System Information

Winsage
September 2, 2026
An active malware campaign is using counterfeit software-download websites to distribute malicious installers, primarily targeting users seeking popular software. This campaign has significantly affected China-based operations of multinational corporations and Chinese-speaking users. The malware, once executed, can establish persistence, undermine security measures, and communicate with attacker-controlled infrastructure. Victims span various sectors, including healthcare, manufacturing, gaming, technology, logistics, government, and education. Microsoft associates this campaign with a Chinese threat cluster called Silver Fox, known for using spoofed vendor download pages to spread Gh0st RAT and ValleyRAT. The malicious websites are hosted on .com.cn and .hl.cn domains, featuring Chinese-language content. The downloaded files are dynamically generated, and upon execution, they deploy a wrapper installer that initiates the malware payload. The malware achieves persistence through scheduled tasks and interferes with Windows Update services. The campaign establishes command-and-control communication over non-standard ports, with two identified domains linked to the activity. Microsoft Defender has detected the threat and initiated containment procedures. Kaspersky reported a related malicious installer exploiting a legitimate adware application to execute a backdoor, which captures keystrokes and clipboard contents. ValleyRAT, a sophisticated implant, can collect system information, reboot the computer, capture screenshots, and transmit logs. The attackers are motivated by cyber espionage and financial gain, targeting organizations globally. A subgroup within GoldenEyeDog, known as CuboidalCanine, has also been linked to the use of ValleyRAT, particularly in the gambling industry. In June 2026, Chinese authorities addressed cybercrime cases involving a new variant of the Silver Fox trojan.
AppWizard
August 29, 2026
Terminal emulators allow users to interact with operating systems through text commands. Termux is an open-source terminal emulator for Android available on the F-Droid store. Users can test internet speed directly from Termux by installing Python and using the speedtest command. Weather information can be accessed using the curl command for a three-day forecast, and users can create shortcuts for convenience. Termux can display system information using colorful ASCII art with tools like fastfetch or macchina. It allows remote access to the phone via SSH after installing openssh. Users can run AI chatbots locally using the command-line tool Ollama. Termux can also facilitate the installation of Linux-based operating systems on Android devices using the proot-distro tool.
Winsage
August 18, 2026
Microsoft is phasing out the Windows Management Instrumentation Command-line (WMIC) tool, which will be entirely absent from existing Windows PCs following the latest preview update. WMIC, a command-line utility for extracting system information and performing administrative tasks, is being removed, although the underlying Windows Management Instrumentation (WMI) framework will remain supported. Users relying on older management and automation scripts that utilize WMIC may face challenges, as commands associated with WMIC will no longer function after the update.
Winsage
August 13, 2026
Dave W. Plummer, a notable figure in programming, contributed significantly to Microsoft by introducing ZIP file support for Windows, adapting Space Cadet Pinball for Windows NT, and creating the Windows Task Manager, which debuted in 1996. He has shared insights from his time at Microsoft through his platform, Dave's Garage. Recently, he released a mockup of a redesigned Task Manager, named "Task Manager OG" (TMOG), which features a cyberpunk aesthetic and is currently available as a beta version for macOS, with a Windows version planned. TMOG combines elements of macOS's Activity Monitor and Windows Task Manager, providing essential system information and deeper diagnostics. The application is described as being half the size of the Windows Task Manager and is available for free download.
Winsage
July 21, 2026
Frustration with Microsoft's data collection practices has increased, particularly since the transition from Windows 7, where the amount of user data collected has significantly risen. Microsoft gathers extensive data points, including device IDs, user IDs, operating system information, and application usage data. Many users are turning to Linux as an alternative, as it respects user privacy and does not collect personal data without consent. Microsoft has also employed manipulative design tactics to influence user behavior, such as persistent prompts and misleading visuals. Additionally, the introduction of ads in Windows 11 has been viewed as disrespectful to paying customers, while Linux remains ad-free. Users are encouraged to switch to Linux to express dissatisfaction with Microsoft's practices and to reclaim their digital autonomy.
Winsage
June 21, 2026
The expiration of Microsoft's Secure Boot 2011 certificates on June 24 will not prevent older Windows PCs from booting, as confirmed by Microsoft. Devices will continue to operate normally, but they will miss future boot-level security updates, including updates to the Windows Boot Manager and mitigations for newly identified vulnerabilities. The ability to receive the Secure Boot 2023 update depends on the device firmware's compatibility, with many manufacturers, including Dell, HP, Lenovo, and ASUS, having cutoffs for BIOS updates based on the device's End of Service Life. Older PCs using Legacy BIOS or Compatibility Support Module (CSM) mode do not utilize UEFI Secure Boot, making the update irrelevant. Users running Windows 11 on unsupported hardware may have Secure Boot disabled or improperly configured. Without the 2023 certificates, devices cannot receive future revocation updates to the Secure Boot DBX, which lists compromised bootloaders. Users on Windows 10 with supported OEMs may receive the update if a compatible BIOS is available, while those on older PCs without updates can continue using their devices but will lack future security updates. The Secure Boot status can be checked through the Windows Security app, with color-coded badges indicating the status of the certificates.
Search