threats

Winsage
May 24, 2025
This month's KB5058497 update for Windows 11 24H2 introduces the first 'hotpatch' update, allowing installation without a reboot, but it is only available for Windows 11 24H2 Enterprise users. There is no timeline for extending this feature to Pro and Home users. To use hotpatch updates, users must have a Microsoft subscription that includes Windows 11 Enterprise E3, E5, or F3, Windows 11 Education A3 or A5, or a Windows 365 Enterprise subscription, along with devices running Windows 11 Enterprise version 24H2 (Build 26100.2033 or later), an x64 CPU, Microsoft Intune for deployment management, and Virtualization-based Security (VBS) enabled. Users of Windows 11 24H2 or older versions must reboot their systems to apply new security updates, except for specific patches for Windows Defender, while every third update will still require a reboot. KB5058497 is scheduled to be released between May and June 2025 during the 'no restart' period, and it has been reported to install seamlessly without prompting for a reboot. Users of Windows 11 Home and Pro still face the traditional monthly reboot requirement for updates.
Tech Optimizer
May 24, 2025
Apple devices, previously considered largely immune to cyber threats, are experiencing a rise in ransomware attacks targeting macOS, as reported by cybersecurity firm Black Fog. This shift is attributed to the increasing popularity of Apple devices and evolving ransomware tactics. Notable ransomware incidents include EvilQuest and MacRansom, with new threats like NotLockBit and FrigidStealer emerging. In response, Arms Cyber has begun offering ransomware protection for macOS, becoming the first firm to provide comprehensive protection across Windows, Linux, and macOS. Their solutions include real-time file entropy analysis, Steal Archival technology for rapid recovery, and Automated Moving Target Defense (AMTD) to thwart attacks. The growing use of Mac devices in critical sectors highlights the need for enhanced security measures, as attackers see opportunities in less protected systems. Managed Security Service Providers (MSSPs) are also being equipped with these protections to strengthen defenses against ransomware.
Winsage
May 23, 2025
Microsoft will end support for Windows 10 and Windows Server 2019 on October 14, 2025. After this date, Microsoft will no longer provide updates, including security patches and programming fixes, potentially increasing vulnerability to operational failures and cyber threats. Upgrading to Windows 11 may be possible at no additional cost if hardware meets minimum requirements. Companies should consider a migration strategy that balances costs and needs, possibly redistributing older devices for less demanding roles. For server upgrades, it is recommended to consolidate functionalities, utilize physical servers for virtual systems, assess company growth for informed investments, and prioritize redundancy through frequent backups.
Tech Optimizer
May 23, 2025
The AhnLab Security Intelligence Center (ASEC) has identified a new strain of backdoor malware that works with a Monero coin miner, utilizing the PyBitmessage library for covert P2P communications. This malware uses encryption to secure data exchanges and anonymize identities, complicating detection by security tools. It decrypts resources using XOR operations to deploy a Monero miner and a backdoor component. The Monero miner exploits the cryptocurrency's anonymity, while the backdoor, created with PowerShell, installs PyBitmessage and retrieves files from GitHub or a Russian file-sharing platform. Commands are executed as PowerShell scripts, making detection difficult. The malware may be distributed as legitimate software or cracked files. ASEC advises caution with unverified files and recommends keeping security solutions updated. Indicators of Compromise (IOCs): - MD5: 17909a3f757b4b31ab6cd91b3117ec50 - MD5: 29d43ebc516dd66f2151da9472959890 - MD5: 36235f722c0f3c71b25bcd9f98b7e7f0 - MD5: 498c89a2c40a42138da00c987cf89388 - MD5: 604b3c0c3ce5e6bd5900ceca07d587b9 - URLs: - http://krb.miner.rocks:4444/ - http://krb.sberex.com:3333/ - http://pool.karbowanec.com:3333/ - http://pool.supportxmr.com:3333/ - https://spac1.com/files/view/bitmessage-6-3-2-80507747/
Winsage
May 23, 2025
A new tool called Defendnot can disable Windows Defender by masquerading as a legitimate antivirus program, exploiting a feature of Windows that allows only one antivirus solution to operate at a time. When Defendnot is installed, Windows automatically disables Defender, leaving systems vulnerable to cyber threats.
Winsage
May 22, 2025
A new tool called Defendnot can disable Windows Defender by masquerading as another antivirus program, exploiting a limitation of the Windows operating system that prevents multiple antivirus solutions from running simultaneously. When Defendnot is installed, Windows automatically disables Defender, leaving systems vulnerable. Cybersecurity experts recommend using robust antivirus solutions like TotalAV for additional security.
AppWizard
May 22, 2025
Indie game developer Rhinotales Studio has announced their new game, Critical Shift, a hardcore turn-based tactical RPG set in an Antarctic research station. Players lead a squad of elite agents to investigate a distress call from ICE-1 Station, where communications have ceased. The game features a tactical combat system that emphasizes positioning and weapon range, allowing players to adapt their strategies in real-time. It includes over 30 levels with unique challenges, a story-driven narrative crafted by writer Guilty Three, and will be available on PC via Steam, Xbox, and PlayStation, though a release date has not been announced.
Search