Windows
Windows and Microsoft Defender security: patch releases, exploit reports and mitigations. Each report retains its own dates and evidence.
Scope and limits
Articles are selected by explicit product mentions in their original headlines, within the last 365 days. This is a chronology of our reporting, not a complete incident history. Separate stories do not imply a shared attack campaign. Read each article for its sources, affected versions and uncertainties.
Coverage timeline
BlueMoon Exploit Kit Gives Four Espionage Groups a Shared Chrome-to-Windows Attack Chain
Four espionage groups use BlueMoon exploit kit chaining Chrome V8 flaws and Windows ALPC bug to escape sandbox and deploy payloads.
Microsoft Defender ShieldCrash PoC Claims to Bypass the ShieldBreak Fix
New ShieldCrash PoC allegedly bypasses Microsoft's ShieldBreak fix (CVE-2026-69414), enabling SYSTEM file read via Defender engine.
REVSTEALER-Linked Windows Malware Persists to Steal Crypto, Relay Traffic, and Mine Coins
Elastic links four persistent Windows executables to REVSTEALER that steal crypto wallets, hijack clipboards, proxy traffic, and mine coins.
BraZetsu Turns Infected PCs into Access for Sale to Criminals
BraZetsu malware catalogs infected PCs and sells access via Infected Marketplace, enabling fraud, data theft and corporate intrusions.
WordlistLoader and SynkLoader: Two New Criminal Tools Target Credentials and Network Access
Learn about WordlistLoader and SynkLoader malware that steal credentials and enable network access through phishing and advanced evasion methods.
Windows 11: Microsoft publishes a workaround for game crashes caused by the August update
Microsoft publishes a registry workaround to fix Windows 11 game crashes caused by the August update KB5121003, affecting RGB drivers.
E4del and PINHOLE: FTP Banners Become Hidden Channels for Distributing Windows RATs
E4del and PINHOLE RATs use FTP banners as hidden channels to distribute Windows malware. Campaign active since July 2026, using phishing and dead-drop resolvers.
Windows Named Pipes: The Local Channel That Can Become a Privilege-Escalation Path
Discover how Windows named pipes can be exploited for privilege escalation and key security practices to mitigate risks.
BTR Reforged: Microsoft Defender’s Driver Can Be Weaponized Against Windows Security
BTR Reforged: Abusing Defender's driver to bypass Windows security. Requires admin access, affects Windows 7-11. Presented at Black Hat 2026.
Microsoft Fixes “LegacyHive” Windows Zero-Day with August Patches
Microsoft patches LegacyHive zero-day CVE-2026-62832 in August updates, fixing privilege escalation in Windows User Profile Service. Apply now.
ShieldBreak, the New Zero-Day Exploit That Elevates Windows Users to SYSTEM
ShieldBreak is a zero-day exploit that abuses Microsoft Defender for local privilege escalation to SYSTEM on Windows 11 and Server 2025, with technical analysis and defense tips.
Lazarus Exploits a Windows Zero-Day to Gain SYSTEM Privileges
Check Point Research attributes a cyber-espionage campaign targeting defense and aerospace companies in France, Germany, Brazil, and India to the Lazarus
Lazarus Exploits a Windows Zero-Day in a Fake Job Offer Campaign
Lazarus group exploits Windows zero-day in fake job campaign targeting defense. Microsoft patched CVE-2026-68820; update now.
ShieldBreak: PoC Bypasses Microsoft Defender Patch and Targets SYSTEM Privileges
ShieldBreak PoC bypasses MS Defender patch for CVE-2026-50656, granting SYSTEM access. Tested on Win11 25H2 & Server 2025. Update systems promptly.
Windows Hello for Business Can Be Abused by Malware to Maintain Access to Entra ID
Malware can exploit Windows Hello for Business to maintain persistent access to Microsoft Entra ID without admin privileges. Learn about detection and mitigations.
Compromised QuickFox Installers: FDMTP Backdoor Targets Windows Users
FortiGuard Labs identifies supply chain attack in QuickFox VPN installers, delivering FDMTP backdoor to Windows users since August 2025. Mitigation steps provided.