<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Windows</title><description>Cybersecurity articles tagged #Windows on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>ShieldBreak: Windows Zero-Day EoP via Microsoft Defender</title><link>https://runtimerebel.com/blog/shieldbreak-windows-zero-day-eop-via-microsoft-defender</link><guid isPermaLink="true">https://runtimerebel.com/blog/shieldbreak-windows-zero-day-eop-via-microsoft-defender</guid><description>Security researcher Nightmare Eclipse released &apos;ShieldBreak,&apos; a Windows zero-day exploit enabling privilege escalation via Microsoft Defender.</description><pubDate>Thu, 13 Aug 2026 09:03:52 GMT</pubDate><category>Nightmare Eclipse</category><category>Microsoft Defender</category><category>Windows</category><category>Privilege Escalation</category><category>Zero-Day</category></item><item><title>Plug and Pwn: SYSTEM Access via Windows Plug and Play Abuse</title><link>https://runtimerebel.com/blog/plug-and-pwn-system-access-via-windows-plug-and-play-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/plug-and-pwn-system-access-via-windows-plug-and-play-abuse</guid><description>New Plug and Pwn attacks leverage Windows Plug and Play to install vulnerable vendor software, granting attackers SYSTEM privileges via USB emulation or RDP.</description><pubDate>Wed, 12 Aug 2026 16:47:58 GMT</pubDate><category>Windows</category><category>Plug and Pwn</category><category>Plug and Play</category><category>SYSTEM Privileges</category><category>USB Attacks</category></item><item><title>CVE-2026-68820: Windows afd.sys Privilege Escalation Exploited</title><link>https://runtimerebel.com/blog/cve-2026-68820-windows-afd-sys-privilege-escalation-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-68820-windows-afd-sys-privilege-escalation-exploited</guid><description>Microsoft addresses 398 vulnerabilities, including an actively exploited privilege escalation flaw in Windows&apos; afd.sys component.</description><pubDate>Wed, 12 Aug 2026 01:06:41 GMT</pubDate><category>Microsoft</category><category>Windows</category><category>Privilege Escalation</category><category>Zero-Day</category><category>CVE-2026-68820</category></item><item><title>Microsoft August 2026 Patch Tuesday: 398 Flaws and Zero-Day</title><link>https://runtimerebel.com/blog/microsoft-august-2026-patch-tuesday-398-flaws-and-zero-day</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-august-2026-patch-tuesday-398-flaws-and-zero-day</guid><description>Microsoft patches 398 flaws in August 2026, including an actively exploited Windows kernel driver zero-day and four critical RCE vulnerabilities.</description><pubDate>Wed, 12 Aug 2026 01:05:21 GMT</pubDate><category>Windows</category><category>SharePoint</category><category>Zero-Day</category><category>Lazarus Group</category><category>CVE-2026-68820</category></item><item><title>NatJack Attacks: Exploiting NAT Trust in Windows, Linux, macOS</title><link>https://runtimerebel.com/blog/natjack-attacks-exploiting-nat-trust-in-windows-linux-macos</link><guid isPermaLink="true">https://runtimerebel.com/blog/natjack-attacks-exploiting-nat-trust-in-windows-linux-macos</guid><description>Synack&apos;s research reveals NatJack attacks, a new class of NAT exploitation affecting Windows, Linux, and macOS, leveraging trust assumptions.</description><pubDate>Sun, 09 Aug 2026 00:58:42 GMT</pubDate><category>Windows</category><category>Linux</category><category>macOS</category><category>NatJack</category><category>NAT</category></item><item><title>khunt Toolkit Leverages SQLi in Oracle for SYSTEM Access</title><link>https://runtimerebel.com/blog/khunt-toolkit-leverages-sqli-in-oracle-for-system-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/khunt-toolkit-leverages-sqli-in-oracle-for-system-access</guid><description>Attackers exploit SQL injection in a public-facing web app to compile the khunt toolkit within Oracle, achieving SYSTEM-level access on Windows servers.</description><pubDate>Thu, 06 Aug 2026 10:29:03 GMT</pubDate><category>SQL Injection</category><category>Post Exploitation</category><category>Windows</category><category>Oracle Database</category><category>Khunt</category></item><item><title>Pass-ta-key Attacks Hijack Google-Synced Passkeys on Windows</title><link>https://runtimerebel.com/blog/pass-ta-key-attacks-hijack-google-synced-passkeys-on-windows</link><guid isPermaLink="true">https://runtimerebel.com/blog/pass-ta-key-attacks-hijack-google-synced-passkeys-on-windows</guid><description>Researchers uncover Pass-ta-key attack methods that allow malware to hijack passkey-protected accounts on Windows without user interaction.</description><pubDate>Wed, 05 Aug 2026 17:21:16 GMT</pubDate><category>Malware</category><category>Credential Theft</category><category>Authentication</category><category>Windows</category><category>Google</category></item><item><title>AI-Assisted Phishing Leverages WebDAV for Infostealer Deployment</title><link>https://runtimerebel.com/blog/ai-assisted-phishing-leverages-webdav-for-infostealer-deployment</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-phishing-leverages-webdav-for-infostealer-deployment</guid><description>An exposed server revealed an AI-assisted phishing toolkit used in a WebDAV-based infostealer campaign targeting Windows users in Mexico. Learn detection and mitigation.</description><pubDate>Mon, 20 Jul 2026 18:05:04 GMT</pubDate><category>AI Assisted Phishing</category><category>WebDAV</category><category>Infostealer</category><category>Malware Toolkit</category><category>Mexico</category><category>Windows</category><category>Rapid7</category></item><item><title>Windows LegacyHive Zero-Day Exploit Grants Admin Access — Patch Status</title><link>https://runtimerebel.com/blog/windows-legacyhive-zero-day-exploit-grants-admin-access-patch-status</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-legacyhive-zero-day-exploit-grants-admin-access-patch-status</guid><description>The LegacyHive Zero-Day exploit allows local attackers to gain SYSTEM privileges on patched Windows systems by targeting legacy registry hive permissions.</description><pubDate>Fri, 17 Jul 2026 13:49:23 GMT</pubDate><category>LegacyHive</category><category>Windows</category><category>Zero-Day</category><category>Privilege Escalation</category><category>Abdelhamid Naceri</category></item><item><title>Zoom CVE-2026-53412: Critical Windows Client Account Takeover Fix</title><link>https://runtimerebel.com/blog/zoom-cve-2026-53412-critical-windows-client-account-takeover-fix</link><guid isPermaLink="true">https://runtimerebel.com/blog/zoom-cve-2026-53412-critical-windows-client-account-takeover-fix</guid><description>Zoom releases critical security updates for CVE-2026-53412, a high-severity input validation flaw in Windows clients allowing unauthenticated account takeover.</description><pubDate>Thu, 16 Jul 2026 10:12:19 GMT</pubDate><category>Zoom</category><category>CVE-2026-53412</category><category>Windows</category><category>Account Takeover</category><category>Input Validation</category></item><item><title>CVE-2024-24691: Zoom Windows Client Account Takeover - Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-24691-zoom-windows-client-account-takeover-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-24691-zoom-windows-client-account-takeover-patch-now</guid><description>Zoom has addressed CVE-2024-24691, a critical 9.6 CVSS vulnerability in Windows clients allowing unauthenticated account takeover. Learn how to patch and defend.</description><pubDate>Wed, 15 Jul 2026 21:05:22 GMT</pubDate><category>CVE-2024-24691</category><category>Zoom</category><category>Account Takeover</category><category>Windows</category><category>Remote Code Execution</category></item><item><title>LabubaRAT: Rust-Based RAT Masquerades as NVIDIA Software on Windows</title><link>https://runtimerebel.com/blog/labubarat-rust-based-rat-masquerades-as-nvidia-software-on-windows</link><guid isPermaLink="true">https://runtimerebel.com/blog/labubarat-rust-based-rat-masquerades-as-nvidia-software-on-windows</guid><description>Blackpoint Cyber researchers warn of LabubaRAT, a new Rust-based remote access trojan disguised as NVIDIA software, granting full control over Windows hosts.</description><pubDate>Tue, 14 Jul 2026 17:20:39 GMT</pubDate><category>LabubaRAT</category><category>Rust</category><category>NVIDIA</category><category>RAT</category><category>Windows</category><category>Remote Access Trojan</category></item><item><title>Ousaban Banking Trojan: Phishing Lures Target Iberian Bank Users</title><link>https://runtimerebel.com/blog/ousaban-banking-trojan-phishing-lures-target-iberian-bank-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/ousaban-banking-trojan-phishing-lures-target-iberian-bank-users</guid><description>Ousaban, a Brazilian banking trojan, targets Windows users in Spain and Portugal via fake PDF phishing lures, aiming to steal financial credentials.</description><pubDate>Wed, 01 Jul 2026 16:53:05 GMT</pubDate><category>Ousaban</category><category>Banking Trojan</category><category>Phishing</category><category>Spain</category><category>Portugal</category><category>Windows</category><category>Financial Crime</category><category>Malware Analysis</category></item><item><title>Hola Browser for Windows Compromised: Cryptominer Delivery via Supply Chain</title><link>https://runtimerebel.com/blog/hola-browser-for-windows-compromised-cryptominer-delivery-via-supply-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/hola-browser-for-windows-compromised-cryptominer-delivery-via-supply-chain</guid><description>Critical alert: Hola Browser for Windows compromised in a supply chain attack, delivering an undeclared cryptominer. Learn to detect and mitigate the threat.</description><pubDate>Fri, 05 Jun 2026 01:00:59 GMT</pubDate><category>Hola Browser</category><category>Windows</category><category>Supply Chain Attack</category><category>Cryptominer</category><category>Malware</category></item><item><title>PHP RCE via CVE-2024-4577 — Windows Argument Injection Analysis</title><link>https://runtimerebel.com/blog/php-rce-via-cve-2024-4577-windows-argument-injection-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/php-rce-via-cve-2024-4577-windows-argument-injection-analysis</guid><description>Technical analysis of the CVE-2024-4577 vulnerability affecting PHP on Windows. Learn how argument injection leads to RCE and how to secure PHP-CGI environments.</description><pubDate>Wed, 03 Jun 2026 05:44:55 GMT</pubDate><category>CVE-2024-4577</category><category>PHP</category><category>RCE</category><category>Windows</category><category>Argument Injection</category></item><item><title>YellowKey Zero-Day: Mitigating BitLocker Encryption Bypasses in Windows</title><link>https://runtimerebel.com/blog/yellowkey-zero-day-mitigating-bitlocker-encryption-bypasses-in-windows</link><guid isPermaLink="true">https://runtimerebel.com/blog/yellowkey-zero-day-mitigating-bitlocker-encryption-bypasses-in-windows</guid><description>Microsoft releases mitigation guidance for the YellowKey zero-day, a Windows BitLocker vulnerability allowing unauthorized access to encrypted data volumes.</description><pubDate>Wed, 20 May 2026 09:16:25 GMT</pubDate><category>Windows</category><category>BitLocker</category><category>YellowKey</category><category>Zero-Day</category><category>Encryption</category><category>Microsoft</category></item><item><title>MiniPlasma 0-Day: Windows SYSTEM Privilege Escalation via cldflt.sys</title><link>https://runtimerebel.com/blog/miniplasma-0-day-windows-system-privilege-escalation-via-cldflt-sys</link><guid isPermaLink="true">https://runtimerebel.com/blog/miniplasma-0-day-windows-system-privilege-escalation-via-cldflt-sys</guid><description>Technical analysis of the MiniPlasma zero-day vulnerability in cldflt.sys enabling SYSTEM privilege escalation on fully patched Windows systems.</description><pubDate>Mon, 18 May 2026 09:19:37 GMT</pubDate><category>MiniPlasma</category><category>Cldflt Sys</category><category>Zero-Day</category><category>Windows</category><category>Chaotic Eclipse</category></item><item><title>Windows MiniPlasma Zero-Day Exploit: How to Mitigate LPE Threats</title><link>https://runtimerebel.com/blog/windows-miniplasma-zero-day-exploit-how-to-mitigate-lpe-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-miniplasma-zero-day-exploit-how-to-mitigate-lpe-threats</guid><description>A new zero-day exploit dubbed MiniPlasma allows local attackers to gain SYSTEM privileges on fully patched Windows systems. Learn detection and mitigation steps.</description><pubDate>Mon, 18 May 2026 00:55:54 GMT</pubDate><category>MiniPlasma</category><category>Windows</category><category>Zero-Day</category><category>Local Privilege Escalation</category><category>LPE</category></item><item><title>Dell SupportAssist v4.0.3 Causes Windows BSOD — Remediation Guide</title><link>https://runtimerebel.com/blog/dell-supportassist-v4-0-3-causes-windows-bsod-remediation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/dell-supportassist-v4-0-3-causes-windows-bsod-remediation-guide</guid><description>Dell confirms SupportAssist v4.0.3 causes frequent Windows BSOD crashes and system reboots. Learn how to identify and mitigate these stability issues now.</description><pubDate>Thu, 14 May 2026 12:46:18 GMT</pubDate><category>Dell</category><category>SupportAssist</category><category>BSOD</category><category>Windows</category><category>Reliability</category></item><item><title>Windows Zero-Days: Analyzing YellowKey and GreenPlasma Exploits</title><link>https://runtimerebel.com/blog/windows-zero-days-analyzing-yellowkey-and-greenplasma-exploits</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-zero-days-analyzing-yellowkey-and-greenplasma-exploits</guid><description>A technical breakdown of the unpatched YellowKey BitLocker bypass and GreenPlasma local privilege escalation vulnerabilities affecting Windows systems.</description><pubDate>Thu, 14 May 2026 09:05:16 GMT</pubDate><category>YellowKey</category><category>GreenPlasma</category><category>Windows</category><category>BitLocker</category><category>Privilege Escalation</category><category>LPE</category></item><item><title>Microsoft&apos;s 137 Patches: Critical Flaws in Azure, Windows, Dynamics</title><link>https://runtimerebel.com/blog/microsoft-s-137-patches-critical-flaws-in-azure-windows-dynamics</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-s-137-patches-critical-flaws-in-azure-windows-dynamics</guid><description>Microsoft&apos;s latest security updates address 137 vulnerabilities, including critical flaws in Azure, Windows, and Dynamics 365, requiring immediate patching.</description><pubDate>Tue, 12 May 2026 20:39:17 GMT</pubDate><category>Microsoft</category><category>Security Update</category><category>Azure</category><category>Windows</category><category>Dynamics 365</category><category>SSO Plugin</category><category>Jira</category><category>Confluence</category><category>Vulnerability Management</category></item><item><title>CVE-2024-1708 &amp; CVE-2026-32202: CISA KEV Update — Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-1708-cve-2026-32202-cisa-kev-update-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-1708-cve-2026-32202-cisa-kev-update-patch-now</guid><description>CISA adds CVE-2024-1708 and CVE-2026-32202 to the Known Exploited Vulnerabilities Catalog following evidence of active exploitation in the wild.</description><pubDate>Wed, 29 Apr 2026 08:55:48 GMT</pubDate><category>CVE-2024-1708</category><category>CVE-2026-32202</category><category>Connectwise</category><category>Screenconnect</category><category>Windows</category><category>CISA KEV</category></item><item><title>Unpatched PhantomRPC: Windows Privilege Escalation via RPC Flaw</title><link>https://runtimerebel.com/blog/unpatched-phantomrpc-windows-privilege-escalation-via-rpc-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/unpatched-phantomrpc-windows-privilege-escalation-via-rpc-flaw</guid><description>Runtime Rebel analyzes the unpatched &apos;PhantomRPC&apos; flaw in Windows, detailing how an architectural weakness in RPC enables local privilege escalation.</description><pubDate>Mon, 27 Apr 2026 16:41:23 GMT</pubDate><category>PhantomRPC</category><category>Windows</category><category>Privilege Escalation</category><category>RPC</category><category>Vulnerability</category><category>Unpatched</category></item><item><title>APT28 Exploits Incomplete Windows Patch: Zero-Click Attacks Persist</title><link>https://runtimerebel.com/blog/apt28-exploits-incomplete-windows-patch-zero-click-attacks-persist</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt28-exploits-incomplete-windows-patch-zero-click-attacks-persist</guid><description>An incomplete Windows patch leaves systems vulnerable to zero-click attacks. Russia-linked APT28 exploited this against Ukraine and EU. Learn how to defend.</description><pubDate>Mon, 27 Apr 2026 16:40:47 GMT</pubDate><category>Windows</category><category>Zero Click</category><category>APT28</category><category>Patch Bypass</category><category>Vulnerability</category><category>Microsoft</category><category>Cyber Warfare</category></item><item><title>Kyber Ransomware Targets Windows, ESXi with Post-Quantum Encryption</title><link>https://runtimerebel.com/blog/kyber-ransomware-targets-windows-esxi-with-post-quantum-encryption</link><guid isPermaLink="true">https://runtimerebel.com/blog/kyber-ransomware-targets-windows-esxi-with-post-quantum-encryption</guid><description>Kyber ransomware is encrypting Windows and VMware ESXi systems, with one variant leveraging Kyber1024 post-quantum encryption, posing new decryption challenges.</description><pubDate>Wed, 22 Apr 2026 20:25:36 GMT</pubDate><category>Kyber</category><category>Ransomware</category><category>Kyber1024</category><category>Post Quantum Cryptography</category><category>Windows</category><category>VMware ESXi</category></item><item><title>April 2026 Patch Tuesday: SharePoint Zero-Day, BlueHammer, &amp; Adobe RCE</title><link>https://runtimerebel.com/blog/april-2026-patch-tuesday-sharepoint-zero-day-bluehammer-adobe-rce</link><guid isPermaLink="true">https://runtimerebel.com/blog/april-2026-patch-tuesday-sharepoint-zero-day-bluehammer-adobe-rce</guid><description>Microsoft&apos;s April 2026 Patch Tuesday addresses 167 vulnerabilities, including a SharePoint Server zero-day, Windows Defender &apos;BlueHammer&apos; flaw, and an actively exploited…</description><pubDate>Wed, 15 Apr 2026 00:45:50 GMT</pubDate><category>Microsoft</category><category>Windows</category><category>SharePoint Server</category><category>Windows Defender</category><category>Adobe Reader</category><category>Google Chrome</category><category>Patch Tuesday</category><category>Zero-Day</category><category>RCE</category><category>BlueHammer</category><category>Vulnerability</category><category>Exploitation</category></item><item><title>CVE-2024-43451: How NTLM Hash Disclosure Impacts Windows Systems</title><link>https://runtimerebel.com/blog/cve-2024-43451-how-ntlm-hash-disclosure-impacts-windows-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-43451-how-ntlm-hash-disclosure-impacts-windows-systems</guid><description>Technical analysis of CVE-2024-43451, a Windows NTLM hash disclosure vulnerability triggered by minimal user interaction. Learn detection and mitigation steps.</description><pubDate>Mon, 13 Apr 2026 05:08:48 GMT</pubDate><category>CVE-2024-43451</category><category>Windows</category><category>NTLM</category><category>Hash Disclosure</category><category>Microsoft</category></item><item><title>BlueHammer Zero-Day: Windows Local Privilege Escalation Exploit Risks</title><link>https://runtimerebel.com/blog/bluehammer-zero-day-windows-local-privilege-escalation-exploit-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/bluehammer-zero-day-windows-local-privilege-escalation-exploit-risks</guid><description>Researcher Chaotic Eclipse released the BlueHammer zero-day exploit for Windows, enabling local privilege escalation. Learn how to detect and mitigate it.</description><pubDate>Fri, 10 Apr 2026 08:40:43 GMT</pubDate><category>BlueHammer</category><category>Windows</category><category>Privilege Escalation</category><category>Zero-Day</category><category>Chaotic Eclipse</category><category>Microsoft</category></item><item><title>WhatsApp VBS Malware Bypasses UAC to Hijack Windows Systems</title><link>https://runtimerebel.com/blog/whatsapp-vbs-malware-bypasses-uac-to-hijack-windows-systems</link><guid isPermaLink="true">https://runtimerebel.com/blog/whatsapp-vbs-malware-bypasses-uac-to-hijack-windows-systems</guid><description>Microsoft warns of a new campaign distributing VBS malware via WhatsApp, exploiting UAC bypass to establish persistence and remote access on Windows systems, starting…</description><pubDate>Wed, 01 Apr 2026 16:25:50 GMT</pubDate><category>WhatsApp</category><category>VBScript</category><category>UAC Bypass</category><category>Windows</category><category>Malware</category><category>Persistence</category><category>Remote Access</category></item><item><title>Axios npm Package Hijacked: Cross-Platform Malware Distribution</title><link>https://runtimerebel.com/blog/axios-npm-package-hijacked-cross-platform-malware-distribution</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-package-hijacked-cross-platform-malware-distribution</guid><description>Analysis of the Axios npm package hijack distributing remote access trojans to Linux, Windows, and macOS systems. Learn to protect your software supply chain.</description><pubDate>Tue, 31 Mar 2026 16:29:10 GMT</pubDate><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>Remote Access Trojan</category><category>Malware</category><category>JavaScript</category><category>Linux</category><category>Windows</category><category>macOS</category></item><item><title>Microsoft Patch Tuesday Analysis: Addressing Critical RCE and Quishing</title><link>https://runtimerebel.com/blog/microsoft-patch-tuesday-analysis-addressing-critical-rce-and-quishing</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-patch-tuesday-analysis-addressing-critical-rce-and-quishing</guid><description>Technical analysis of the March 2026 Patch Tuesday cycle, focusing on Windows RCE, kernel-level privilege escalation, and emerging QR code phishing trends.</description><pubDate>Fri, 13 Mar 2026 04:38:08 GMT</pubDate><category>CVE-2024-26252</category><category>CVE-2024-29988</category><category>CVE-2024-21323</category><category>Microsoft</category><category>Windows</category><category>Patch Tuesday</category></item><item><title>Zoom and Splunk Patch Critical RCE and PE Vulnerabilities</title><link>https://runtimerebel.com/blog/zoom-and-splunk-patch-critical-rce-and-pe-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/zoom-and-splunk-patch-critical-rce-and-pe-vulnerabilities</guid><description>Security updates for Splunk Enterprise and Zoom Desktop Client address critical vulnerabilities, including a 9.6-rated RCE and high-severity privilege escalation.</description><pubDate>Thu, 12 Mar 2026 12:20:43 GMT</pubDate><category>CVE-2024-24691</category><category>CVE-2024-36985</category><category>Splunk</category><category>Zoom</category><category>RCE</category><category>Windows</category></item><item><title>Microsoft Windows Hotpatching to be Enabled by Default in May 2026</title><link>https://runtimerebel.com/blog/microsoft-windows-hotpatching-to-be-enabled-by-default-in-may-2026</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-windows-hotpatching-to-be-enabled-by-default-in-may-2026</guid><description>Microsoft will enable hotpatching by default for Intune-managed Windows devices in May 2026, allowing security updates without reboots to reduce downtime.</description><pubDate>Tue, 10 Mar 2026 12:19:01 GMT</pubDate><category>Windows</category><category>Microsoft Intune</category><category>Hotpatching</category><category>Patch Management</category></item><item><title>Chinese Cyber Threat: Persistent Espionage in Critical Asian Sectors</title><link>https://runtimerebel.com/blog/chinese-cyber-threat-persistent-espionage-in-critical-asian-sectors</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-cyber-threat-persistent-espionage-in-critical-asian-sectors</guid><description>An undefined Chinese-speaking actor conducts long-term cyber espionage against critical Asian sectors using custom malware and living-off-the-land binaries.</description><pubDate>Mon, 09 Mar 2026 16:35:16 GMT</pubDate><category>Chinese APT</category><category>Espionage</category><category>Windows</category><category>Linux</category><category>LOTL</category><category>Custom Malware</category><category>Critical Infrastructure</category><category>Threat Actor</category></item><item><title>Windows Administrator Protection Bypassed via UI Access Abuse</title><link>https://runtimerebel.com/blog/windows-administrator-protection-bypassed-via-ui-access-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-administrator-protection-bypassed-via-ui-access-abuse</guid><description>Analysis of UI Access abuse techniques that bypassed Windows Administrator Protection, a new UAC feature, detailing historical context and fixes.</description><pubDate>Wed, 25 Feb 2026 04:47:06 GMT</pubDate><category>Windows</category><category>UAC</category><category>Administrator Protection</category><category>UI Access</category><category>Privilege Escalation</category><category>Shatter Attack</category><category>Project Zero</category></item><item><title>Microsoft February 2026 Security Update: Analysis of Six Actively Exploited Zero-Days</title><link>https://runtimerebel.com/blog/microsoft-february-2026-security-update-analysis-of-six-actively-exploited-zero-days</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-february-2026-security-update-analysis-of-six-actively-exploited-zero-days</guid><description>Microsoft&apos;s latest security release addresses 50+ vulnerabilities, including six zero-day exploits targeting Windows kernel components and browser engines.</description><pubDate>Mon, 23 Feb 2026 08:22:09 GMT</pubDate><category>Patch Tuesday</category><category>Microsoft</category><category>Zero-Day</category><category>Windows</category><category>RCE</category><category>LPE</category></item></channel></rss>