that the Windows 11 version 24H2 Home and Pro editions will reach the end of updates on October 13, 2026. This date also marks the end of servicing for Windows 10 Enterprise LTSB 2016. As a result, both organizations and individual users must plan their upgrade or migration activities […]

The post Windows 11 24H2 Home and Pro Support Ends in October 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections

HoneyMyte, the China-aligned espionage group also tracked as Mustang Panda, has upgraded its CoolClient backdoor with a signed Windows kernel-mode rootkit that can conceal malware artifacts and command-and-control infrastructure from security tools. The development marks a notable escalation in the group’s post-compromise tradecraft, moving protection and evasion below the user-mode layer where many endpoint inspection […]

The post HoneyMyte Upgrades CoolClient With Windows Kernel Rootkit to Hide Malware and C2 Connections appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Malicious Google Apps Script Profiles Crypto Victims Before Delivering Signed Windows Malware

A targeted cryptocurrency intrusion has exposed how Google-hosted Apps Script pages can be weaponized to profile prospective victims before delivering signed Windows malware. The campaign used a fake Web3 recruitment process to deploy a three-payload stack: NeedleStealer, an unclassified Rust infostealer, and a custom Go RAT with hidden VNC capabilities. A fake recruiter initiated contact […]

The post Malicious Google Apps Script Profiles Crypto Victims Before Delivering Signed Windows Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

12 KB Backdoor Masquerades as Realtek Software and Hides C2 in Windows Whitespace

A compact, custom-built Windows backdoor that impersonates Realtek software, persists through WMI, and conceals its command-and-control address inside what appears to be an almost empty desktop.ini file. At just 12,288 bytes, the x64 implant was observed on a single domain-joined Windows 7 SP1 workstation, a low-prevalence footprint that researchers assess may indicate selective targeting rather […]

The post 12 KB Backdoor Masquerades as Realtek Software and Hides C2 in Windows Whitespace appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPL

Security researchers have introduced a new technique called “Bring Your Own EDR” (BYOEDR) that exploits legitimate SentinelOne components to bypass Windows Protected Process Light (PPL) protections, allowing the execution of unsigned code within highly secured processes. This research, presented by Akamai at DEF CON 34, demonstrates how trusted endpoint detection and response (EDR) software can […]

The post New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse to Bypass Windows PPL appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Armored Likho Turns Windows Microphones Into Automated Eavesdropping Devices

Armored Likho, also tracked as Eagle Werewolf, has expanded its espionage capability with a Rust-based toolkit that can hijack Telegram sessions and transform compromised Windows endpoints into automated audio-surveillance devices. The newly documented May 2026 campaign primarily targets Russian private individuals, corporations, government bodies, IT organizations, and educational institutions through a fraudulent donation-service application. The […]

The post Armored Likho Turns Windows Microphones Into Automated Eavesdropping Devices appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Plug & Pwn Attack Exploits Windows PnP to Gain SYSTEM Access With Zero Clicks

Security researchers Alejandro Hernando, also known as 0xedh, and Borja Martínez have unveiled a research project titled “Plug & Pwn.” This project demonstrates how the Windows Plug and Play (PnP) driver installation workflows can be exploited to execute vendor-supplied code with NT AUTHORITY\SYSTEM privileges. Presented at DEF CON 34, the research explores the risky intersection […]

The post Plug & Pwn Attack Exploits Windows PnP to Gain SYSTEM Access With Zero Clicks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts

Security researcher has disclosed a technique involving Windows Hello for Business (WHFB) that could allow attackers with access to an active Windows user session to authenticate to Microsoft Entra ID services without needing the victim’s PIN, biometric verification, or password. Mollema’s research demonstrates how attackers can effectively “borrow” the cryptographic key that underlies Windows Hello […]

The post Windows Hello Key Abuse Lets Attackers Access Microsoft Entra ID Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Can Abuse Microsoft WSUS Servers to Deploy Malicious Updates via NTLM Relay

Security researchers have shown how attackers could exploit Microsoft Windows Server Update Services (WSUS) infrastructure to distribute malicious software updates across enterprise networks. This technique relies on NTLM authentication coercion and relay attacks targeting WSUS deployments that utilize a separate Microsoft SQL Server database. WSUS is commonly used by organizations to centrally manage, approve, and […]

The post Hackers Can Abuse Microsoft WSUS Servers to Deploy Malicious Updates via NTLM Relay appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment

Microsoft Defender’s new automatic device isolation capability has emerged as a decisive control against modern ransomware intrusions that abuse legitimate Windows binaries, as demonstrated in a recent incident at QNET where a multi-stage attack was stopped in just 128 seconds. The mshta.exe process reached out to attacker-controlled infrastructure, retrieved a remote second-stage payload, and began […]

The post Ransomware Attack Abuses Legitimate Windows Tool to Evade Traditional Containment appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌