<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Windows Security</title><description>Cybersecurity articles tagged #Windows Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Weaponizing Defender&apos;s BTR.sys to Disable Security Software</title><link>https://runtimerebel.com/blog/weaponizing-defender-s-btr-sys-to-disable-security-software</link><guid isPermaLink="true">https://runtimerebel.com/blog/weaponizing-defender-s-btr-sys-to-disable-security-software</guid><description>Attackers can weaponize a legitimate Microsoft Defender driver to delete security software at boot, impacting Windows 7-11.</description><pubDate>Sat, 22 Aug 2026 08:17:55 GMT</pubDate><category>Microsoft Defender</category><category>Kernel Driver</category><category>Defense Evasion</category><category>Check Point Research</category><category>Windows Security</category></item><item><title>PowerShell and WMI Detection: Analyzing Suspicious Command Lines</title><link>https://runtimerebel.com/blog/powershell-and-wmi-detection-analyzing-suspicious-command-lines</link><guid isPermaLink="true">https://runtimerebel.com/blog/powershell-and-wmi-detection-analyzing-suspicious-command-lines</guid><description>Learn to detect obfuscated PowerShell commands and malicious WMI activity through advanced command-line monitoring and log analysis for security teams.</description><pubDate>Fri, 17 Jul 2026 06:18:20 GMT</pubDate><category>PowerShell</category><category>WMI</category><category>Command Line Analysis</category><category>Windows Security</category><category>Detection Engineering</category></item><item><title>Windows Bind Link Evasion: How to Detect Malware Hiding from EDR</title><link>https://runtimerebel.com/blog/windows-bind-link-evasion-how-to-detect-malware-hiding-from-edr</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-bind-link-evasion-how-to-detect-malware-hiding-from-edr</guid><description>Bitdefender researchers reveal how Windows bind links create filesystem discrepancies to bypass security tools. Learn how to mitigate this evasion technique.</description><pubDate>Wed, 15 Jul 2026 13:48:18 GMT</pubDate><category>Windows Security</category><category>Bind Link</category><category>EDR Evasion</category><category>Bitdefender</category><category>Filesystem Attacks</category></item><item><title>Microsoft Patch Tuesday: Addressing 570 Security Flaws</title><link>https://runtimerebel.com/blog/microsoft-patch-tuesday-addressing-570-security-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-patch-tuesday-addressing-570-security-flaws</guid><description>Microsoft released updates for a record 570 security flaws in Windows and other software, with AI aiding discovery. Learn the impact and mitigation.</description><pubDate>Wed, 15 Jul 2026 06:16:23 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Vulnerability Management</category><category>Software Updates</category><category>AI</category><category>Windows Security</category></item><item><title>Microsoft Patches Record 622 Flaws and Two Zero-Days — Patch Now</title><link>https://runtimerebel.com/blog/microsoft-patches-record-622-flaws-and-two-zero-days-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-patches-record-622-flaws-and-two-zero-days-patch-now</guid><description>Microsoft releases its largest Patch Tuesday ever, addressing 622 vulnerabilities and two zero-days under active attack. Analyze the security impact here.</description><pubDate>Tue, 14 Jul 2026 21:01:48 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Zero-Day</category><category>Windows Security</category><category>RCE</category><category>Privilege Escalation</category></item><item><title>Microsoft Defender RoguePlanet Zero-Day Vulnerability Patching Guide</title><link>https://runtimerebel.com/blog/microsoft-defender-rogueplanet-zero-day-vulnerability-patching-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-rogueplanet-zero-day-vulnerability-patching-guide</guid><description>Microsoft addresses the RoguePlanet zero-day in Defender. Learn about the exploitation risks, detection methods, and how to update systems effectively.</description><pubDate>Thu, 09 Jul 2026 07:41:23 GMT</pubDate><category>Microsoft Defender</category><category>RoguePlanet</category><category>Zero-Day</category><category>Windows Security</category><category>Endpoint Protection</category></item><item><title>WhatsApp Phishing Campaign Deploys VBScript to Compromise PCs</title><link>https://runtimerebel.com/blog/whatsapp-phishing-campaign-deploys-vbscript-to-compromise-pcs</link><guid isPermaLink="true">https://runtimerebel.com/blog/whatsapp-phishing-campaign-deploys-vbscript-to-compromise-pcs</guid><description>Attackers target WhatsApp users with malicious ZIP files disguised as business documents to deliver VBScript-based remote access malware.</description><pubDate>Tue, 23 Jun 2026 09:27:07 GMT</pubDate><category>WhatsApp</category><category>VBScript</category><category>AsyncRAT</category><category>Social Engineering</category><category>Windows Security</category></item><item><title>June 2026 Patch Tuesday: Microsoft Fixes 200 Flaws — Patch Now</title><link>https://runtimerebel.com/blog/june-2026-patch-tuesday-microsoft-fixes-200-flaws-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/june-2026-patch-tuesday-microsoft-fixes-200-flaws-patch-now</guid><description>Microsoft’s June 2026 Patch Tuesday addresses a record-breaking 200 vulnerabilities, including 36 critical flaws and several with public exploit code.</description><pubDate>Thu, 11 Jun 2026 09:40:38 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Windows Security</category><category>RCE</category><category>Exploit Code</category></item><item><title>Microsoft Defender &apos;RoguePlanet&apos; Zero-Day Grants SYSTEM Privileges</title><link>https://runtimerebel.com/blog/microsoft-defender-rogueplanet-zero-day-grants-system-privileges</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-defender-rogueplanet-zero-day-grants-system-privileges</guid><description>Analysis of &apos;RoguePlanet&apos; zero-day in Microsoft Defender allowing local privilege escalation to SYSTEM, its impact, and critical patch guidance.</description><pubDate>Wed, 10 Jun 2026 01:03:15 GMT</pubDate><category>Microsoft Defender</category><category>RoguePlanet</category><category>Privilege Escalation</category><category>Zero-Day</category><category>Windows Security</category></item><item><title>Microsoft Rust-Based Coreutils for Windows: Security Analysis</title><link>https://runtimerebel.com/blog/microsoft-rust-based-coreutils-for-windows-security-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-rust-based-coreutils-for-windows-security-analysis</guid><description>Microsoft is adopting Rust-based Coreutils for Windows, offering a memory-safe alternative to legacy GnuWin32 tools. Learn about the security implications.</description><pubDate>Thu, 04 Jun 2026 09:27:24 GMT</pubDate><category>Microsoft</category><category>Rust</category><category>Coreutils</category><category>Memory Safety</category><category>Windows Security</category></item><item><title>Microsoft Coreutils for Windows: Security and Memory Safety Analysis</title><link>https://runtimerebel.com/blog/microsoft-coreutils-for-windows-security-and-memory-safety-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-coreutils-for-windows-security-and-memory-safety-analysis</guid><description>Microsoft introduces native Linux Coreutils for Windows via Rust. Analyze the security impact, memory safety benefits, and potential living-off-the-land risks.</description><pubDate>Wed, 03 Jun 2026 01:09:39 GMT</pubDate><category>Microsoft</category><category>Coreutils</category><category>Rust</category><category>Windows Security</category><category>Living-off-the-Land</category></item><item><title>Microsoft MDASH AI Discovers 16 Windows Vulnerabilities</title><link>https://runtimerebel.com/blog/microsoft-mdash-ai-discovers-16-windows-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-mdash-ai-discovers-16-windows-vulnerabilities</guid><description>Microsoft reveals MDASH, a new AI-driven agentic scanning harness that discovered 16 vulnerabilities in Windows, now fixed in recent Patch Tuesday updates.</description><pubDate>Wed, 13 May 2026 16:52:01 GMT</pubDate><category>Microsoft</category><category>MDASH</category><category>Windows Security</category><category>AI Security</category><category>Patch Tuesday</category></item><item><title>Analysis of the Deep#Door Backdoor Framework and Windows Implants</title><link>https://runtimerebel.com/blog/analysis-of-the-deep-door-backdoor-framework-and-windows-implants</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-the-deep-door-backdoor-framework-and-windows-implants</guid><description>Technical analysis of Deep#Door, a Python-based backdoor using Discord for C2. Learn about its persistence, stealth, and mitigation strategies.</description><pubDate>Fri, 01 May 2026 12:29:42 GMT</pubDate><category>DEEP DOOR</category><category>Discord C2</category><category>Python Backdoor</category><category>Windows Security</category><category>Bitdefender</category></item><item><title>CVE-2026-33825: Microsoft Defender Access Control Exploit Analysis</title><link>https://runtimerebel.com/blog/cve-2026-33825-microsoft-defender-access-control-exploit-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-33825-microsoft-defender-access-control-exploit-analysis</guid><description>CISA adds CVE-2026-33825 to the KEV catalog following active exploitation of Microsoft Defender&apos;s access control mechanisms. Learn how to secure your systems.</description><pubDate>Thu, 23 Apr 2026 05:05:39 GMT</pubDate><category>CVE-2026-33825</category><category>Microsoft Defender</category><category>CISA KEV</category><category>Access Control</category><category>Windows Security</category></item><item><title>CVE-2024-36985: Splunk Enterprise RCE via File Upload - Patch Guide</title><link>https://runtimerebel.com/blog/cve-2024-36985-splunk-enterprise-rce-via-file-upload-patch-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-36985-splunk-enterprise-rce-via-file-upload-patch-guide</guid><description>Splunk patches a high-severity RCE vulnerability (CVE-2024-36985) allowing low-privileged users to execute code on Windows-based Enterprise instances.</description><pubDate>Thu, 16 Apr 2026 12:34:23 GMT</pubDate><category>CVE-2024-36985</category><category>Splunk Enterprise</category><category>Remote Code Execution</category><category>Windows Security</category><category>Patch Management</category></item><item><title>Google Chrome 146 DBSC Implementation Hardens Windows Against Session Hijacking</title><link>https://runtimerebel.com/blog/google-chrome-146-dbsc-implementation-hardens-windows-against-session-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-chrome-146-dbsc-implementation-hardens-windows-against-session-hijacking</guid><description>Google releases Device Bound Session Credentials (DBSC) in Chrome 146 for Windows to mitigate cookie theft and session hijacking via hardware-backed security.</description><pubDate>Fri, 10 Apr 2026 08:37:21 GMT</pubDate><category>Google Chrome</category><category>DBSC</category><category>Session Hijacking</category><category>Cookie Theft</category><category>TPM</category><category>Windows Security</category></item><item><title>54 EDR Killers Use BYOVD to Abuse 34 Signed Drivers</title><link>https://runtimerebel.com/blog/54-edr-killers-use-byovd-to-abuse-34-signed-drivers</link><guid isPermaLink="true">https://runtimerebel.com/blog/54-edr-killers-use-byovd-to-abuse-34-signed-drivers</guid><description>Analysis reveals 54 EDR killer programs abusing 34 signed drivers via BYOVD to neutralize security before ransomware deployment.</description><pubDate>Thu, 19 Mar 2026 20:15:35 GMT</pubDate><category>BYOVD</category><category>EDR Killer</category><category>Ransomware</category><category>Kernel Exploitation</category><category>Windows Security</category></item><item><title>Microsoft March Patch Tuesday: 84 Flaws Fixed Including Public Zero-Days</title><link>https://runtimerebel.com/blog/microsoft-march-patch-tuesday-84-flaws-fixed-including-public-zero-days</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-march-patch-tuesday-84-flaws-fixed-including-public-zero-days</guid><description>Microsoft releases March security updates for 84 vulnerabilities, including 8 Critical flaws and 2 public zero-days. Patch now to prevent RCE and privilege escalation.</description><pubDate>Wed, 11 Mar 2026 12:19:24 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Windows Security</category><category>Zero-Day</category><category>Remote Code Execution</category></item><item><title>March 2026 Patch Tuesday: Microsoft Fixes 77 Vulnerabilities</title><link>https://runtimerebel.com/blog/march-2026-patch-tuesday-microsoft-fixes-77-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/march-2026-patch-tuesday-microsoft-fixes-77-vulnerabilities</guid><description>Microsoft&apos;s March 2026 Patch Tuesday addresses 77 vulnerabilities across Windows and other software. Learn about the risks and how to prioritize patching.</description><pubDate>Wed, 11 Mar 2026 04:37:49 GMT</pubDate><category>Microsoft</category><category>Patch Tuesday</category><category>Windows Security</category><category>RCE</category><category>Privilege Escalation</category></item><item><title>Credential Abuse Risks: Solving Microsoft Entra ID MFA Coverage Gaps</title><link>https://runtimerebel.com/blog/credential-abuse-risks-solving-microsoft-entra-id-mfa-coverage-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/credential-abuse-risks-solving-microsoft-entra-id-mfa-coverage-gaps</guid><description>Examine how coverage gaps in Microsoft Entra ID and Okta MFA implementations allow attackers to exploit valid credentials within Windows network environments.</description><pubDate>Thu, 05 Mar 2026 12:18:56 GMT</pubDate><category>MFA</category><category>Microsoft Entra ID</category><category>Credential Abuse</category><category>Windows Security</category><category>Identity Provider</category></item><item><title>GetProcessHandleFromHwnd API: UAC Bypass Implications</title><link>https://runtimerebel.com/blog/getprocesshandlefromhwnd-api-uac-bypass-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/getprocesshandlefromhwnd-api-uac-bypass-implications</guid><description>Investigate the GetProcessHandleFromHwnd API&apos;s role in a Quick Assist UAC bypass. Understand its mechanism, UIAccess implications, and defender recommendations.</description><pubDate>Thu, 26 Feb 2026 20:17:06 GMT</pubDate><category>GetProcessHandleFromHwnd</category><category>UAC Bypass</category><category>UI Access</category><category>Quick Assist</category><category>Windows Security</category><category>API Analysis</category><category>Privilege Escalation</category></item></channel></rss>