Patch PowerShell to Fix WDAC Exploit

Microsoft announced a patch for PowerShell 7 that fixes two vulnerabilities allowing attackers to bypass WDAC (Windows Defender Application Control) enforcement and gain access to credentials written in plain text.…
Phishing-as-a-Service in  limelight

Phishing-as-a-Service in limelight

Microsoft’s security team has detected a large-scale operation that provides built-in hosting and email-sending phishing services to cybercriminals via a portal dubbee BulletProofLink. Array of phishing templates available for evading…
Zloader defends.. Evades Defender

Zloader defends.. Evades Defender

An ongoing Zloader campaign uses a new infection chain to disable Microsoft Defender Antivirus to evade detection. The attackers have also changed the malware delivery vector from spam or phishing…
Windows blocks PUA

Windows blocks PUA

Microsoft’s Windows Defender functionality has significantly improved since the release of Windows 10 in 2015. With Windows 10 version 2004 (May 2020 Update), Microsoft added a new optional setting that…
BazaCall  📞 Dials to Harm

BazaCall 📞 Dials to Harm

Microsoft is warning Office users of a new malware campaign, called BazaCall involving fake subscriptions, fraudulent call centers, and a malicious Excel spreadsheet identified had human operated attacks and Ransomware…
Defender Blocks Proxy Logon

Defender Blocks Proxy Logon

Microsoft announced that Defender Antivirus and System Center Endpoint Protection now provide automatic protection against attacks exploiting the recently disclosed ProxyLogon vulnerabilities in Microsoft Exchange. “Today, we have taken an…