registry key

Winsage
September 15, 2026
Iranian state cyber actors are targeting individuals through popular messaging applications, using surveillance and data-stealing malware known as "Chosen Brick," which has been in use since at least 2025. This malware is designed for Windows systems and enables the theft of personal data, allowing Iranian spies to monitor perceived threats such as dissidents, activists, and journalists. The attacks typically begin with messages sent via WhatsApp or Telegram, impersonating trusted contacts. Attackers conduct extensive research on their targets to craft convincing messages that encourage victims to download malicious files disguised as legitimate applications. Once executed, Chosen Brick operates stealthily, evading detection and establishing a connection for command-and-control communications. It can enumerate processes, capture screen and audio content, extract sensitive information, and even wipe infected systems. Organizations suspecting compromise are advised to engage IT providers for investigations and to inform staff about potential risks. Recent alerts follow cyberattacks on water and energy sectors linked to Iran, with ongoing concerns about the implications for cybersecurity amid escalating military tensions. Additionally, five US agencies have reported that attackers are using AI-generated scripts to exploit vulnerabilities in critical infrastructure systems.
Winsage
September 9, 2026
Recent investigations have identified the BlueMoon exploit kit, used by espionage-driven threat activity clusters, particularly linked to APT31, a China-aligned state-sponsored group, since August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046 (a type confusion vulnerability in Google Chrome's V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC). Google and Microsoft have released patches for these vulnerabilities, which were exploited as "patch-gap" zero-days. The attack vectors typically begin with phishing emails that lead victims to malicious URLs, triggering the vulnerabilities for code execution and privilege escalation. Variants of BlueMoon have been detected, featuring modifications for specific campaigns. Notable attack chains include: - APT31 targeting NGOs and mining firms in the U.S. with a malicious browser add-on called GemStone. - UNK_LateNight targeting U.S. aerospace companies, deploying BlueMoon alongside the ShadowPad backdoor. - UNK_DoubleCheck targeting a Vietnamese manufacturer, using DLL sideloading to execute a Rust binary. - UNK_QuietRacket targeting government and financial organizations in Indonesia and Singapore, modifying BlueMoon to execute a .NET assembly. CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026, requiring federal agencies to apply patches by September 18, 2026. Indicators of compromise include specific process trees, files, folders, scheduled tasks, mutexes, and registry keys. Proofpoint has released detection rules to help organizations identify and mitigate these threats.
Winsage
September 4, 2026
The preview update KB5120998 for Windows 11 versions 24H2 and 25H2, released on August 27, 2026, has caused issues such as erratic mouse pointer behavior and disappearing desktop backgrounds, particularly in non-English versions. Microsoft has acknowledged these problems, indicating that they stem from coding practices that fail to load certain settings correctly. Specific issues include a "black desktop background" due to desktop settings not loading and mouse customization resetting to default configurations. The problems may be related to translation issues within the registry, as registry keys have been altered post-update. Users have suggested that manually adjusting these registry keys could restore normal functionality.
Tech Optimizer
August 31, 2026
Silver Fox is linked to the distribution of a backdoor malware called ValleyRAT, disguised as the legitimate QN Wallpaper adware application. Once installed, ValleyRAT provides complete control over the compromised machine. The malware uses DLL sideloading to operate under the guise of a legitimate process, bypassing security measures. It disables Windows Defender and adds itself to autorun entries, and can mark its process as critical, causing system crashes if terminated. Kaspersky has identified specific indicators of compromise (IoCs) including hashes, command-and-control servers, and associated domains. In 2026, Kaspersky recorded over 100,000 detections of ValleyRAT affecting more than 1,500 unique users, mainly in China and India.
Winsage
August 28, 2026
Microsoft has begun rolling out a permanent solution to a system stability and gaming performance issue on Windows 11 devices, which has caused crashes, game launch failures, and freezing, often with the "EXCEPTIONACCESSVIOLATION" error message. The problem was linked to updates from August 2026 and was identified as being related to peripherals with RGB lighting features that installed disruptive drivers. Specifically, the inpoutx64.sys driver was found to be responsible for these disruptions. Microsoft is deploying a fix that disables this driver on affected systems, starting from August 26, 2026. This driver block will also be included in the September 2026 Windows security updates. For enterprise-managed devices, a temporary workaround involves manually disabling the inpoutx64 driver via the Windows Registry. Microsoft has assured users that this action should not cause unintended behavior and can be reversed.
Winsage
August 28, 2026
Microsoft has begun rolling out a permanent solution to a problem causing system crashes and gaming disruptions on Windows 11 devices, specifically related to game launch failures and freezing with "EXCEPTIONACCESSVIOLATION" errors. The issue affects various games, including ARC Raiders, MARVEL Tōkon: Fighting Souls, and The Finals, particularly on Windows 11 versions 24H2 and 25H2, and is linked to peripherals with built-in RGB lighting. The inpoutx64.sys driver has been identified as the cause of these complications. Microsoft is deploying a fix that disables this driver on affected devices, starting on August 26, 2026, and it may take up to 24 hours to reach all impacted devices. This driver block will also be included in the September 2026 Windows security updates. For enterprise-managed devices that do not automatically receive the fix, a temporary workaround involves disabling the inpoutx64 driver via the Windows Registry. Microsoft has stated that disabling this registry key should not lead to unintended behavior.
Winsage
August 28, 2026
Late last week, reports emerged about gameplay disruptions linked to the Windows 11 August update, causing issues like forced crashes, unexpected freezing, and device restarts. Microsoft identified the interaction between gaming applications and RGB peripherals as the cause. They released a workaround involving a registry modification to prevent the inpoutx64 driver from loading, which resolved the issue temporarily. This workaround specifically targets devices with the inpoutx64 driver enabled and the game ARC Raiders installed. Users can disable the driver by modifying the registry key HKEYLOCALMACHINESYSTEMCurrentControlSetServicesinpoutx64, changing the Start value to 4, and restarting the computer. Microsoft is also working to block RGB peripherals for the game MARVEL Tōkon: Fighting Souls and has addressed similar issues for THE FINALS. The driver block will be included in the September 2026 Windows security updates and future releases.
Winsage
August 27, 2026
Microsoft addressed printing issues and gaming-related complications linked to recent .NET Patch Tuesday updates. The problems were associated with RGB applications and the inpoutx64 system driver, which caused compatibility issues when certain games were launched. Microsoft has implemented a block to prevent the inpoutx64 driver from loading on affected devices, specifically targeting systems with the driver enabled and ARC Raiders installed. Users will receive a notification after the block is implemented, and the game should launch without further issues. The block is also being extended to systems running MARVEL Tōkon: Fighting Souls, while the issue with THE FINALS has been resolved. The resolution is being distributed automatically, and users need to restart their devices after the fix is applied. For enterprise-managed devices, IT administrators must manually apply the fix. Microsoft provided a temporary workaround by suggesting users disable the inpoutx64 driver through the Windows Registry. Users can change the Start value in the Registry Editor to 4 to disable the driver and may need to restart their devices for changes to take effect. Users are advised to back up the Registry before making modifications, and they can restore the driver by reverting the Start value back to its original setting.
Winsage
August 24, 2026
Microsoft has acknowledged gaming issues related to Windows 11 updates released on August 11, 2026, affecting games like ARC Raiders, MARVEL Tōkon: Fighting Souls, and The Finals. Problems reported include game crashes, failures to launch, freezes, and unexpected system restarts, particularly on Windows 11 versions 24H2 and 25H2. Microsoft identified a link between these issues and drivers or components associated with RGB lighting devices, specifically the inpoutx64.sys driver. A temporary workaround involves disabling the inpoutx64 driver through the Windows Registry, with caution advised regarding potential unintended consequences. Users are encouraged to report issues via the Feedback Hub app as Microsoft investigates further.
Winsage
August 24, 2026
Microsoft's update for Windows 11, designated “KB5121003,” has caused issues for users with RGB peripherals, leading to system freezes, game crashes, and Blue Screen of Death (BSOD) errors. The problems are linked to drivers associated with RGB lighting, particularly a driver named “inpoutx64,” which disrupts system stability when certain games are launched. Affected games include Arc Raiders, Marvel Tokon: Fighting Souls, and The Finals, with BSOD errors citing “EXCEPTIONACCESSVIOLATION.” Microsoft has suggested a workaround involving temporarily disabling the inpoutx64 driver via the Windows registry, but users are cautioned about potential complications. Disabling this driver may affect the functionality of RGB features on peripherals, and re-enabling it carries risks as well.
Search