Cookie Consent by Free Privacy Policy Generator 📌 Microsoft Patches Windows Defender Zero-Day Exploited by DarkMe RAT

🏠 Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeiträge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden Überblick über die wichtigsten Aspekte der IT-Sicherheit in einer sich ständig verändernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch übersetzen, erst Englisch auswählen dann wieder Deutsch!

Google Android Playstore Download Button für Team IT Security



📚 Microsoft Patches Windows Defender Zero-Day Exploited by DarkMe RAT


💡 Newskategorie: Hacking
🔗 Quelle: blackhatethicalhacking.com

Microsoft Patches Windows Defender Zero-Day Exploited by DarkMe RAT




Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos.

Patreon
Reading Time: 3 Minutes

In a recent security development, Microsoft has responded to an active threat by patching a zero-day vulnerability in Windows Defender SmartScreen, which was exploited by a financially motivated threat group to distribute the DarkMe remote access trojan (RAT).

The threat actors, identified as Water Hydra and DarkCasino, were observed leveraging the zero-day (CVE-2024-21412) in attacks targeting foreign exchange traders on New Year’s Eve, according to insights from Trend Micro security researchers.

Describing the vulnerability, Microsoft stated in a security advisory that an unauthenticated attacker could exploit it by sending a specially crafted file to the targeted user, bypassing displayed security checks. However, the attacker relies on social engineering to persuade users to interact with the malicious file.

See Also: So, you want to be a hacker?
Offensive Security, Bug Bounty Courses




Discover your weakest link. Be proactive, not reactive. Cybercriminals need just one flaw to strike.

Security researcher Peter Girnus, credited with reporting the zero-day, revealed that CVE-2024-21412 bypasses another Windows Defender SmartScreen vulnerability (CVE-2023-36025), which was patched during the November 2023 Patch Tuesday.

Targeting Forex Traders

The attackers’ modus operandi involved spearphishing campaigns aimed at forex traders, particularly those engaged in high-stakes currency trading. Exploiting the zero-day, they targeted trading forums and stock trading Telegram channels, enticing victims with malicious stock charts linking to compromised trading information sites.

Trend Micro’s investigation revealed that Water Hydra utilized similar tactics and procedures observed in previous campaigns, exploiting internet shortcuts and WebDAV components to evade SmartScreen protections effectively.




...



📌 Microsoft Ships Antivirus For macOS as Windows Defender Becomes Microsoft Defender


📈 24.73 Punkte

📌 Microsoft Patches Zero-Days Exploited by Russia-Linked Hackers


📈 24.69 Punkte

📌 Microsoft patches three exploited zero-days (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823)


📈 24.69 Punkte

📌 Microsoft patches two zero-days exploited by attackers (CVE-2024-21412, CVE-2024-21351)


📈 24.69 Punkte

📌 Microsoft Patches Two Zero-Days Exploited for Malware Delivery


📈 24.69 Punkte

📌 Microsoft Patches 2 Zero Days Exploited For Malware Delivery


📈 24.69 Punkte

📌 Week in review: Palo Alto Networks firewalls under attack, Microsoft patches two exploited zero-days


📈 24.69 Punkte

📌 Install Latest Windows Update ASAP! Patches Issued for 6 Actively Exploited Zero-Days


📈 24.64 Punkte

📌 Ignite 2022: Microsoft Defender für DevOps & Microsoft Defender CSPM


📈 22.86 Punkte

📌 Windows Defender ATP is dead. Long live Microsoft Defender ATP


📈 22.8 Punkte

📌 Microsoft Defender ATP: Der Windows Defender verteidigt auch Macs


📈 22.8 Punkte

📌 Windows Defender ATP kommt auf den Mac – und wird "Microsoft Defender"


📈 22.8 Punkte

📌 Windows Defender Gets a New Name: Microsoft Defender


📈 22.8 Punkte

📌 Windows Defender wird wohl zum Microsoft Defender umbenannt


📈 22.8 Punkte

📌 Mozilla Patches Two Actively Exploited Firefox Zero-Days


📈 22.76 Punkte

📌 Apple patches three actively exploited iOS zero-days


📈 22.76 Punkte

📌 Google Patches Two More Chrome Zero-Days Exploited in Attacks


📈 22.76 Punkte

📌 Apple Patches Three Actively Exploited Zero-Days, Part of iOS Emergency Update


📈 22.76 Punkte

📌 Apple Patches Two Zero-Days Exploited in the Wild


📈 22.76 Punkte

📌 Apple Patches 3 Zero-Days Possibly Already Exploited


📈 22.76 Punkte

📌 Apple Patches Actively Exploited iOS Zero-Days


📈 22.76 Punkte

📌 Mozilla Patches Firefox Zero Days Exploited At Pwn2Own


📈 22.76 Punkte

📌 Microsoft bestätigt: Der Defender legitime URLs oder Dateien als schädlich gemeldet (Defender Issue DZ534539)


📈 20.93 Punkte

📌 X-Post r/Funny Windows Defender is best Defender.


📈 20.87 Punkte

📌 Defender-Pretender: When Windows Defender Updates Become a Security Risk


📈 20.87 Punkte

📌 Defeat-Defender - Powerful Batch Script To Dismantle Complete Windows Defender Protection And Even Bypass Tamper Protection


📈 20.87 Punkte

📌 Free Darktrack RAT Has the Potential of Being the Best RAT on the Market


📈 20.69 Punkte

📌 Free Darktrack RAT Has the Potential of Being the Best RAT on the Market


📈 20.69 Punkte

📌 Open source RAT collection, and malicious RAT analysis reports.


📈 20.69 Punkte

📌 Medium CVE-2022-31510: Simple-rat project Simple-rat


📈 20.69 Punkte

📌 Powershell-RAT – Gmail Exfiltration RAT


📈 20.69 Punkte

📌 MobiHok RAT, a new Android malware based on old SpyNote RAT


📈 20.69 Punkte

📌 The RAT King “NetSupport RAT” is Back in Action Via fake browser updates


📈 20.69 Punkte

📌 Rafel-Rat - Android Rat Written In Java With WebPanel For Controlling Victims


📈 20.69 Punkte

📌 Microsoft Patches Two Windows Flaws Exploited in Targeted Attacks


📈 20.62 Punkte











matomo