Tag: Windows

KB5002907 Paused After Office 2016 and 2019 Lose Activation or Disappear

Microsoft paused KB5002907 after some Office 2016 and 2019 installations lost activation…

Brendan Smith

Kothamine Carries Hostile Commands Through a Legitimate Tunnel

Kothamine uses tailcat for encrypted remote control. The research shows why localhost…

Brendan Smith

Example Domains in Developer Docs Lead to ClickFix and Scams

Manifold found a Windows ClickFix lure and intermittent Mac scams behind familiar…

Daniel Zimmermann

RemotePanel and BoundSiphon Split a ClickFix Attack in Two

A ClickFix command installs persistent RemotePanel access and the BoundSiphon stealer. Why…

Brendan Smith

Storm-2570 Uses Four Ransomware Brands—and the Same Access Tools

Microsoft links Storm-2570 to four ransomware families. Repeated remote access, credential theft…

Brendan Smith

CLOSEDQUORUM: Windows Malware Puts Its Next Move to a Vote

Talos found a Windows implant designed to take votes from four AI…

Brendan Smith

Diagnostic Policy Service High CPU: Find What Keeps It Busy

Trace Diagnostic Policy Service CPU spikes to their trigger. Check the host…

Brendan Smith

Service Host Network Service High Network Usage: Find the Download

Identify the service behind heavy Windows network traffic, separate downloads from peer…

Brendan Smith

State Repository Service High CPU: Find the App Behind It

Trace State Repository Service high CPU to an app, update or Windows…

Brendan Smith

PAYLOAD Turns Windows Group Policy Into a Ransom Demand

PAYLOAD attackers used domain policy to display ransom notes without encrypting Windows…

Brendan Smith

The Gentlemen Turn Stolen Backups Into a Source of Credentials

Talos traced backup images being opened for credential extraction and cloud transfer.…

Brendan Smith

AvastUI.exe Not Opening? Fix Application Errors Safely

AvastUI.exe will not open or shows an application error? Check protection status,…

Brendan Smith

AI Assistant

Hello! 👋 How can I help you today?