Current:Home > Stocks'Criminals are preying on Windows users': Software subject of CISA, cybersecurity warnings -MacroWatch
'Criminals are preying on Windows users': Software subject of CISA, cybersecurity warnings
Ethermac View
Date:2025-04-07 01:24:07
The U.S. Cybersecurity and Infrastructure Security Agency added a vulnerability in Microsoft's Windows 10 software to a list of exploited security weak spots.
CISA said that "Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution," in a listing added to the agency's Known Exploited Vulnerability Catalog Monday.
The listing advised users to stop using software or utilize a patch through Windows.
CISA said that it did not know if the vulnerability, titled CVE-2018-0824, had been used in a ransomware campaign but a CISCO Talos report released Thursday said that a Chinese hacking group utilized the vulnerability in an attack on a Taiwanese government research center. The report said the center was, "likely compromised."
Second organization issues Windows warning
CISA was not the only organization to issue a warning to Windows users Monday.
"Criminals are preying on Windows users yet again, this time in an effort to hit them with a keylogger that can also steal credentials and take screenshots," enterprise technology news site the Register reported Monday.
The outlet reported that FortiGuard Labs, a threat intelligence agency, found an uptick in malware attacks with SnakeKeylogger. The malware is known to steal credentials and record keystrokes in infected machines.
It was originally sold on a subscription basis on Russian crime forums and became a major threat in 2020, according to the Register.
In 2022 Check Point Research, a cyber security firm, warned that the malware, "is usually spread through emails that include docx or xlsx attachments with malicious macros," and through PDF files.
The warnings come on the heels of the "Crowdstrike outage" in July, where a defective software update rendered devices using Windows software useless for hours.
veryGood! (56123)
Related
- Realtor group picks top 10 housing hot spots for 2025: Did your city make the list?
- The NCAA looks to weed out marijuana from its banned drug list
- Is gun violence an epidemic in the U.S.? Experts and history say it is
- OceanGate CEO Stockton Rush said in 2021 he'd broken some rules in design of Titan sub that imploded
- The White House is cracking down on overdraft fees
- Nearly a year later, most Americans oppose Supreme Court's decision overturning Roe
- Exxon’s Sitting on Key Records Subpoenaed in Climate Fraud Investigation, N.Y. Says
- Consumer Group: Solar Contracts Force Customers to Sign Away Rights
- Off the Grid: Sally breaks down USA TODAY's daily crossword puzzle, Triathlon
- California Utility Says Clean Energy Will Replace Power From State’s Last Nuclear Plant
Ranking
- How to watch new prequel series 'Dexter: Original Sin': Premiere date, cast, streaming
- How to protect yourself from poor air quality
- In Cities v. Fossil Fuels, Exxon’s Allies Want the Accusers Investigated
- Opioid settlement payouts are now public — and we know how much local governments got
- Federal appeals court upholds $14.25 million fine against Exxon for pollution in Texas
- American Climate Video: On a Normal-Seeming Morning, the Fire Suddenly at Their Doorstep
- Afghan evacuee child with terminal illness dies while in federal U.S. custody
- Sarah, the Duchess of York, undergoes surgery following breast cancer diagnosis
Recommendation
Most popular books of the week: See what topped USA TODAY's bestselling books list
How Pruitt’s New ‘Secret Science’ Policy Could Further Undermine Air Pollution Rules
Ohio River May Lose Its Regional Water Quality Standards, Vote Suggests
How a secret Delaware garden suddenly reemerged during the pandemic
Romantasy reigns on spicy BookTok: Recommendations from the internet’s favorite genre
Premature Birth Rates Drop in California After Coal and Oil Plants Shut Down
Top Democrats, Republicans offer dueling messages on abortion a year after Roe overturned
Rust armorer facing an additional evidence tampering count in fatal on-set shooting