Current:Home > Contact'Criminals are preying on Windows users': Software subject of CISA, cybersecurity warnings -MoneyFlow Academy
'Criminals are preying on Windows users': Software subject of CISA, cybersecurity warnings
View
Date:2025-04-25 21:08:54
The U.S. Cybersecurity and Infrastructure Security Agency added a vulnerability in Microsoft's Windows 10 software to a list of exploited security weak spots.
CISA said that "Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution," in a listing added to the agency's Known Exploited Vulnerability Catalog Monday.
The listing advised users to stop using software or utilize a patch through Windows.
CISA said that it did not know if the vulnerability, titled CVE-2018-0824, had been used in a ransomware campaign but a CISCO Talos report released Thursday said that a Chinese hacking group utilized the vulnerability in an attack on a Taiwanese government research center. The report said the center was, "likely compromised."
Second organization issues Windows warning
CISA was not the only organization to issue a warning to Windows users Monday.
"Criminals are preying on Windows users yet again, this time in an effort to hit them with a keylogger that can also steal credentials and take screenshots," enterprise technology news site the Register reported Monday.
The outlet reported that FortiGuard Labs, a threat intelligence agency, found an uptick in malware attacks with SnakeKeylogger. The malware is known to steal credentials and record keystrokes in infected machines.
It was originally sold on a subscription basis on Russian crime forums and became a major threat in 2020, according to the Register.
In 2022 Check Point Research, a cyber security firm, warned that the malware, "is usually spread through emails that include docx or xlsx attachments with malicious macros," and through PDF files.
The warnings come on the heels of the "Crowdstrike outage" in July, where a defective software update rendered devices using Windows software useless for hours.
veryGood! (65)
Related
- Google unveils a quantum chip. Could it help unlock the universe's deepest secrets?
- How Much Does Climate Change Cost? Biden Raises Carbon’s Dollar Value, but Not by Nearly Enough, Some Say
- Investors Pressure Oil Giants on Ocean Plastics Pollution
- The Warming Climates of the Arctic and the Tropics Squeeze the Mid-latitudes, Where Most People Live
- In ‘Nickel Boys,’ striving for a new way to see
- Where did all the Sriracha go? Sauce shortage hiking prices to $70 in online markets
- Power Plants on Indian Reservations Get No Break on Emissions Rules
- An Android update is causing thousands of false calls to 911, Minnesota says
- Rams vs. 49ers highlights: LA wins rainy defensive struggle in key divisional game
- Minorities Targeted with Misinformation on Obama’s Clean Power Plan, Groups Say
Ranking
- Buckingham Palace staff under investigation for 'bar brawl'
- A German Initiative Seeks to Curb Global Emissions of a Climate Super-Pollutant
- Father’s Day Gifts From Miko That Will Make Dad Feel the Opposite of the Way He Does in Traffic
- Kathy Hilton Confirms Whether or Not She's Returning to The Real Housewives of Beverly Hills
- FACT FOCUS: Inspector general’s Jan. 6 report misrepresented as proof of FBI setup
- In the San Joaquin Valley, Nothing is More Valuable than Water (Part 1)
- A Renewable Energy Battle Is Brewing in Arizona, with Confusion as a Weapon
- Exxon Accused of Pressuring Witnesses in Climate Fraud Case
Recommendation
New Mexico governor seeks funding to recycle fracking water, expand preschool, treat mental health
How 90 Day Fiancé's Kenny and Armando Helped Their Family Embrace Their Love Story
Why Kim Cattrall Says Getting Botox and Fillers Isn't a Vanity Thing
Hailey Bieber and Kendall Jenner Set the Record Straight on Feud Rumors
Paula Abdul settles lawsuit with former 'So You Think You Can Dance' co
Midwest Flooding Exposes Another Oil Pipeline Risk — on Keystone XL’s Route
State Department report on chaotic Afghan withdrawal details planning and communications failures
The 9 Best Amazon Air Conditioner Deals to Keep You Cool All Summer Long