investigation

Winsage
April 18, 2026
A vulnerability has been discovered in Windows Defender that allows standard users to exploit a logic error in the file remediation process, enabling code execution with elevated privileges without administrative access. This flaw, identified by security researcher Chaotic Eclipse, occurs because Windows Defender does not verify if the restoration location of flagged files has been altered through a junction point. The exploit, named RedSun, takes advantage of a missing validation in the MpSvc.dll file, allowing attackers to redirect file restoration to the C:WindowsSystem32 directory. RedSun operates by chaining together four legitimate Windows features: Opportunistic Locks (OPLOCKs), Cloud Files API, Volume Shadow Copy Service (VSS), and Junction Points. The execution of the exploit involves monitoring shadow copies, triggering Defender's detection, synchronizing OPLOCKs, and ultimately writing malicious binaries to the System32 directory. The root cause is the lack of reparse point validation in the restoration process, and currently, no patch or CVE has been assigned for this vulnerability. It affects Windows 10, Windows 11, and Windows Server 2019 and later, and organizations are advised to implement behavioral detection strategies until a fix is available.
Winsage
April 17, 2026
Microsoft has acknowledged that the April 2026 security update for Windows Server, patch KB5082063, has caused significant disruptions for some enterprise domain controllers, leading to continuous reboot cycles in non-Global Catalog domain controllers used in Privileged Access Management (PAM) deployments. This has resulted in the unavailability of Active Directory authentication and directory services on affected servers. Additionally, the installation of KB5082063 may fail on some Windows Server 2025 systems. This issue marks the third consecutive year that April security updates have caused problems for Windows Server domain controllers. In previous years, Microsoft issued emergency fixes for similar issues, including crashes and complications with NTLM authentication. Administrators currently have limited options, including delaying the update, isolating a test domain controller, or engaging with Microsoft Support for tailored mitigation steps.
AppWizard
April 16, 2026
A shooting incident at a school in Zakarpattia has been classified as a terrorist act by authorities. A 15-year-old student discharged several rounds from a modified blank gun, injuring a classmate, who received prompt medical attention and is not in critical condition. Preliminary investigations indicate that the teenager acted under duress from unidentified individuals who threatened harm to his relatives if he did not comply with their demands. The shooter fled but was apprehended by patrol police shortly after. The Uzhhorod District Prosecutor's Office is overseeing the pre-trial investigation, which falls under Part 1 of Article 258 of the Criminal Code of Ukraine.
Tech Optimizer
April 16, 2026
Security researchers at Huntress discovered adware signed by Dragon Boss Solutions LLC that primarily displayed unwanted advertisements and redirected users to various sites. The malware included a sophisticated update mechanism that disabled antivirus programs. The primary update domain and its backup were not registered, making them exploitable. Tens of thousands of endpoints were compromised, affecting universities, operational technology networks, government agencies, and Fortune 500 firms.
Winsage
April 14, 2026
Cybercriminals are using sophisticated tactics to deceive users, particularly with a counterfeit website posing as a legitimate Windows 11 update. This site operates under the domain microsoft-update[.]support and is designed to trick individuals into downloading malware that compromises sensitive information. The site is written in French and mimics a genuine cumulative update for Windows 11, version 24H2, featuring a convincing KB article number and a blue download button. The malware is packaged as a Windows update using the WiX Toolset 4.0.0.5512 and is labeled "WindowsUpdate 1.0.0.msi," with properties that suggest it is from Microsoft. At the time of analysis, VirusTotal showed no detections for the malware, which conceals its harmful code within an Electron shell, making it difficult to identify. Users are advised to download updates directly through the Windows Settings app or from Microsoft's official support hub.
AppWizard
April 14, 2026
KuloNiku: Bowl Up! — 97% positive reviews of 474 ratings, Developer: Gambir Studio, Publisher: Raw Fury, Genre: Casual, Indie, Simulation, Release Date: 7 Apr, 2026. Sol Cesto — 93% positive reviews of 2461 ratings, Developer: Tambouille, Géraud Zucchini, Chariospirale, Publisher: Goblinz Publishing, Genre: Indie, Strategy, Release Date: 10 Apr, 2026. Nautical Survival — 99% positive reviews of 162 ratings, Developer: Idan Rooze, Publisher: Idan Rooze, Genre: Action, Adventure, Casual, Release Date: 9 Apr, 2026. Wannabe Galgame God!!! — 98% positive reviews of 235 ratings, Developer: Noctella Observatory, Publisher: Noctella Observatory, Genre: Free To Play, Release Date: 10 Apr, 2026. Idols of Ash — 98% positive reviews of 259 ratings, Developer: Leafy Games, Publisher: Leafy Games, Genre: Adventure, Indie, Simulation, Release Date: 9 Apr, 2026. Draw Steel — 6 reviews, Developer: Verisim, MCDM, Publisher: MCDM, Genre: Action, Adventure, RPG, Release Date: 8 Apr, 2026. Elton Manor: Requiem of the Cursed Roses — 98% positive reviews of 65 ratings, Developer: 阿魯, Publisher: Playmeow, Genre: Casual, RPG, Release Date: 7 Apr, 2026. Origament: A Paper Adventure — 97% positive reviews of 44 ratings, Developer: Space Sauce Studio, Publisher: Beverlor, Genre: Action, Adventure, Casual, Release Date: 7 Apr, 2026. WRATH: Aeon of Ruin VR - Brutal Edition — 91% positive reviews of 34 ratings, Developer: Team Beef, Flat2VR Studios, Publisher: Flat2VR Studios, Genre: Action, Release Date: 9 Apr, 2026. Arcadia Fallen II — 100% positive reviews of 32 ratings, Developer: Galdra Studios, Publisher: Galdra Studios, Genre: Adventure, Casual, Indie, Release Date: 9 Apr, 2026. GGST Additional Character 18 - Jam Kuradoberi — 94% positive reviews of 76 ratings, Developer: Arc System Works, Publisher: Arc System Works, Genre: Action, Release Date: 9 Apr, 2026. Barking from the Dark — 100% positive reviews of 27 ratings, Developer: shoftArt, Publisher: shoftArt, Genre: Adventure, Indie, Simulation, Release Date: 8 Apr, 2026. Fortune Seller — 97% positive reviews of 40 ratings, Developer: Kiwick, Publisher: Kiwick, Genre: Casual, Indie, Strategy, Release Date: 6 Apr, 2026. Find Your Words — 96% positive reviews of 56 ratings, Developer: Capybara Games, Publisher: Capybara Games, Genre: Adventure, Casual, Indie, Release Date: 8 Apr, 2026. Spinny Dungeon — 97% positive reviews of 44 ratings, Developer: Typing Monkey, Publisher: Typing Monkey, Genre: Indie, RPG, Strategy, Release Date: 6 Apr, 2026. Pluralys — 96% positive reviews of 28 ratings, Developer: Ivalys Studios, Publisher: Ivalys Studios, Genre: Adventure, Casual, Indie, Release Date: 8 Apr, 2026. MINOS — 90% positive reviews of 152 ratings, Developer: Artificer, Publisher: Devolver Digital, Genre: Action, Adventure, Simulation, Release Date: 9 Apr, 2026. Subversive Memories — 96% positive reviews of 33 ratings, Developer: Southward Studio, Publisher: Southward Studio, Genre: Action, Adventure, Indie, Release Date: 8 Apr, 2026. Nippets: A Hidden Object Game — 91% positive reviews of 59 ratings, Developer: Blink Industries, Publisher: Blink Industries, Genre: Casual, Indie, Release Date: 7 Apr, 2026. [Redacted] The Safehouse — 100% positive reviews of 21 ratings, Developer: Heartbeast, Publisher: Heartbeast, Genre: Indie, Release Date: 9 Apr, 2026.
Winsage
April 13, 2026
Mozilla has accused Microsoft of using its dominance in the Windows operating system to marginalize competitors in the AI sector, particularly through the promotion of its Copilot feature. Mozilla claims that misleading update mechanisms are being used to push Copilot onto users and that system settings are being adjusted to hinder the performance of alternative browsers like Firefox. This situation is reminiscent of the 1990s browser wars when Microsoft bundled Internet Explorer with Windows to eliminate competition. In July 2025, Opera filed a formal antitrust complaint in Brazil against Microsoft, leading to an investigation into whether Microsoft was coercing hardware manufacturers to bundle Edge exclusively. A ruling against Microsoft could require a separation between the operating system and AI services. Microsoft's current strategy aims to control the AI inference layer, with each interaction through Copilot representing valuable data and monetization opportunities. Reports indicate that Microsoft is removing Copilot branding from standalone applications to further integrate it into the operating system. Despite Edge being the third most popular browser, Microsoft's tactics suggest a focus on securing AI infrastructure rather than just competing for browser market share. Regulatory scrutiny may increase due to ongoing antitrust challenges related to Microsoft's OpenAI investment and cloud AI bundling practices. The development of OEM relationships and potential resistance to Microsoft's requirements could significantly impact its integration strategy.
Search