Tag

Windows

All articles tagged with #windows

Windows Defender's Boot Driver Could Be Weaponized to Wipe Security Tools at Startup
technology3 days ago

Windows Defender's Boot Driver Could Be Weaponized to Wipe Security Tools at Startup

Check Point Research disclosed a technique that abuses Microsoft Defender’s built-in boot-time removal driver, BTR.sys, to perform kernel-level file and registry operations and potentially delete Defender components during boot. The driver is embedded in Defender and can be triggered with a PoC tool (BTR_CLI); it requires administrative SeLoadDriverPrivilege, but there is no evidence of real-world abuse yet. This isn’t a traditional software vulnerability but an architectural trust boundary that could be exploited, and Microsoft notes it doesn’t require immediate servicing. Defenses include restricting SeLoadDriverPrivilege and monitoring for specific Sysmon/Windows events, since BTR.sys is hard to blocklist without disrupting Defender.

MacBook Air Shines in Ultralight Showdown Against ThinkPad X1 Carbon
technology9 days ago

MacBook Air Shines in Ultralight Showdown Against ThinkPad X1 Carbon

The article compares the base models of the MacBook Air and Lenovo ThinkPad X1 Carbon Gen 14 Aura Edition, finding the Air at $1,299 generally offers stronger price-to-performance (M5, 16GB RAM, 512GB SSD) and a brighter mini‑LED display, while the ThinkPad at $2,249 provides more RAM (32GB), more ports, and an optional 2.8K OLED 120Hz screen. In benchmarks, the MacBook Air outperforms the ThinkPad, and battery life is competitive (Air ~18 hours video; ThinkPad up to ~19 hours on LCD or ~13 hours with OLED). The verdict: the MacBook Air is the better ultralight value for most buyers, but the ThinkPad remains the choice for Windows users who want more RAM, diverse ports, and OLED options.

Microsoft fixes LegacyHive Windows zero-day after Nightmare Eclipse PoC disclosure
security11 days ago

Microsoft fixes LegacyHive Windows zero-day after Nightmare Eclipse PoC disclosure

Microsoft issued August Patch Tuesday updates to fix CVE-2026-62832, a Windows User Profile Service zero-day nicknamed LegacyHive that could let an authenticated local attacker load another user's registry hive and gain administrator privileges. The Nightmare Eclipse PoC reportedly required credentials, limiting weaponization, and defenders published Defender detection queries while 0Patch released unofficial patches; several related zero-days remain unpatched.

Lazarus Group Exploits Windows Zero-Day to Deploy Backdoor Worldwide
technology12 days ago

Lazarus Group Exploits Windows Zero-Day to Deploy Backdoor Worldwide

North Korea’s Lazarus Group exploited a Windows zero-day (CVE-2026-68820) to gain SYSTEM privileges and install a backdoor named Troy as part of Operation Dream Job, targeting defense and aerospace firms in France, Germany, Brazil and India. The campaign blends social engineering (fake LinkedIn recruiters) with a trojanized SecurityPDF viewer to trigger a DLL side-loading chain, dropping the MISTPEN downloader and ForestTiger/ScoringMathTea for remote access, while hijacking compromised WordPress/SharePoint/Roundcube infrastructure for C2 via Microsoft Graph API/OneDrive and using AFD.sys privilege escalation to stay hidden.

Windows 11 KB5101684 update boosts reliability and speed on low-RAM PCs
technology13 days ago

Windows 11 KB5101684 update boosts reliability and speed on low-RAM PCs

Microsoft’s Windows 11 KB5101684 update adds reliability and performance improvements across versions 24H2/25H2/26H1. It enhances Explorer-related tasks (Jump Lists, recent files), file sharing, and Task View, plus lock/login screen stability and startup responsiveness for Start Menu/Taskbar. The post-update cleanup is lighter, making systems feel faster immediately after install. While benefits are claimed for all RAM levels, devices with 8GB RAM or less should notice the biggest gains in responsiveness.

Active Windows zero-day drives urgent August patch Tuesday across core services
security13 days ago

Active Windows zero-day drives urgent August patch Tuesday across core services

Microsoft’s August Patch Tuesday closes 398 CVEs, including CVE-2026-68820—a use‑after‑free in afd.sys that can escalate from code execution to SYSTEM and is under active exploitation—making it the top priority; four other high‑severity flaws (CVE-2026-62878 in Windows DNS Server, CVE-2026-62893 in Windows Deployment Services, CVE-2026-62815 in Microsoft QUIC, and CVE-2026-59124 in HPC Pack) are unauthenticated RCEs whose exploitation depends on service exposure. The update also finishes a two‑part SharePoint chain (CVE-2026-55040 and CVE-2026-63520) first disclosed by Rapid7. Prioritize systems with exposed DNS/WDS/QUIC/HPC services and ensure on‑prem SharePoint farms apply both July and August fixes to close the chain.

Microsoft Deploys Massive August 2026 Patch Tuesday to Close 400 Flaws, Three Zero-Days
security14 days ago

Microsoft Deploys Massive August 2026 Patch Tuesday to Close 400 Flaws, Three Zero-Days

Microsoft’s August 2026 Patch Tuesday patches roughly 400 vulnerabilities across a broad Microsoft stack, including three zero-days. The fixes span Windows, Office, Azure, Exchange, SharePoint, SQL, PowerShell, and more, with many critical remote code execution and elevation-of-privilege flaws addressed. Organizations should apply the updates promptly to reduce exposure to exploitation.

OEM Windows licensing hike may push PC prices higher as RAM costs surge
technology14 days ago

OEM Windows licensing hike may push PC prices higher as RAM costs surge

Taiwan’s United Daily News reports Microsoft boosted Windows license fees for OEMs by about 7–10%, a sharper rise than the typical single-digit increases, a move that could be passed to consumers via higher PC prices amid ongoing RAM shortages. Consumer Windows licenses stay at $99 for Home and $199 for Pro, and Microsoft did not comment on the report.

Apple to bring iPhone-to-Windows clipboard syncing to Windows PCs
news21 days ago

Apple to bring iPhone-to-Windows clipboard syncing to Windows PCs

Apple plans to enable cross-device clipboard syncing between iPhone and Windows PCs as part of the EU interoperability push, a feature Android users have had for years via Microsoft’s Phone Link and SwiftKey. The implementation uses an iOS extension and Apple’s Accessory Transport Extension framework, and requires user permission for each paired PC. Microsoft pushed for the feature, and Apple notes it’s a major engineering effort that may wrap up in fall 2027, potentially limited to EU users under current rules.

Apple to enable iPhone clipboard sharing with Windows PCs in EU
technology21 days ago

Apple to enable iPhone clipboard sharing with Windows PCs in EU

Apple has agreed in the EU to develop a cross-device clipboard feature that would let iPhone clipboard contents be shared with paired Windows PCs, responding to Microsoft's interoperability request. The plan uses an extension to transfer pasteboard data via the Accessory Notifications and Accessory Transport Extension frameworks, with per-device user consent and reliance on AccessorySetupKit. Development is targeted for completion by fall 2027, with a developer beta before a public release, potentially as part of iOS 28, and the EU scope may limit availability.

Three Attack Vectors Threaten Chrome Passkeys on Windows
security22 days ago

Three Attack Vectors Threaten Chrome Passkeys on Windows

Unit 42 details three post-compromise attack paths—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—that let malware on Windows abuse Chrome's Google Password Manager to sign into passkey-protected accounts, re-enroll devices, or extract the 32-byte Security Domain Secret from memory. The flaws do not break cryptography but target how Chrome stores device keys, re-enrolls devices, and checks user verification. No CVEs are listed and there are no confirmed exploits in the wild as of Aug 3, 2026. Mitigations include requiring userVerification, attesting newly enrolled keys, strengthening re-registration/recovery checks, restricting local passkey state access, and avoiding logging sensitive data. It’s unclear if SDS rotation or revocation is possible with current fixes.

USB Tethering Demystified: How to share your phone’s internet with a PC via USB
technology23 days ago

USB Tethering Demystified: How to share your phone’s internet with a PC via USB

USB tethering lets you share your phone’s cellular data with a computer over a USB cable, often providing a more stable, private connection (and charging the phone) compared to wireless hotspots. On Android, enable USB tethering under Settings > Network & internet > Hotspot & tethering (the USB option must be data-capable and may be greyed out on some cables). On iPhone, connect via USB and enable Personal Hotspot, then accept Trust prompts as needed. Note that Android-to-Mac tethering isn’t supported, and some carriers or plans may limit or charge for tethering; performance also depends on your phone’s cellular signal and cable quality.