TerminalFix uses fake Cloudflare CAPTCHA pages to trick users into running PowerShell malware, creating reverse tunnels that ...
TerminalFix tricks victims into running malicious PowerShell commands, launching a multi-stage attack that ends with a ...
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
Bogus software download sites deploy malware that weakens Windows defenses and establishes persistence in China-based ...
Microsoft is warning that a campaign using fake human-verification prompts can turn a user's Windows computer into an entry point for attackers to reach an organization's internal network .
Kerberos unconstrained delegation is one of those Active Directory configurations that can sit quietly for years and still create a disproportionate amount of risk. It is often introduced to make a ...
Threat actors are increasingly exploiting overlooked Active Directory service principal name misconfigurations, making ...
SynkLoader malware is spreading through Microsoft Teams phishing, using a fake Windows lock screen to steal credentials and enable remote access.
Spread the loveWhen you’re trying to keep a project on track, collaboration tools like Microsoft Planner can feel like a ...
A ransomware affiliate weaponized Claude Code to autonomously steal LDAP credentials, backdoor VPNs, and exfiltrate SQL ...
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based ...
Decentralized social network Bluesky was one of the bigger beneficiaries of the exodus from Elon Musk’s X in November 2024, following the U.S. elections. But now, nearly two years later, the social ...