cybersecurity threats

AppWizard
July 21, 2026
Zyaire Dontaevious Zamarion Wilkins, a 21-year-old from Florida, was arrested for allegedly leading a cybercrime operation that targeted approximately 8,000 gamers by distributing malware disguised as popular Steam games. Wilkins and two accomplices used social media platforms like Discord, Telegram, X, and LinkedIn to promote their malware-infused games, focusing on individuals with significant cryptocurrency holdings. The compromised games include Dashverse (2024), Lunara (2024), PirateFi (2025), Blockblasters (2025), and Lampy (2026). The FBI's investigation revealed that Bitcoin payments were sent from one of Wilkins' co-conspirators to a user identified as "Sibel.eth," who had lost funds intended for medical treatments for stage 4 cancer.
Winsage
July 16, 2026
Approximately 16.9 percent of monitored Windows devices are still running Windows 10, a decline from about half a year ago. Windows 10 will receive updates until October 12, 2027, for consumer devices and until October 10, 2028, for commercial customers. Small and medium-sized businesses (SMBs) have 21.4 percent of their machines on Windows 10, with 23 percent in healthcare and pharmaceutical sectors and 22.7 percent in consumer and retail. A Windows 10 device has an average of 1,903 active Common Vulnerabilities and Exposures (CVEs), compared to 652 on Windows 11. Only 14 percent of Windows 10 assets have Extended Security Updates (ESU) patches applied. Many devices are tied to vendor certifications that complicate upgrades, and the rising cost of new PC hardware is a concern. The stagnation of Windows 11 adoption continues, with minimal change in market share distribution.
Winsage
July 15, 2026
Microsoft released its July Patch Tuesday updates, addressing 570 security vulnerabilities in Windows, a record number for the company. This update includes three zero-day vulnerabilities, two of which have been exploited in real-world attacks, affecting Microsoft’s Active Directory and SharePoint, while the third concerns BitLocker encryption. The update also enhances Windows features, including changes to the Widgets app, improvements in File Explorer speed, refined Bluetooth connectivity, and a new feature allowing users to pause updates until a specific date. However, the update has been temporarily halted for certain Dell computers due to compatibility issues, with Microsoft working on a fix.
Winsage
June 17, 2026
The Windows variant of SprySOCKS malware, developed by the Chinese threat group Earth Lusca, targets government entities globally and features advanced capabilities such as rootkit-level stealth and extensive command-and-control (C2) functionalities. It operates on Windows systems, utilizing two main variants: WINDRV, which includes kernel drivers for stealth operations, and WINPLUS, a streamlined backdoor. The malware can communicate over TCP, UDP, and WebSocket, offering over 30 C2 commands for various operations, including system information gathering and keystroke logging. WINDRV loads a driver named ‘RawWNPF’ into memory using another signed kernel driver, allowing it to conceal processes and achieve persistence. The malware's design incorporates open-source elements and exploits vulnerabilities in the software supply chain, notably using a leaked certificate for driver signing. To combat SprySOCKS, organizations are advised to implement advanced endpoint detection and response (EDR) solutions, maintain regular patching, and manage supply chain risks vigilantly. The malware's adaptability and reliance on legitimate certificates complicate detection efforts, necessitating continuous refinement of security practices.
Winsage
June 15, 2026
A cybersecurity researcher known as “Nightmare Eclipse” has revealed two zero-day exploits threatening Windows systems: RoguePlanet and GreatXML. RoguePlanet targets Microsoft Defender, allowing attackers to execute privileged actions and gain SYSTEM-level access on Windows machines. It is a local privilege escalation vulnerability that remains effective on fully updated systems. GreatXML claims to bypass BitLocker disk encryption by manipulating the Windows Recovery Environment, potentially granting access to protected files. However, its effectiveness may be overstated, as it might require administrator-level access. Microsoft advises organizations to implement security updates, treat lost or accessible devices as high-risk, enforce stricter policies, and monitor threat intelligence to mitigate exposure to these vulnerabilities.
Winsage
June 12, 2026
Authorities in Phu Tho province have initiated a criminal case regarding the illegal installation and use of copyrighted software, specifically targeting pirated Microsoft Windows and Office products. Formal charges for "infringement of copyright and related rights" have been made following urgent searches at five locations in Hanoi and Phu Tho. The investigation revealed that individuals and businesses were using various platforms to promote, distribute, and sell unlicensed software, including cracked software and counterfeit license keys. The inquiry began with Song Lam Trading and Service Co, whose director faces allegations of supplying 81 computers pre-installed with unauthorized software. An additional 350 computers linked to a local educational institution were also found to have illegal software activation. The implicated companies include Athena Vietnam Information Systems Co and Tek-Solution Technology Co, whose directors are under police scrutiny. Authorities estimate that the financial losses for copyright holders could reach tens of billions of đồng, and they have raised concerns about cybersecurity threats associated with illegally activated software.
Winsage
June 1, 2026
The Centre for Cybersecurity Belgium (CCB) has warned about the exploitation of a critical vulnerability in Windows Netlogon, identified as CVE-2026-41089, which allows remote code execution on domain controllers without prior access or authentication. This vulnerability, characterized as a stack-based buffer overflow, was patched by Microsoft during the May 2026 Patch Tuesday. The CCB emphasized the urgency of patching vulnerable servers, noting that the vulnerability is actively being exploited. The CVSS score for this vulnerability is 9.8. Further details on the ongoing attacks have not been disclosed, and Microsoft has not updated its advisory on the vulnerability.
Search