Microsoft Windows

Winsage
September 15, 2026
A spear-phishing campaign linked to the Chinese threat actor UTA0560 targeted various NGOs on September 1, 2026, exploiting recently patched vulnerabilities in Google Chrome and Microsoft Windows. The campaign utilized a malicious JavaScript backdoor called GRIMWEDGE, which was deployed through a multi-stage exploit chain that involved three vulnerabilities: CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880. The attack began with spear-phishing emails that led recipients to a vulnerable U.S.-based university website, allowing attackers to redirect users to their infrastructure. The exploit chain enabled arbitrary code execution and facilitated the deployment of GRIMWEDGE, which is capable of host reconnaissance, file and process management, command execution, and payload delivery. The initial payload was an executable named "msgbox.exe," which extracted a legitimate Windows binary and a malicious DLL called "wsc.dll." This DLL initiated a sideloading chain and contacted a command-and-control server for further instructions. GRIMWEDGE allows for several commands, including system reconnaissance, directory listing, file deletion, and command execution in a hidden window. It lacks built-in persistence or lateral movement mechanisms but provides a foothold for further exploitation. Concurrently, another Chinese threat actor, JungleBamboo (APT31), used the same exploit chain to deploy a loader named SUPERSTOMP, which installs a credential-stealing Chrome extension called LONGTALE. The simultaneous use of the exploit chain by multiple actors suggests potential sharing or sale of the exploit, raising concerns about patch-gap vulnerabilities that pose risks for exploitation campaigns.
Winsage
September 10, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has expanded its Known Exploited Vulnerabilities (KEV) catalog, adding critical vulnerabilities that need immediate attention. 1. CVE-2026-75650: A vulnerability in Adobe Commerce and Magento with a CVSS score of 10.0, allowing unauthenticated remote code execution. Affected versions include Magento Open Source releases 2.4.7, 2.4.8, and 2.4.9. It has been actively exploited since September 4. 2. CVE-2026-81963: A Microsoft Windows vulnerability with a CVSS score of 7.8, related to a link-following issue within the Update Stack, allowing local attackers to escalate privileges. It is currently being exploited. 3. CVE-2026-85880: Another Microsoft Windows vulnerability rated at 7.8, involving a heap-based buffer overflow in the ALPC component, permitting local privilege escalation. This flaw is also actively exploited. 4. CVE-2026-86218: A N-able N-central vulnerability with a CVSS score of 10.0, allowing pre-authenticated remote code execution. N-able has released an emergency hotfix for this issue. Federal agencies must address these vulnerabilities by specified deadlines: Windows flaws by September 22 and other vulnerabilities by September 11, 2026, in accordance with Binding Operational Directive (BOD) 22-01. Private organizations are advised to review the KEV catalog and take necessary actions to strengthen their infrastructure against these vulnerabilities.
Winsage
September 10, 2026
Microsoft is continuing the rollout of Secure Boot certificate updates, with the next significant deadline on October 19, 2026, when the Microsoft Windows Production PCA 2011 certificate expires. The September 2026 Patch Tuesday update has expanded eligibility for Secure Boot certificates to more PCs classified as “high confidence.” Users may need to reboot their PCs to install these updates, and some may require firmware updates beforehand. Microsoft has confirmed that the update process will persist beyond established deadlines, and older certificates are expiring in stages, with the first two deadlines having already passed. Users should ensure they have the latest updates installed and check their Secure Boot status in Windows Security. Microsoft has assured that PCs without the newer certificates will continue to boot normally and receive standard updates while the rollout continues.
Winsage
September 9, 2026
Recent investigations have identified the BlueMoon exploit kit, used by espionage-driven threat activity clusters, particularly linked to APT31, a China-aligned state-sponsored group, since August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046 (a type confusion vulnerability in Google Chrome's V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC). Google and Microsoft have released patches for these vulnerabilities, which were exploited as "patch-gap" zero-days. The attack vectors typically begin with phishing emails that lead victims to malicious URLs, triggering the vulnerabilities for code execution and privilege escalation. Variants of BlueMoon have been detected, featuring modifications for specific campaigns. Notable attack chains include: - APT31 targeting NGOs and mining firms in the U.S. with a malicious browser add-on called GemStone. - UNK_LateNight targeting U.S. aerospace companies, deploying BlueMoon alongside the ShadowPad backdoor. - UNK_DoubleCheck targeting a Vietnamese manufacturer, using DLL sideloading to execute a Rust binary. - UNK_QuietRacket targeting government and financial organizations in Indonesia and Singapore, modifying BlueMoon to execute a .NET assembly. CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026, requiring federal agencies to apply patches by September 18, 2026. Indicators of compromise include specific process trees, files, folders, scheduled tasks, mutexes, and registry keys. Proofpoint has released detection rules to help organizations identify and mitigate these threats.
Winsage
September 9, 2026
Windows 11 Pro is currently on sale for .97, down from its regular price of 9. It includes features such as BitLocker encryption, Hyper-V and Windows Sandbox for virtual machines, and Azure AD for business connectivity. Additional enhancements include Snap layouts, DirectX 12 Ultimate for gaming, TPM 2.0 for secure logins, and Copilot for assistance. The license is only compatible with PCs that meet Windows 11's minimum specifications, which can be checked using Microsoft's free PC Health Check app.
Winsage
September 6, 2026
Windows and macOS offer various power management features to optimize energy consumption for both laptop and desktop users. In Windows, users can access power options through Settings > System > Power (for desktops) or System > Power & battery (for laptops). Key features include: - Power Mode options: Best Power Efficiency, Balanced, and Best Performance. - Configurable screen, sleep, and hibernate time-outs to reduce energy use. - Energy Saver mode, which minimizes background activity and dims the display. - Customization of the Power & sleep button controls. In macOS, users can find power settings under System Settings via the Apple menu. Key features include: - Low Power Mode for laptops, which reduces background activity and dims the screen. - Energy Mode options for Macs with Apple Silicon: Low Power, Automatic, and High Power. - Options to prevent automatic sleep and optimize video streaming performance. - Screen time-out settings under Lock Screen to adjust display delay when idle.
Winsage
September 6, 2026
Power management options in Windows and macOS can help extend battery life for laptops and reduce energy consumption for desktops. In Windows 11, users can access power options via Settings > System > Power (for desktops) or System > Power & battery (for laptops). Key settings include Power Mode (Best Power Efficiency, Balanced, Best Performance), screen and sleep time-outs, Energy Saver mode, and Power & sleep button controls. In macOS 27 Golden Gate, users find power settings under System Settings > Energy (for desktops) or Battery (for laptops). Key features include Low Power Mode, Energy Mode options (Low Power, Automatic, High Power) for Apple Silicon Macs, and additional settings under the Options button. Screen time-out settings are found under Lock Screen in System Settings. Adjusting these settings can significantly impact energy usage.
Winsage
August 24, 2026
Microsoft Windows NT 4.0 was officially released on August 24, 1996, marking its 30th anniversary today. Codenamed “Tukwila,” it integrated the Windows Explorer desktop from Windows 95 with the NT operating system. Windows 95 was released a year earlier on August 24, 1995, and was initially codenamed “Chicago.” Windows NT 4 incorporated a modern user interface while maintaining the reliability of the NT kernel. It introduced features like the journaling NTFS filesystem but had limitations such as stability issues due to changes in the Graphics Device Interface (GDI) and lack of support for FAT32 and USB interfaces. Despite these shortcomings, NT 4 was a significant operating system that contributed to the competitive landscape of operating systems.
Search