Current:Home > My'Criminals are preying on Windows users': Software subject of CISA, cybersecurity warnings -AssetTrainer
'Criminals are preying on Windows users': Software subject of CISA, cybersecurity warnings
View
Date:2025-04-19 04:43:47
The U.S. Cybersecurity and Infrastructure Security Agency added a vulnerability in Microsoft's Windows 10 software to a list of exploited security weak spots.
CISA said that "Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution," in a listing added to the agency's Known Exploited Vulnerability Catalog Monday.
The listing advised users to stop using software or utilize a patch through Windows.
CISA said that it did not know if the vulnerability, titled CVE-2018-0824, had been used in a ransomware campaign but a CISCO Talos report released Thursday said that a Chinese hacking group utilized the vulnerability in an attack on a Taiwanese government research center. The report said the center was, "likely compromised."
Second organization issues Windows warning
CISA was not the only organization to issue a warning to Windows users Monday.
"Criminals are preying on Windows users yet again, this time in an effort to hit them with a keylogger that can also steal credentials and take screenshots," enterprise technology news site the Register reported Monday.
The outlet reported that FortiGuard Labs, a threat intelligence agency, found an uptick in malware attacks with SnakeKeylogger. The malware is known to steal credentials and record keystrokes in infected machines.
It was originally sold on a subscription basis on Russian crime forums and became a major threat in 2020, according to the Register.
In 2022 Check Point Research, a cyber security firm, warned that the malware, "is usually spread through emails that include docx or xlsx attachments with malicious macros," and through PDF files.
The warnings come on the heels of the "Crowdstrike outage" in July, where a defective software update rendered devices using Windows software useless for hours.
veryGood! (8)
Related
- The FBI should have done more to collect intelligence before the Capitol riot, watchdog finds
- Tampa Bay Times keeps publishing despite a Milton crane collapse cutting off access to newsroom
- Ohio State and Oregon has more than Big Ten, College Football Playoff implications at stake
- Christopher Reeve’s kids wanted to be ‘honest, raw and vulnerable’ in new documentary ‘Super/Man’
- SFO's new sensory room helps neurodivergent travelers fight flying jitters
- JD Vance refused five times to acknowledge Donald Trump lost 2020 election in podcast interview
- Fisher-Price recalls over 2 million ‘Snuga Swings’ following the deaths of 5 infants
- Nevada high court to review decision in ex-Raiders coach Jon Gruden’s lawsuit over NFL emails
- Opinion: Gianni Infantino, FIFA sell souls and 2034 World Cup for Saudi Arabia's billions
- Millions still without power after Milton | The Excerpt
Ranking
- Finally, good retirement news! Southwest pilots' plan is a bright spot, experts say
- Audit of Arkansas governor’s security, travel records from State Police says no laws broken
- Hugh Jackman Makes Public Plea After Broadway Star Zelig Williams Goes Missing
- NFL Week 6 bold predictions: Which players, teams will turn heads?
- Why we love Bear Pond Books, a ski town bookstore with a French bulldog 'Staff Pup'
- Massachusetts pharmacist gets up to 15 years in prison for meningitis outbreak deaths
- BaubleBar’s Biggest Custom Sale of the Year Has 25% off Rings, Necklaces, Bracelets & More Holiday Gifts
- Why Eminem Didn’t Initially Believe Daughter Hailie Jade’s Pregnancy News
Recommendation
Off the Grid: Sally breaks down USA TODAY's daily crossword puzzle, Triathlon
An elevator mishap at a Colorado tourist mine killed 1 and trapped 12. The cause is still unknown
Don't want to worry about a 2025 Social Security COLA? Here's what to do.
Tammy Slaton's Doctor Calls Her Transformation Unbelievable As She Surpasses Goal Weight
The FTC says 'gamified' online job scams by WhatsApp and text on the rise. What to know.
Tesla unveils Cybercab driverless model in 'We, Robot' event
Woman lands plane in California after her husband, the pilot, suffers medical emergency
Jury finds ex-member of rock band Mr. Bungle guilty of killing his girlfriend