Windows 11 RAM Attack Lets Admins Disable Defender and VBS
USENIX researchers turned writable DIMM configuration into arbitrary physical-memory access. April's Windows update blocks their current chain under Secure Boot.
Read article →Reader view
Choose the default article length.
Endpoint security, malware, device controls, and host visibility.
USENIX researchers turned writable DIMM configuration into arbitrary physical-memory access. April's Windows update blocks their current chain under Secure Boot.
Read article →Chrome 151 fixes five high-severity use-after-free bugs; endpoint inventories must show the fixed build or a later superseding release.
Read article →Researchers chain signed Windows device installers into SYSTEM execution through emulated USB hardware or an ordinary RDP session.
Read article →A signed ClickOnce app delivered two stealers and an hVNC RAT after a fake Web3 interview. Hunt per-user ClickOnce records, then rotate every secret reachable from affected hosts.
Read article →Microsoft's August updates fix an AFD.sys race used in attacks; defenders must verify fixed builds and investigate pre-patch privilege escalation.
Read article →August Windows updates fix a public registry-hive privilege escalation; defenders can hunt its staging files, virtual paths, and unusual DLL loads.
Read article →OVSwrap exploits a 16-bit nested-action limit in the Linux kernel, leaving defenders to verify both the running fix and the earlier exposure window.
Read article →A Microsoft case study traces mshta execution to one isolated QNET host and shows which workstations qualify for the preview action.
Read article →A remote SCTP peer can trigger the kernel flaw, while Tencent separately demonstrated local privilege escalation and container escape. Defenders need both reachability and running-kernel checks.
Read article →Cisco's August IOS XE hardening release fixes seven vulnerability classes across five reviewed trains; affected devices need an upgrade.
Read article →An automated npm campaign uses hundreds of disposable packages to launch detached native malware, with DNS TXT records as a fallback delivery channel.
Read article →Remus uses an Ethereum smart contract to resolve changing command infrastructure before stealing browser sessions, credentials, and wallet data.
Read article →Code in a signed-in Windows session can invoke a TPM-backed Windows Hello for Business key, authenticate without a device identity claim, and create a path to durable Entra access.
Read article →