ZeroHour

Source: Infosecurity Magazine

7 stories in the last 30d

Microsoft Releases Emergency Patch to Fix RDS Snafu

Microsoft's out-of-band KB5129195 fixes September Patch Tuesday regressions breaking RDS connections, Hyper-V shared folders, and USB audio.

Microsoft released cumulative out-of-band update KB5129195 on September 14, 2026, fixing RDS instability causing failing RDP connections, sign-in issues, and hanging servers. The patch also resolves Hyper-V Plan9 shared-folder failures affecting WSL and Claude Cowork, plus USB Audio Class 1.0 device failures. This is Microsoft's sixth emergency patch after a September Patch Tuesday that fixed a record 974 CVEs.

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

Attackers keep distributing WeedHack malware through fake Minecraft clients even though the original infrastructure was taken down in July.

A threat actor continues distributing WeedHack malware to Minecraft players via fake game clients. The campaign persists despite the takedown of the malware's original infrastructure in July, indicating resilient or reconstituted distribution infrastructure.

Infosecurity Magazine · 21d agoMalware in the wild1

New Agent Tesla Malware Variant Boosts Evasion Capabilities

KnowBe4 documented an Agent Tesla v4 campaign using emoji-based code obfuscation to evade detection.

KnowBe4 researchers reported a campaign distributing Agent Tesla v4, a long-running Windows keylogger and infostealer. The new variant uses emoji-based code obfuscation, a novel technique, to hinder static analysis and evade security tooling. Defenders should watch for behavioral indicators such as credential theft and unusual process activity.

Infosecurity Magazine · 25d agoMalware in the wild

Def Con Attendees Targeted by Persistent Phishing Campaign

Huntress reports a persistent and elaborate phishing campaign targeting attendees following the Def Con security conference.

A Huntress researcher documented being targeted by an elaborate and persistent phishing scam after attending Def Con. The campaign specifically went after conference attendees, suggesting deliberate targeting of the security community. Details of the social engineering approach and persistence were shared.

Infosecurity Magazine · 26d agoPhishing & fraud

Hacked Voice Remote Becomes

Hackers compromised a voice-controlled remote control and repurposed it, highlighting security gaps in connected consumer devices.

Infosecurity Magazine's headline indicates a voice-controlled remote was hacked and turned to another purpose. The full article text was unavailable, so technical details, victim, and actor remain unconfirmed. The item underscores risks around consumer IoT and smart-home peripherals.

Infosecurity Magazine · 27d agoThreat actor in the wild

Manufacturing Top Targeted Orange

Orange threat data reportedly shows manufacturing is the most targeted sector, highlighting elevated attack pressure on industrial organizations.

The headline suggests Orange Cyberdefense telemetry ranks manufacturing as the most targeted sector. The article text was unavailable, so the underlying metrics and time frame are unconfirmed. The finding is relevant to defenders prioritizing industrial and manufacturing environments.

Infosecurity Magazine · 27d agoThreat actor

Online Exam Tool Suffers Data

An online exam tool reportedly suffered a data breach, potentially exposing student or user information, according to Infosecurity Magazine.

Infosecurity Magazine published a report indicating that an online examination platform suffered a data breach. The available metadata does not include the vendor name, number of affected users, or the types of data exposed. Scope and impact cannot be fully assessed without the full article text.

Infosecurity Magazine · 29d agoData breach