user permissions

Winsage
September 4, 2026
Microsoft has identified a new malware campaign called TerminalFix that uses fake CAPTCHA prompts to trick Windows users into executing malicious commands. This campaign is a variation of ClickFix attacks and employs deceptive pages that impersonate reputable services like Cloudflare. Instead of traditional CAPTCHA challenges, users are instructed to open PowerShell or Command Prompt and paste in commands, allowing attackers to execute complex scripts more easily. TerminalFix initiates a multi-stage intrusion, granting attackers persistent proxy access to the infected machine, which can lead to further exploitation of the company's network. The campaign relies on social engineering tactics, requiring user compliance with counterfeit verification instructions. Microsoft has released mitigation guidance, recommending restrictions on PowerShell access, monitoring for DLL sideloading, blocking outdated Flash plugins, and enabling cloud-delivered protection in Microsoft Defender Antivirus. The campaign poses significant risks to enterprise networks, but individual users should also be cautious about executing commands requested by websites.
Winsage
August 30, 2026
Windows 11's privacy settings have caused confusion among users regarding the Text and image generation feature, leading to misconceptions that AI processes are actively running and draining system resources. Screenshots showing "zero" requests in the Recent activity section indicate that these features are not consuming RAM. The privacy page is intended to inform users about which applications can use on-device generative AI models, but it does not imply that these applications are currently using AI. The processing occurs on a specialized chip, ensuring that it does not burden the CPU, GPU, or standard RAM. Users can disable the feature by navigating to Settings > Privacy & security > Text and image generation. The terminology used in the operating system has contributed to misunderstandings, and the setting was enabled by default, which has led to skepticism among users due to Microsoft's history of implementing features without clear communication.
AppWizard
August 28, 2026
Developers are encouraged to upgrade to OkHttp 5.5.0 and enable Encrypted Client Hello (ECH) for modern networking practices. Android 17 introduces Local Network Protection, requiring apps to obtain user permission before scanning local networks. Android has implemented Certificate Transparency (CT) by default to log all certificates in a public registry, reducing the risk of fraudulent certificates. Scammers are using portable devices known as “SMS blasters” to target mobile users by forcing them onto less secure 2G networks, allowing phishing texts to bypass modern spam filters.
AppWizard
August 25, 2026
Nothing OS 5.0 is an upcoming major Android software release built on Android 17, featuring a redesigned visual identity, expanded lock screen customization, improved Glyph Interface controls, new widgets, optimized system performance, and AI-powered Essential tools. Open beta testing will start tomorrow with the Nothing Phone 3, and a stable release is expected by mid-October. Key features include a refined design language with a new typeface, adaptive color system for app icons, enhanced lock screen customization with new clock styles, two new widgets for personal organization, a dedicated Glyph Interface app, improved system performance and Bluetooth controls, and expanded Essential AI tools. The update will not be available for the Nothing Phone 1, Nothing Phone 2, and CMF Phone 1, which have reached the end of their software support.
Winsage
August 19, 2026
Windows 11 has introduced individual privacy controls for desktop applications, allowing users to manage access permissions for apps like Chrome and Steam through Settings > Privacy & security. This change enables users to selectively grant or deny access to features such as the microphone, camera, and location for each app, moving away from the previous system where traditional Win32 software was grouped under a single toggle. With the latest Experimental build (26340.9212), apps like Edge and Brave now have separate toggles for microphone, camera, and location access. Additionally, a new centered system dialog prompts users for permission when a desktop app attempts to access the microphone or camera for the first time. These features are still in testing and may not be universally available.
Winsage
August 18, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that ransomware gangs are exploiting a significant vulnerability in the Windows Task Host system, tracked as CVE-2025-60710. This high-severity flaw, affecting Windows 11 and Windows Server 2025, allows local attackers with basic user permissions to escalate their privileges to SYSTEM level. Microsoft patched this vulnerability in November 2025, but it poses a threat to unpatched devices. CISA added CVE-2025-60710 to its list of actively exploited vulnerabilities on April 13 and provided Federal Civilian Executive Branch agencies with a two-week window to secure their systems. CISA warns that such vulnerabilities are frequent attack vectors for malicious actors and urges organizations to apply mitigations or discontinue the use of affected products. Additionally, CISA noted that ransomware groups are also exploiting a Microsoft SharePoint remote code execution vulnerability (CVE-2026-45659), confirmed to be actively exploited in early July. Since November 2021, CISA has identified 383 actively exploited vulnerabilities across various Microsoft products, with 112 being used in ransomware attacks.
AppWizard
July 23, 2026
GitHub will reject command-line support bundle uploads from outdated versions of GitHub Enterprise Server lacking security patches starting August 18, 2026. The npm package @copilot-mcp/apex has been identified as a post-install dropper that installs a macOS infostealer, phishing for sensitive information and maintaining a connection to an attacker's server. A rogue extension on the Microsoft Visual Studio Code marketplace, "Markdown All Pro," impersonates a legitimate tool and opens a backdoor after installation. A phishing campaign targeting Portuguese users delivers the Lampion banking malware, which has been active since 2019. DoubleVerify reports a rise in "AfterCall" apps that exploit user permissions for ad fraud. The GhostCommit attack method hides malicious instructions within PNG images in pull requests. The U.S. government has updated its advisory on Iranian-affiliated cyber activity targeting operational technology devices. An Android app posing as a civil defense alert system has been found to contain malware for data harvesting. An Iranian threat actor is distributing MarkiRAT malware through fake applications. An analysis of 28 AI-coded applications revealed 434 vulnerabilities, prompting Cisco to introduce Antares to identify vulnerabilities in codebases. A Russian-speaking threat actor is dismantling guardrails on AI models to create offensive tools.
Winsage
June 3, 2026
Perplexity has launched Personal Computer for Windows, a desktop software that streamlines user interactions with files, applications, and online resources through a unified interface. It operates natively on Windows, allowing users to manage tasks directly from their machines. The software integrates with Microsoft applications such as Excel, PowerPoint, Word, Outlook, and OneDrive, enabling users to execute tasks without manual data transfer. Users can approve specific local folders for the AI to access, ensuring control over information. The platform supports remote execution from other devices and features Voice Mode for natural language interaction. Personal Computer utilizes over 20 AI models to facilitate complex tasks and includes security features like folder scoping, user permissions, activity logs, and administrative controls for enterprise clients. Access is initially available to paying Max and Enterprise Max subscribers on the waitlist.
Search