Tag: Windows zero-day

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
News

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The zero-day exploitation of a recently patched security vulnerability affecting Microsoft Windows has been linked to the North Korean threat actor Lazarus Group, which is responsible for delivering a never-before-seen backdoor that targets defense and aerospace businesses in France, Germany, Brazil, and India. According to Check Point Research, the activity is a part of Operation Dream Job, a long-running cyber espionage and social engineering campaign carried out by hackers backed by Pyongyang that targets professionals worldwide with phony but alluring job offers at companies like Lockheed Martin and Enveil in order to steal sensitive data and install malware by approaching them on platforms like LinkedIn while posing as recruiters in an effort to gain their trust. The attacks ha...
Microsoft fixes Windows zero-day exploited in QakBot malware attacks
News

Microsoft fixes Windows zero-day exploited in QakBot malware attacks

A zero-day vulnerability that was used in campaigns to install QakBot and other malware payloads on susceptible Windows systems has been patched by Microsoft. This privilege escalation flaw, tracked as CVE-2024-30051, is brought on by a heap-based buffer overflow in the core library of the Desktop Window Manager (DWM). After an attack is successful, the attacker can obtain SYSTEM privileges. When generating graphical user interface features like glass window frames and 3D transition animations, the OS can employ hardware acceleration thanks to the Desktop Window Manager Windows service, which was first released in Windows Vista. While looking into another Windows DWM Core Library privilege escalation problem, tracked as CVE-2023-36033 and also used as a zero-day in attacks, Kaspe...