Security dossiers

Windows

Windows and Microsoft Defender security: patch releases, exploit reports and mitigations. Each report retains its own dates and evidence.

Scope and limits

Articles are selected by explicit product mentions in their original headlines, within the last 365 days. This is a chronology of our reporting, not a complete incident history. Separate stories do not imply a shared attack campaign. Read each article for its sources, affected versions and uncertainties.

Coverage timeline

  1. BlueMoon Exploit Kit Gives Four Espionage Groups a Shared Chrome-to-Windows Attack Chain

    Four espionage groups use BlueMoon exploit kit chaining Chrome V8 flaws and Windows ALPC bug to escape sandbox and deploy payloads.

  2. Microsoft Defender ShieldCrash PoC Claims to Bypass the ShieldBreak Fix

    New ShieldCrash PoC allegedly bypasses Microsoft's ShieldBreak fix (CVE-2026-69414), enabling SYSTEM file read via Defender engine.

  3. REVSTEALER-Linked Windows Malware Persists to Steal Crypto, Relay Traffic, and Mine Coins

    Elastic links four persistent Windows executables to REVSTEALER that steal crypto wallets, hijack clipboards, proxy traffic, and mine coins.

  4. BraZetsu Turns Infected PCs into Access for Sale to Criminals

    BraZetsu malware catalogs infected PCs and sells access via Infected Marketplace, enabling fraud, data theft and corporate intrusions.

  5. WordlistLoader and SynkLoader: Two New Criminal Tools Target Credentials and Network Access

    Learn about WordlistLoader and SynkLoader malware that steal credentials and enable network access through phishing and advanced evasion methods.

  6. Windows 11: Microsoft publishes a workaround for game crashes caused by the August update

    Microsoft publishes a registry workaround to fix Windows 11 game crashes caused by the August update KB5121003, affecting RGB drivers.

  7. E4del and PINHOLE: FTP Banners Become Hidden Channels for Distributing Windows RATs

    E4del and PINHOLE RATs use FTP banners as hidden channels to distribute Windows malware. Campaign active since July 2026, using phishing and dead-drop resolvers.

  8. Windows Named Pipes: The Local Channel That Can Become a Privilege-Escalation Path

    Discover how Windows named pipes can be exploited for privilege escalation and key security practices to mitigate risks.

  9. BTR Reforged: Microsoft Defender’s Driver Can Be Weaponized Against Windows Security

    BTR Reforged: Abusing Defender's driver to bypass Windows security. Requires admin access, affects Windows 7-11. Presented at Black Hat 2026.

  10. Microsoft Fixes “LegacyHive” Windows Zero-Day with August Patches

    Microsoft patches LegacyHive zero-day CVE-2026-62832 in August updates, fixing privilege escalation in Windows User Profile Service. Apply now.

  11. ShieldBreak, the New Zero-Day Exploit That Elevates Windows Users to SYSTEM

    ShieldBreak is a zero-day exploit that abuses Microsoft Defender for local privilege escalation to SYSTEM on Windows 11 and Server 2025, with technical analysis and defense tips.

  12. Lazarus Exploits a Windows Zero-Day to Gain SYSTEM Privileges

    Check Point Research attributes a cyber-espionage campaign targeting defense and aerospace companies in France, Germany, Brazil, and India to the Lazarus

  13. Lazarus Exploits a Windows Zero-Day in a Fake Job Offer Campaign

    Lazarus group exploits Windows zero-day in fake job campaign targeting defense. Microsoft patched CVE-2026-68820; update now.

  14. ShieldBreak: PoC Bypasses Microsoft Defender Patch and Targets SYSTEM Privileges

    ShieldBreak PoC bypasses MS Defender patch for CVE-2026-50656, granting SYSTEM access. Tested on Win11 25H2 & Server 2025. Update systems promptly.

  15. Windows Hello for Business Can Be Abused by Malware to Maintain Access to Entra ID

    Malware can exploit Windows Hello for Business to maintain persistent access to Microsoft Entra ID without admin privileges. Learn about detection and mitigations.

  16. Compromised QuickFox Installers: FDMTP Backdoor Targets Windows Users

    FortiGuard Labs identifies supply chain attack in QuickFox VPN installers, delivering FDMTP backdoor to Windows users since August 2025. Mitigation steps provided.