CISA warns of active exploitation of a critical remote code execution vulnerability in the Windows Internet Key Exchange Service Extensions, enabling attacker code execution without user interaction.
CISA confirms ransomware groups are actively exploiting a high-severity Windows Task Host vulnerability, posing increased risk to enterprise environments.
North Korea's Lazarus Group exploited a recently patched Windows zero-day to deploy a new backdoor targeting defense and aerospace firms as part of Operation Dream Job.
The DOUBLECUP loader uses ClickFix attacks to embed malware within PNG images cached by browsers on Windows and macOS, complicating detection.
CERT-UA has identified a campaign where a fake Notepad++ plugin delivers MATCHBOIL.V2 malware, linked to the Russia-aligned UAC-0099 threat group targeting Windows systems.