Antivirus

Microsoft warns that hackers are exploiting a severe Windows security flaw

Homeland Security issued a rare warning about a Windows Server vulnerability that would give attackers complete control of every computer on a network. The CISA warning said at the time that it assumes active exploitation is occurring in the wild, advising everyone to apply the August patch that Microsoft release. Microsoft on Thursday noted that…

Homeland Security issued a rare warning about a Windows Server vulnerability that would give attackers complete control of every computer on a network.
The CISA warning said at the time that it assumes active exploitation is occurring in the wild, advising everyone to apply the August patch that Microsoft release.
Microsoft on Thursday noted that it has already observed attacks that incorporate the new Windows flaw.

Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) issued a rare emergency alert last week, over what appears to be one of the worst Windows flaws in recent history. Security researchers have identified a vulnerability so severe that it received a maximum severity score (10.0), prompting the agency to advise all governmental agencies to update their computers using Microsoft’s first patch for the issue that was launched a few weeks ago. The issue is so severe that a second update will be released early next year to further deal with the matter.

When CISA released the warning, it advised everyone to “go get patching,” including governmental agencies, state and local governments, private companies, and the general public. It also said at the time that it assumed that “active exploitation of this vulnerability is occurring in the wild.” Microsoft has since confirmed those assumptions, indicating that it found evidence of hackers taking advantage of the Zerologon vulnerability.

Zerologon is very dangerous because it allows malicious individuals to take over computers on a network without stealing any credentials beforehand. The attack involves forging an authentication token for a Netlogon functionality, which then opens doors to everything.

A flaw in a cryptographic authentication scheme makes it all possible. After access is granted to the network, the attackers could infect computers with additional malware and extract data from those computers.

Microsoft tweeted an updated on the matter on Thursday, saying that it is “is actively tracking threat actor activity using exploits for the CVE-2020-1472 Netlogon EoP vulnerability, dubbed Zerologon.” The company said that it observed “attacks where public exploits have been incorporated into attacker playbooks,” without detailing any security incidents.

Despite the warning from CISA, not everyone may have patched their network, which explains why some hackers might already be exploiting the attack. The flaw affects most supported versions of Windows Server, KrebsOnSecurity explains. That includes Server 2008 through Server 2019.

Most Windows users would not even have to deal with the patch themselves. Still, they could be directly impacted if the governmental agency or company they worked at is targeted via a Zerologon attack before admins patch the network.

Microsoft might not be the only company to have observed malicious activity involving the new exploit. Tenable research engineering manager Scott Caveza said that samples of .NET executables called “SharpZeroLogon.exe” had been uploaded to VirusTotal, a Google service that scans suspicious files against antivirus programs.
Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Antivirus

This hidden Windows 11 setting runs Defender scans you missed

Windows Security and its Defender antivirus component carries out quick scans and full scans of the files on your computer at regular, scheduled intervals. However, if the computer is switched off at the scheduled time, the virus scan will not take place. You can use a setting in the registry to specify the number of

Windows Security and its Defender antivirus component carries out quick scans and full scans of the files on your computer at regular, scheduled intervals. However, if the computer is switched off at the scheduled time, the virus scan will not take place.

You can use a setting in the registry to specify the number of days without a scan after which a forced quick scan of the drive will take place…
Read More

Continue Reading
Antivirus

Do you really need an antivirus app on your Android?

You probably don’t need antivirus software on your Android phone, but there are some exceptions…

You probably don’t need antivirus software on your Android phone, but there are some exceptions…
Read More

Continue Reading
Antivirus

The best antivirus software to protect your computer in 2026

Our favorite antivirus software protects your PC, laptop, and mobile devices from malware without costing a fortune…

Our favorite antivirus software protects your PC, laptop, and mobile devices from malware without costing a fortune…
Read More

Continue Reading
Antivirus

Beyond Antivirus: How AI, EDR and XDR Are Redefining Enterprise Cybersecurity

Why intelligent detection, automated response and unified security platforms are redefining enterprise cyber defence Artificial intelligence (AI) has fundamentally changed the cybersecurity landscape. While organisations are harnessing AI to improve productivity, automate workflows and accelerate digital transformation, cybercriminals are using it for faster and highly targeted attacks. …

Why intelligent detection, automated response and unified security platforms are redefining enterprise cyber defence Artificial intelligence (AI) has fundamentally changed the cybersecurity landscape. While organisations are harnessing AI to improve productivity, automate workflows and accelerate digital transformation, cybercriminals are using it for faster and highly targeted attacks. …
Read More

Continue Reading