Skip to main content
← All Articles

Tag

#Windows Security

21 articles

Advertisement

Weaponizing Defender's BTR.sys to Disable Security Software
MEDIUM
Vulnerabilities

Weaponizing Defender's BTR.sys to Disable Security Software

Attackers can weaponize a legitimate Microsoft Defender driver to delete security software at boot, impacting Windows 7-11.

Runtime Rebel Intel
4 min read · Aug 22, 2026
MEDIUM
Threat Intel

PowerShell and WMI Detection: Analyzing Suspicious Command Lines

Learn to detect obfuscated PowerShell commands and malicious WMI activity through advanced command-line monitoring and log analysis for security teams.

Runtime Rebel Intel
3 min read · Jul 17, 2026
HIGH
Threat Intel

Windows Bind Link Evasion: How to Detect Malware Hiding from EDR

Bitdefender researchers reveal how Windows bind links create filesystem discrepancies to bypass security tools. Learn how to mitigate this evasion technique.

Runtime Rebel Intel
4 min read · Jul 15, 2026
HIGH
Vulnerabilities

Microsoft Patch Tuesday: Addressing 570 Security Flaws

Microsoft released updates for a record 570 security flaws in Windows and other software, with AI aiding discovery. Learn the impact and mitigation.

Runtime Rebel Intel
4 min read · Jul 15, 2026
Microsoft Patches Record 622 Flaws and Two Zero-Days — Patch Now
CRITICAL
Vulnerabilities

Microsoft Patches Record 622 Flaws and Two Zero-Days — Patch Now

Microsoft releases its largest Patch Tuesday ever, addressing 622 vulnerabilities and two zero-days under active attack. Analyze the security impact here.

Runtime Rebel Intel
4 min read · Jul 14, 2026
CRITICAL
Vulnerabilities

Microsoft Defender RoguePlanet Zero-Day Vulnerability Patching Guide

Microsoft addresses the RoguePlanet zero-day in Defender. Learn about the exploitation risks, detection methods, and how to update systems effectively.

Runtime Rebel Intel
4 min read · Jul 9, 2026

Advertisement

HIGH
Threat Intel

WhatsApp Phishing Campaign Deploys VBScript to Compromise PCs

Attackers target WhatsApp users with malicious ZIP files disguised as business documents to deliver VBScript-based remote access malware.

Runtime Rebel Intel
4 min read · Jun 23, 2026
HIGH
Vulnerabilities

June 2026 Patch Tuesday: Microsoft Fixes 200 Flaws — Patch Now

Microsoft’s June 2026 Patch Tuesday addresses a record-breaking 200 vulnerabilities, including 36 critical flaws and several with public exploit code.

Runtime Rebel Intel
3 min read · Jun 11, 2026
CRITICAL
Vulnerabilities

Microsoft Defender 'RoguePlanet' Zero-Day Grants SYSTEM Privileges

Analysis of 'RoguePlanet' zero-day in Microsoft Defender allowing local privilege escalation to SYSTEM, its impact, and critical patch guidance.

Runtime Rebel Intel
4 min read · Jun 10, 2026
INFO
Threat Intel

Microsoft Rust-Based Coreutils for Windows: Security Analysis

Microsoft is adopting Rust-based Coreutils for Windows, offering a memory-safe alternative to legacy GnuWin32 tools. Learn about the security implications.

Runtime Rebel Intel
3 min read · Jun 4, 2026
INFO
Threat Intel

Microsoft Coreutils for Windows: Security and Memory Safety Analysis

Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.

Runtime Rebel Intel
3 min read · Jun 3, 2026
Microsoft MDASH AI Discovers 16 Windows Vulnerabilities
HIGH
Vulnerabilities

Microsoft MDASH AI Discovers 16 Windows Vulnerabilities

Microsoft reveals MDASH, a new AI-driven agentic scanning harness that discovered 16 vulnerabilities in Windows, now fixed in recent Patch Tuesday updates.

Runtime Rebel Intel
3 min read · May 13, 2026
HIGH
Threat Intel

Analysis of the Deep#Door Backdoor Framework and Windows Implants

Technical analysis of Deep#Door, a Python-based backdoor using Discord for C2. Learn about its persistence, stealth, and mitigation strategies.

Runtime Rebel Intel
4 min read · May 1, 2026
HIGH
Vulnerabilities

CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis

CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender's access control mechanisms. Learn how to secure your systems.

Runtime Rebel Intel
4 min read · Apr 23, 2026
HIGH
Vulnerabilities

CVE-2024-36985: Splunk Enterprise RCE via File Upload - Patch Guide

Splunk patches a high-severity RCE vulnerability (CVE-2024-36985) allowing low-privileged users to execute code on Windows-based Enterprise instances.

Runtime Rebel Intel
3 min read · Apr 16, 2026
Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking
INFO
Identity & Access

Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking

Google releases Device Bound Session Credentials (DBSC) in Chrome 146 for Windows to mitigate cookie theft and session hijacking via hardware-backed security.

Runtime Rebel Intel
4 min read · Apr 10, 2026
54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers
HIGH
Malware

54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers

Analysis reveals 54 EDR killer programs abusing 34 signed drivers via BYOVD to neutralize security before ransomware deployment.

Runtime Rebel Intel
3 min read · Mar 19, 2026
Microsoft March Patch Tuesday: 84 Flaws Fixed Including Public Zero-Days
HIGH
Vulnerabilities

Microsoft March Patch Tuesday: 84 Flaws Fixed Including Public Zero-Days

Microsoft releases March security updates for 84 vulnerabilities, including 8 Critical flaws and 2 public zero-days. Patch now to prevent RCE and privilege escalation.

Runtime Rebel Intel
3 min read · Mar 11, 2026
HIGH
Vulnerabilities

March 2026 Patch Tuesday: Microsoft Fixes 77 Vulnerabilities

Microsoft's March 2026 Patch Tuesday addresses 77 vulnerabilities across Windows and other software. Learn about the risks and how to prioritize patching.

Runtime Rebel Intel
3 min read · Mar 11, 2026
Credential Abuse Risks: Solving Microsoft Entra ID MFA Coverage Gaps
HIGH
Identity & Access

Credential Abuse Risks: Solving Microsoft Entra ID MFA Coverage Gaps

Examine how coverage gaps in Microsoft Entra ID and Okta MFA implementations allow attackers to exploit valid credentials within Windows network environments.

Runtime Rebel Intel
3 min read · Mar 5, 2026
HIGH
Vulnerabilities

GetProcessHandleFromHwnd API: UAC Bypass Implications

Investigate the GetProcessHandleFromHwnd API's role in a Quick Assist UAC bypass. Understand its mechanism, UIAccess implications, and defender recommendations.

Runtime Rebel Intel
4 min read · Feb 26, 2026