Windows systems

Winsage
August 22, 2026
Windows 11 will remove the Windows Management Instrumentation Command-line (WMIC) tool in the upcoming September 2026 Update, marking its complete elimination after being deprecated in earlier versions. Testing of early builds shows that WMIC is no longer accessible, with attempts to use it resulting in a "command not recognized" error. Previously, WMIC was available as an optional feature, but it will no longer be included or reactivatable in the new update. Microsoft stated that this removal aims to improve the security and reliability of Windows, as WMIC has been exploited by cybercriminals for attacks. The September 2026 Update will also introduce other enhancements, including the ability to disable Bing in Windows Search and improvements in app speed.
Winsage
August 22, 2026
Check Point Research revealed a technique that uses the boot-time remediation driver BTR.sys, part of Windows Defender, to execute kernel-level operations on Windows systems from Windows 7 to Windows 11 25H2. This method does not exploit software vulnerabilities but leverages BTR.sys, which is designed to remove locked malware components. Researchers reverse-engineered its undocumented protocol, leading to the creation of a proof-of-concept tool, BTR_CLI, that can install the driver as a service without standard management protocols. Once operational, BTR.sys can delete or move files, modify registry entries, and remove security binaries, including parts of Defender, during a specific period when the file system is writable. To exploit this technique, an attacker needs administrator privileges, specifically SeLoadDriverPrivilege. Although Microsoft does not consider this a critical issue due to the requirement of pre-existing administrative access, it highlights a significant potential vulnerability. There have been no documented real-world attacks using this technique.
Winsage
August 20, 2026
Microsoft is investigating reports of game stability issues following the August Patch Tuesday update for Windows 11, specifically the release of KB5121003 for versions 24H2 and 25H2. Users have reported that certain games may become unresponsive, unexpectedly close, or trigger an "EXCEPTIONACCESSVIOLATION" error, leading to device restarts. Affected titles include ARC Raiders, MARVEL Tōkon: Fighting Souls, and The Finals. Microsoft has not confirmed if the issues are caused by their update but is looking into the situation. The update addressed 421 Microsoft CVEs, with 236 affecting Windows systems. Microsoft has also tightened its stance on outdated kernel drivers and initiated the Driver Quality Initiative to enhance OS stability.
Tech Optimizer
August 18, 2026
Executing files directly from the temporary download folder is the primary gateway for infostealers targeting Windows systems, accounting for approximately 35% of analyzed infections. The second most common entry point is C:WindowsMicrosoft.NETFramework, appearing in 32% of cases and associated with advanced tactics like process injection. The findings are based on a report by Kaspersky, which analyzed five million records from the dark web. Malicious files often disguise themselves as legitimate software, such as fake codecs or program activators. Kaspersky recommends monitoring exposed assets and not disabling antivirus software during installations.
Winsage
August 13, 2026
Nightmare Eclipse has released a new zero-day exploit called ShieldBreak, which can bypass Microsoft's RoguePlanet patch (CVE-2026-50656) and allow attackers to gain SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems. The exploit has been confirmed by security expert Kevin Beaumont, who provided detection methods for it. ShieldBreak is the tenth zero-day from Nightmare Eclipse since April and was released shortly after Microsoft's monthly Patch Tuesday. The exploit allows local privilege escalation and has a 100% success rate on the latest version of Windows 11 and Windows Server 2025, while Windows 10 remains vulnerable. Microsoft is aware of the vulnerability and is investigating it, emphasizing the importance of coordinated vulnerability disclosure. Previous exploits from Nightmare Eclipse include LegacyHive and GreatXML, with earlier vulnerabilities having been patched but recent ones still unaddressed. Microsoft had threatened legal action against Nightmare Eclipse in May but later reconsidered its approach to vulnerability disclosure.
Search