๐จ ACTIVE EXPLOITATION
- CISA says ransomware gangs are exploiting a Windows Task Host flaw
CISA says ransomware gangs are exploiting a high-severity Windows Task Host vulnerability.- Windows users are affected by a high-severity Windows Task Host vulnerability.
- Ransomware gangs are actively exploiting the flaw.
- CISA flagged the vulnerability as actively exploited in April.
๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
๐ต๏ธ RESEARCH & DEEP DIVES
- Shadow hVNC Gives Attackers Invisible Control of a Second Windows Desktop
Shadow hVNC gives attackers invisible control of a second Windows desktop.- Windows users and enterprise environments are targeted by the Shadow hVNC malware-as-a-service toolkit.
- Version 5.5 steals browser credentials, cookies, session tokens, financial data, crypto-wallet artifacts, and cloud credentials.
- The malware creates a hidden Win32 desktop named RemoteXHidden for attacker-controlled browsers, shells, and payloads.
- Backstage Mode hijacks Chrome profiles and replays cookies through Chrome DevTools Protocol.
- Observed indicators include RemoteXHidden, RemoteXBackstage, MD5 1d04536714bb22a3e909525a7dd627f0, and IPs 195.3.221[.]225 and 62.60.226[.]253.
๐ Source: malbearlabs.com ยท ๐ Coverage: gbhackers.com ยท ๐ via Cyber Security News, cryptika.com (discovered)