home.social

#windows — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #windows, aggregated by home.social.

  1. 無料の動画編集ソフト「OpenShot 4.0」、カラーグレーディングに対応、ローカルAIも導入/10種類の新エフェクト、ネイティブ「Qt」への移行でタイムラインも快適に
    forest.watch.impress.co.jp/doc

    #forest_watch_impress #OpenShot #OpenShot_4_0 #画像_映像_音楽 #Windows #Mac #Linux

  2. RiseupVPN – a free, open source VPN service created by the Riseup.net collective, which focuses on privacy protection, fighting censorship and encrypting network traffic. archiveapp.org/riseupvpn/ #anonymity #vpn #linux #osx #windows #android

  3. RiseupVPN – a free, open source VPN service created by the Riseup.net collective, which focuses on privacy protection, fighting censorship and encrypting network traffic. archiveapp.org/riseupvpn/ #anonymity #vpn #linux #osx #windows #android

  4. Microsoft alerta para falsos testes humanos que instalam ransomware no Windows. A empresa emitiu um aviso global sobre uma campanha de ciberataques que utiliza ecrãs de verificação humana fraudulentos para enganar funcionários e acessar redes internas. 🚨

    🔗 tugatech.com.pt/t90365-microso

    #alerta #microsoft #ransomware #windows 

  5. 4 Steps to Easily Access #RDP Remote Desktop with #Windows #VPS

    Read this guide, "4 Steps to Easily Access RDP Remote Desktop with Windows VPS" to connect your Windows VPS ...
    Continued 👉 #vpsservers #vpsguide #microsoftremotedesktop #windowsserver #vpsplatform #remotedesktopprotocol #rdpserver

    4 Steps to Easily Access RDP R...

  6. Inside The Gentlemen: Undisclosed TukTuk C2 Framework and EDR Neutralization Research

    Analysis of server infrastructure revealed a complete TukTuk C2 framework (version 2.0) with cross-platform capabilities, including Windows and Linux agents, backend infrastructure, and management panel. The server contained eb.sys matching GentleKiller, along with comprehensive EDR neutralization training materials organized in four progressive lessons covering BYOVD techniques, vulnerable driver hunting, and kernel-level research. DLL sideloading configurations targeting Greenshot, ProcMon, Slack, and Postman were identified. Exfiltrated data included 224 Jira tickets from a global technology company containing information related to U.S. defense organizations and defense contractors, plus credentials from a global healthcare company's Infrastructure-as-Code platform exposing AWS keys, production databases, Azure AD, and Bitbucket access.

    Pulse ID: 6a9869cb21bbf3f757424b7f
    Pulse Link: otx.alienvault.com/pulse/6a986
    Pulse Author: AlienVault
    Created: 2026-09-02 18:24:11

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #EDR #Healthcare #InfoSec #Linux #OTX #OpenThreatExchange #RAT #SideLoading #UK #Windows #bot #AlienVault

  7. Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

    Microsoft Threat Intelligence observed a sophisticated human-operated campaign exploiting Microsoft Teams external collaboration features to impersonate IT helpdesk personnel. Attackers socially engineer users into granting remote access via legitimate remote monitoring tools. Once established, they deploy malicious MSI packages through PowerShell, staging a portable Node.js runtime and obfuscated JavaScript implant for persistent command execution. The campaign progresses through extensive Active Directory reconnaissance, periodic screenshot captures, and lateral movement via Windows Remote Management toward high-value infrastructure including domain controllers. Unlike commodity phishing operations, this hands-on-keyboard intrusion leverages legitimate tooling throughout, blending malicious activity into normal enterprise operations. The reconnaissance patterns and targeting of identity systems indicate precursor activity consistent with data theft, extortion, or ransomware deployment objectives.

    Pulse ID: 6a98ece13ef339971e686ab5
    Pulse Link: otx.alienvault.com/pulse/6a98e
    Pulse Author: AlienVault
    Created: 2026-09-03 03:43:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #DomainController #Extortion #InfoSec #Java #JavaScript #Microsoft #MicrosoftTeams #Nodejs #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RansomWare #Troll #Windows #bot #AlienVault

  8. Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

    Microsoft Threat Intelligence observed a sophisticated human-operated campaign exploiting Microsoft Teams external collaboration features to impersonate IT helpdesk personnel. Attackers socially engineer users into granting remote access via legitimate remote monitoring tools. Once established, they deploy malicious MSI packages through PowerShell, staging a portable Node.js runtime and obfuscated JavaScript implant for persistent command execution. The campaign progresses through extensive Active Directory reconnaissance, periodic screenshot captures, and lateral movement via Windows Remote Management toward high-value infrastructure including domain controllers. Unlike commodity phishing operations, this hands-on-keyboard intrusion leverages legitimate tooling throughout, blending malicious activity into normal enterprise operations. The reconnaissance patterns and targeting of identity systems indicate precursor activity consistent with data theft, extortion, or ransomware deployment objectives.

    Pulse ID: 6a98ece13ef339971e686ab5
    Pulse Link: otx.alienvault.com/pulse/6a98e
    Pulse Author: AlienVault
    Created: 2026-09-03 03:43:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #DomainController #Extortion #InfoSec #Java #JavaScript #Microsoft #MicrosoftTeams #Nodejs #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RansomWare #Troll #Windows #bot #AlienVault

  9. Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

    Microsoft Threat Intelligence observed a sophisticated human-operated campaign exploiting Microsoft Teams external collaboration features to impersonate IT helpdesk personnel. Attackers socially engineer users into granting remote access via legitimate remote monitoring tools. Once established, they deploy malicious MSI packages through PowerShell, staging a portable Node.js runtime and obfuscated JavaScript implant for persistent command execution. The campaign progresses through extensive Active Directory reconnaissance, periodic screenshot captures, and lateral movement via Windows Remote Management toward high-value infrastructure including domain controllers. Unlike commodity phishing operations, this hands-on-keyboard intrusion leverages legitimate tooling throughout, blending malicious activity into normal enterprise operations. The reconnaissance patterns and targeting of identity systems indicate precursor activity consistent with data theft, extortion, or ransomware deployment objectives.

    Pulse ID: 6a98ece13ef339971e686ab5
    Pulse Link: otx.alienvault.com/pulse/6a98e
    Pulse Author: AlienVault
    Created: 2026-09-03 03:43:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #DomainController #Extortion #InfoSec #Java #JavaScript #Microsoft #MicrosoftTeams #Nodejs #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RansomWare #Troll #Windows #bot #AlienVault

  10. Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

    Microsoft Threat Intelligence observed a sophisticated human-operated campaign exploiting Microsoft Teams external collaboration features to impersonate IT helpdesk personnel. Attackers socially engineer users into granting remote access via legitimate remote monitoring tools. Once established, they deploy malicious MSI packages through PowerShell, staging a portable Node.js runtime and obfuscated JavaScript implant for persistent command execution. The campaign progresses through extensive Active Directory reconnaissance, periodic screenshot captures, and lateral movement via Windows Remote Management toward high-value infrastructure including domain controllers. Unlike commodity phishing operations, this hands-on-keyboard intrusion leverages legitimate tooling throughout, blending malicious activity into normal enterprise operations. The reconnaissance patterns and targeting of identity systems indicate precursor activity consistent with data theft, extortion, or ransomware deployment objectives.

    Pulse ID: 6a98ece13ef339971e686ab5
    Pulse Link: otx.alienvault.com/pulse/6a98e
    Pulse Author: AlienVault
    Created: 2026-09-03 03:43:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #DomainController #Extortion #InfoSec #Java #JavaScript #Microsoft #MicrosoftTeams #Nodejs #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RansomWare #Troll #Windows #bot #AlienVault

  11. Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

    Microsoft Threat Intelligence observed a sophisticated human-operated campaign exploiting Microsoft Teams external collaboration features to impersonate IT helpdesk personnel. Attackers socially engineer users into granting remote access via legitimate remote monitoring tools. Once established, they deploy malicious MSI packages through PowerShell, staging a portable Node.js runtime and obfuscated JavaScript implant for persistent command execution. The campaign progresses through extensive Active Directory reconnaissance, periodic screenshot captures, and lateral movement via Windows Remote Management toward high-value infrastructure including domain controllers. Unlike commodity phishing operations, this hands-on-keyboard intrusion leverages legitimate tooling throughout, blending malicious activity into normal enterprise operations. The reconnaissance patterns and targeting of identity systems indicate precursor activity consistent with data theft, extortion, or ransomware deployment objectives.

    Pulse ID: 6a98ece13ef339971e686ab5
    Pulse Link: otx.alienvault.com/pulse/6a98e
    Pulse Author: AlienVault
    Created: 2026-09-03 03:43:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #DomainController #Extortion #InfoSec #Java #JavaScript #Microsoft #MicrosoftTeams #Nodejs #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #RansomWare #Troll #Windows #bot #AlienVault

  12. Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    An active malware campaign utilizes fraudulent software-download websites impersonating trusted vendors to distribute malicious installers. The operation primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The malicious installers deploy malware capable of establishing persistence, disabling Windows Update services, configuring Microsoft Defender exclusions, deleting volume shadow copies, and establishing command-and-control communications. Microsoft attributes this activity with moderate confidence to the Chinese threat cluster Silver Fox, known for using spoofed vendor download pages to distribute remote access trojans. The campaign leverages high-fidelity clones of legitimate vendor websites hosted on Chinese domains, delivering server-side generated payloads through ZIP archives.

    Pulse ID: 6a992140547fc1034bef07a8
    Pulse Link: otx.alienvault.com/pulse/6a992
    Pulse Author: AlienVault
    Created: 2026-09-03 07:26:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #Chinese #CyberSecurity #Education #Government #Healthcare #ICS #InfoSec #Malware #Manufacturing #Microsoft #MicrosoftDefender #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Rust #Trojan #Windows #ZIP #bot #AlienVault

  13. Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    An active malware campaign utilizes fraudulent software-download websites impersonating trusted vendors to distribute malicious installers. The operation primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The malicious installers deploy malware capable of establishing persistence, disabling Windows Update services, configuring Microsoft Defender exclusions, deleting volume shadow copies, and establishing command-and-control communications. Microsoft attributes this activity with moderate confidence to the Chinese threat cluster Silver Fox, known for using spoofed vendor download pages to distribute remote access trojans. The campaign leverages high-fidelity clones of legitimate vendor websites hosted on Chinese domains, delivering server-side generated payloads through ZIP archives.

    Pulse ID: 6a992140547fc1034bef07a8
    Pulse Link: otx.alienvault.com/pulse/6a992
    Pulse Author: AlienVault
    Created: 2026-09-03 07:26:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #Chinese #CyberSecurity #Education #Government #Healthcare #ICS #InfoSec #Malware #Manufacturing #Microsoft #MicrosoftDefender #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Rust #Trojan #Windows #ZIP #bot #AlienVault

  14. Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    An active malware campaign utilizes fraudulent software-download websites impersonating trusted vendors to distribute malicious installers. The operation primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The malicious installers deploy malware capable of establishing persistence, disabling Windows Update services, configuring Microsoft Defender exclusions, deleting volume shadow copies, and establishing command-and-control communications. Microsoft attributes this activity with moderate confidence to the Chinese threat cluster Silver Fox, known for using spoofed vendor download pages to distribute remote access trojans. The campaign leverages high-fidelity clones of legitimate vendor websites hosted on Chinese domains, delivering server-side generated payloads through ZIP archives.

    Pulse ID: 6a992140547fc1034bef07a8
    Pulse Link: otx.alienvault.com/pulse/6a992
    Pulse Author: AlienVault
    Created: 2026-09-03 07:26:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #Chinese #CyberSecurity #Education #Government #Healthcare #ICS #InfoSec #Malware #Manufacturing #Microsoft #MicrosoftDefender #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Rust #Trojan #Windows #ZIP #bot #AlienVault

  15. Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    An active malware campaign utilizes fraudulent software-download websites impersonating trusted vendors to distribute malicious installers. The operation primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The malicious installers deploy malware capable of establishing persistence, disabling Windows Update services, configuring Microsoft Defender exclusions, deleting volume shadow copies, and establishing command-and-control communications. Microsoft attributes this activity with moderate confidence to the Chinese threat cluster Silver Fox, known for using spoofed vendor download pages to distribute remote access trojans. The campaign leverages high-fidelity clones of legitimate vendor websites hosted on Chinese domains, delivering server-side generated payloads through ZIP archives.

    Pulse ID: 6a992140547fc1034bef07a8
    Pulse Link: otx.alienvault.com/pulse/6a992
    Pulse Author: AlienVault
    Created: 2026-09-03 07:26:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #Chinese #CyberSecurity #Education #Government #Healthcare #ICS #InfoSec #Malware #Manufacturing #Microsoft #MicrosoftDefender #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Rust #Trojan #Windows #ZIP #bot #AlienVault

  16. Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    An active malware campaign utilizes fraudulent software-download websites impersonating trusted vendors to distribute malicious installers. The operation primarily targets China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors. The malicious installers deploy malware capable of establishing persistence, disabling Windows Update services, configuring Microsoft Defender exclusions, deleting volume shadow copies, and establishing command-and-control communications. Microsoft attributes this activity with moderate confidence to the Chinese threat cluster Silver Fox, known for using spoofed vendor download pages to distribute remote access trojans. The campaign leverages high-fidelity clones of legitimate vendor websites hosted on Chinese domains, delivering server-side generated payloads through ZIP archives.

    Pulse ID: 6a992140547fc1034bef07a8
    Pulse Link: otx.alienvault.com/pulse/6a992
    Pulse Author: AlienVault
    Created: 2026-09-03 07:26:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #China #Chinese #CyberSecurity #Education #Government #Healthcare #ICS #InfoSec #Malware #Manufacturing #Microsoft #MicrosoftDefender #OTX #OpenThreatExchange #RAT #RemoteAccessTrojan #Rust #Trojan #Windows #ZIP #bot #AlienVault

  17. GDID (Microsoftin estämätön yksilöllisen PC:n seuranta) pärähti laajemmin esiin oikeusjutun tiimoilla. Onko Linuxissa sama...? 🙂 👉 linux.blogaaja.fi/gdid/

    #GDID #Windows #Microsoft #tietoturva #Linux #blogi #PC #Suomi

  18. borgbackup 2.0.0b24 was just released!

    Contains a few new features and a lot of fixes, please check the change log and help testing:

    github.com/borgbackup/borg/rel

    #linux #freebsd #openbsd #netbsd #macOS #windows #python

  19. borgbackup 2.0.0b24 was just released!

    Contains a few new features and a lot of fixes, please check the change log and help testing:

    github.com/borgbackup/borg/rel

    #linux #freebsd #openbsd #netbsd #macOS #windows #python

  20. borgbackup 2.0.0b24 was just released!

    Contains a few new features and a lot of fixes, please check the change log and help testing:

    github.com/borgbackup/borg/rel

    #linux #freebsd #openbsd #netbsd #macOS #windows #python

  21. borgbackup 2.0.0b24 was just released!

    Contains a few new features and a lot of fixes, please check the change log and help testing:

    github.com/borgbackup/borg/rel

    #linux #freebsd #openbsd #netbsd #macOS #windows #python

  22. borgbackup 2.0.0b24 was just released!

    Contains a few new features and a lot of fixes, please check the change log and help testing:

    github.com/borgbackup/borg/rel