ZeroHour

Search: “Windows 10”

6 stories in the last 24h

Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts

Microsoft's Defender Antivirus update 4.18.26080.4 fixes false 'Defender Antivirus is turned off' alerts affecting all supported Windows client and server versions.

Microsoft confirmed in a Windows release health dashboard update that a known issue causing erroneous 'Microsoft Defender Antivirus is turned off' notifications is fixed in the Defender Antivirus update (version 4.18.26080.4) released September 17. The bug affected all supported Windows client and server versions, including Windows 11 26H1 and Windows Server 2025, and triggered alerts even when the antivirus was active and notification settings were disabled. Microsoft had acknowledged the issue in late August after it appeared in the Windows Insider Release Preview channel since at least June.

Steam Windows 0-Day Vulnerability Allows Users to Silently Escalate to Full SYSTEM Privileges

A public BrokenPipe PoC exploits a signature-coverage flaw in Steam's Windows service, letting unprivileged local users gain NT AUTHORITY\SYSTEM without a patch or CVE.

Researcher KillaBoi published the BrokenPipe PowerShell proof of concept on September 14, 2026, targeting steamservice.exe, Steam's privileged Windows client service. The flaw is a signature-coverage gap: the service accepts a caller-controlled installation root alongside a genuine Valve-signed install-script VDF, causing the SYSTEM-level service to execute a relocated attacker-chosen launcher. Testing reportedly succeeded on Steam 10.96.30.42 on recent 64-bit Windows 10 and Windows 11 builds, returning whoami output of NT AUTHORITY\SYSTEM (S-1-5-18). Valve was reportedly aware since March 2026, the HackerOne submission was marked duplicate, and no CVE, advisory, or fix exists at publication time.

Cyber Security Newsupdated · 9h agofirst · 10h agoVulnerability 2 sources

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

SANS dissects a LausivLoader JavaScript malspam sample that passes staged payload file paths to PowerShell via process environment variables.

SANS analyzed a LausivLoader JavaScript sample caught in a customer's mail gateway from an August malspam campaign impersonating a fiber-optic procurement inquiry. The roughly 613 KB attachment (28/55 VirusTotal detections) hides code among 450 junk comment lines, drops two files into a randomized %TEMP% directory, and passes their paths to a PowerShell payload via process environment variables Kv7408 and Kv562. The final command launches PowerShell through conhost.exe with a Base64-encoded command; the script also copies itself and attempts to register a scheduled task.

SANS Internet Storm Center · 23h agoMalware in the wild

12 Best Multi-Cloud Security Platforms Compared (2026): Features & Pricing

A buyer's guide compares pricing and features of 12 multi-cloud security platforms including Wiz, Prisma Cloud, FortiCNAPP, and Defender for Cloud.

The GBHackers roundup profiles 12 multi-cloud security platforms, including Wiz, Fortinet FortiCNAPP, Palo Alto Prisma Cloud, Sysdig, Microsoft Defender for Cloud, Uptycs, and Check Point CloudGuard. It focuses on cross-cloud billing parity, connector fees, ELA absorption, and negotiation tactics for procurement teams. The article notes Ermetic has consolidated into Tenable Cloud Security and that Google's acquisition of Wiz is finalized.

GBHackers · 5h agoTools 10 sources

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Researchers discovered WeaselBiscuit, a stripped-down JavaScript stealer delivered via 13 malicious npm packages, harvesting Chrome extension storage with suspected DPRK links.

OpenSourceMalware identified 13 npm packages, including @biz44/id10-client and process-tailwind, delivering a previously undocumented stealer named WeaselBiscuit. Triggered on npm import, a loader.js pulls the payload from an Npoint dead drop, executes it in memory, and harvests Chrome extension storage (LevelDB) on Windows, macOS, and Linux, with clipboard and keylogging on Windows via C2 at 103.170.217.184:8787. It shares tradecraft with DPRK Contagious Interview's BeaverTail and OtterCookie, including Npoint.io usage and numerical campaign IDs, but definitive attribution is not established.

The Hacker News · 3h agoMalware in the wild

Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites

Attackers compromised Brevo-hosted JavaScript to deliver a WordPress backdoor and ClickFix payloads across 100,000+ websites, exposing visitors and admins.

Sansec found injected script tags loading f.js from attacker-controlled subdomains of sendibt1.com appended to legitimate Brevo resources, with PublicWWW listing 114,371 pages referencing Brevo assets. During a September 14 window (16:05:18–20:12:53 UTC), the conditional payload installed a plugin from cdn10.sendibt1.com/p/wm.zip into WordPress admin sessions and showed other visitors a fake human-verification ClickFix overlay instructing them to run pasted commands. Evidence, including an August 25 SSL certificate for cdn.sendibt1.com and Cloudflare DNS usage, suggests a possible compromise of Brevo's Cloudflare environment, unconfirmed by Brevo. Brevo separately disclosed a September 10 SAML SSO incident in which an attacker accessed 138 accounts, sent phishing from six, and exported contacts from 43.

GBHackersupdated · 4h agofirst · 7h agoMalware in the wild 5 sources