Current:Home > Scams'Criminals are preying on Windows users': Software subject of CISA, cybersecurity warnings -Keystone Capital Education
'Criminals are preying on Windows users': Software subject of CISA, cybersecurity warnings
View
Date:2025-04-14 10:40:33
The U.S. Cybersecurity and Infrastructure Security Agency added a vulnerability in Microsoft's Windows 10 software to a list of exploited security weak spots.
CISA said that "Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution," in a listing added to the agency's Known Exploited Vulnerability Catalog Monday.
The listing advised users to stop using software or utilize a patch through Windows.
CISA said that it did not know if the vulnerability, titled CVE-2018-0824, had been used in a ransomware campaign but a CISCO Talos report released Thursday said that a Chinese hacking group utilized the vulnerability in an attack on a Taiwanese government research center. The report said the center was, "likely compromised."
Second organization issues Windows warning
CISA was not the only organization to issue a warning to Windows users Monday.
"Criminals are preying on Windows users yet again, this time in an effort to hit them with a keylogger that can also steal credentials and take screenshots," enterprise technology news site the Register reported Monday.
The outlet reported that FortiGuard Labs, a threat intelligence agency, found an uptick in malware attacks with SnakeKeylogger. The malware is known to steal credentials and record keystrokes in infected machines.
It was originally sold on a subscription basis on Russian crime forums and became a major threat in 2020, according to the Register.
In 2022 Check Point Research, a cyber security firm, warned that the malware, "is usually spread through emails that include docx or xlsx attachments with malicious macros," and through PDF files.
The warnings come on the heels of the "Crowdstrike outage" in July, where a defective software update rendered devices using Windows software useless for hours.
veryGood! (9654)
Related
- New data highlights 'achievement gap' for students in the US
- Crews at Baltimore bridge collapse continue meticulous work of removing twisted steel and concrete
- The history of No. 11 seeds in the Final Four after NC State's continues March Madness run
- What U.S. consumers should know about the health supplement linked to 5 deaths in Japan
- Could your smelly farts help science?
- Salah fires title-chasing Liverpool to 2-1 win against Brighton, top of the standings
- Woman suspected of kidnapping and killing girl is beaten to death by mob in Mexican tourist city
- States move to shore up voting rights protections after courts erode federal safeguards
- Small twin
- 2 killed, 3 injured during shootings at separate Houston-area birthday parties
Ranking
- Apple iOS 18.2: What to know about top features, including Genmoji, AI updates
- Are you using dry shampoo the right way? We asked a trichologist.
- Transgender athletes face growing hostility: four tell their stories in their own words
- Age vs. Excellence. Can Illinois find way to knock off UConn in major March Madness upset?
- How to watch new prequel series 'Dexter: Original Sin': Premiere date, cast, streaming
- Kansas lawmakers race to solve big fiscal issues before their spring break
- Denny Hamlin wins NASCAR Cup Series' Toyota Owners 400 at Richmond after late caution flag
- 'One last surge': Disruptive rainstorm soaks Southern California before onset of dry season
Recommendation
Alex Murdaugh’s murder appeal cites biased clerk and prejudicial evidence
2 killed, 3 injured during shootings at separate Houston-area birthday parties
States move to shore up voting rights protections after courts erode federal safeguards
Nick Jonas and Priyanka Chopra's Chef Michael Dane Has a Simple Change to Improve Your Diet
Apple iOS 18.2: What to know about top features, including Genmoji, AI updates
LSU's X-factors vs. Iowa in women's Elite Eight: Rebounding, keeping Reese on the floor
A River in Flux
Gmail revolutionized email 20 years ago. People thought it was Google’s April Fool’s Day joke