Current:Home > News'Criminals are preying on Windows users': Software subject of CISA, cybersecurity warnings -Aspire Financial Strategies
'Criminals are preying on Windows users': Software subject of CISA, cybersecurity warnings
View
Date:2025-04-12 10:34:43
The U.S. Cybersecurity and Infrastructure Security Agency added a vulnerability in Microsoft's Windows 10 software to a list of exploited security weak spots.
CISA said that "Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution," in a listing added to the agency's Known Exploited Vulnerability Catalog Monday.
The listing advised users to stop using software or utilize a patch through Windows.
CISA said that it did not know if the vulnerability, titled CVE-2018-0824, had been used in a ransomware campaign but a CISCO Talos report released Thursday said that a Chinese hacking group utilized the vulnerability in an attack on a Taiwanese government research center. The report said the center was, "likely compromised."
Second organization issues Windows warning
CISA was not the only organization to issue a warning to Windows users Monday.
"Criminals are preying on Windows users yet again, this time in an effort to hit them with a keylogger that can also steal credentials and take screenshots," enterprise technology news site the Register reported Monday.
The outlet reported that FortiGuard Labs, a threat intelligence agency, found an uptick in malware attacks with SnakeKeylogger. The malware is known to steal credentials and record keystrokes in infected machines.
It was originally sold on a subscription basis on Russian crime forums and became a major threat in 2020, according to the Register.
In 2022 Check Point Research, a cyber security firm, warned that the malware, "is usually spread through emails that include docx or xlsx attachments with malicious macros," and through PDF files.
The warnings come on the heels of the "Crowdstrike outage" in July, where a defective software update rendered devices using Windows software useless for hours.
veryGood! (798)
Related
- The Grammy nominee you need to hear: Esperanza Spalding
- In Trump, U.S. Puts a Climate Denier in Its Highest Office and All Climate Change Action in Limbo
- China Wins Approval for Giant Dam Project in World Heritage Site
- Here's why China's population dropped for the first time in decades
- How to watch new prequel series 'Dexter: Original Sin': Premiere date, cast, streaming
- U.S. Nuclear Fleet’s Dry Docks Threatened by Storms and Rising Seas
- China's COVID vaccines: Do the jabs do the job?
- An Ambitious Global Effort to Cut Shipping Emissions Stalls
- Average rate on 30
- Open enrollment for ACA insurance has already had a record year for sign-ups
Ranking
- Small twin
- 3,000+ young children accidentally ate weed edibles in 2021, study finds
- Social isolation linked to an increased risk of dementia, new study finds
- Many ERs offer minimal care for miscarriage. One group wants that to change
- 'Most Whopper
- China Wins Approval for Giant Dam Project in World Heritage Site
- The Bachelor's Colton Underwood Marries Jordan C. Brown in California Wedding
- Bernie Sanders on Climate Change: Where the Candidate Stands
Recommendation
Krispy Kreme offers a free dozen Grinch green doughnuts: When to get the deal
Conspiracy theorists hounded Grant Wahl's family when he died. Now they're back
Global Warming Is Messing with the Jet Stream. That Means More Extreme Weather.
Saudi Arabia’s Solar Ambitions Still Far Off, Even With New Polysilicon Plant
Paula Abdul settles lawsuit with former 'So You Think You Can Dance' co
Author Aubrey Gordon Wants To Debunk Myths About Fat People
Miami police prepare for protesters outside courthouse where Trump is being arraigned
Chicago West Hilariously Calls Out Kim Kardashian’s Cooking in Mother’s Day Card