# Microsoft Windows

Published articles for Microsoft Windows.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## From Love Letters to AI Agents: Cybersecurity's Evolution

DevFeed: [From Love Letters to AI Agents: Cybersecurity's Evolution](<https://devfeed.tech/articles/from-love-letters-to-ai-agents-cybersecurity-s-evolution-57491.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/from-love-letters-to-ai-agents-cybersecuritys-evolution/>)

Author: Renato Morais

Published: 2026-09-21T15:00:07Z

Content type: article

Language: en

Sources: [Security @ Cisco](<https://devfeed.tech/sources/security-cisco-blogs.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [email](<https://devfeed.tech/topics/email.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [AI Models](<https://devfeed.tech/topics/ai-models.md>), [Visual Basic](<https://devfeed.tech/topics/visual-basic.md>)

Tags: [2017](<https://devfeed.tech/tags/2017.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-cybersecurity](<https://devfeed.tech/tags/ai-cybersecurity.md>), [breach](<https://devfeed.tech/tags/breach.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [edr](<https://devfeed.tech/tags/edr.md>), [email](<https://devfeed.tech/tags/email.md>), [identity-security](<https://devfeed.tech/tags/identity-security.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [patch-management](<https://devfeed.tech/tags/patch-management.md>), [security](<https://devfeed.tech/tags/security.md>), [security-platform](<https://devfeed.tech/tags/security-platform.md>), [threats](<https://devfeed.tech/tags/threats.md>)

### AI overview

This article traces major shifts in cybersecurity through the ILOVEYOU worm, WannaCry ransomware, and the emerging risks posed by autonomous AI. It connects each era to changes in security awareness, email filtering, patch management, vulnerability management, and endpoint protection.

### Source excerpt

Discover how Cisco security solutions and the four pillars of agentic security protect organizations against autonomous AI risks and evolving threats.

## From Love Letters to AI Agents: Cybersecurity's Evolution

DevFeed: [From Love Letters to AI Agents: Cybersecurity's Evolution](<https://devfeed.tech/articles/from-love-letters-to-ai-agents-cybersecurity-s-evolution-57430.md>)

Original publisher: [Read original article](<https://blogs.cisco.com/security/from-love-letters-to-ai-agents-cybersecuritys-evolution>)

Author: Renato Morais

Published: 2026-09-21T15:00:07Z

Content type: article

Language: en

Sources: [Cisco Blogs](<https://devfeed.tech/sources/cisco-blogs.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Bitcoin](<https://devfeed.tech/topics/bitcoin.md>), [Visual Basic](<https://devfeed.tech/topics/visual-basic.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-cybersecurity](<https://devfeed.tech/tags/ai-cybersecurity.md>), [ai-risks](<https://devfeed.tech/tags/ai-risks.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [identity-security](<https://devfeed.tech/tags/identity-security.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [patch-management](<https://devfeed.tech/tags/patch-management.md>), [patching](<https://devfeed.tech/tags/patching.md>), [security](<https://devfeed.tech/tags/security.md>), [security-platform](<https://devfeed.tech/tags/security-platform.md>), [threats](<https://devfeed.tech/tags/threats.md>)

### AI overview

This article traces major cybersecurity shifts from the ILOVEYOU worm and WannaCry ransomware to autonomous AI as a potential new threat vector. It links these changes to social engineering, patch management, legacy systems, and modern defensive practices.

### Source excerpt

Discover how Cisco security solutions and the four pillars of agentic security protect organizations against autonomous AI risks and evolving threats.

## Gzip 1.15 Released With Many Bug Fixes For Issues Present Since Its Inception

DevFeed: [Gzip 1.15 Released With Many Bug Fixes For Issues Present Since Its Inception](<https://devfeed.tech/articles/gzip-1-15-released-with-many-bug-fixes-for-issues-present-since-its-inception-55589.md>)

Original publisher: [Read original article](<https://www.phoronix.com/news/Gzip-1.15-Released>)

Author: Michael Larabel

Published: 2026-09-20T14:32:12Z

Content type: release

Language: en

Sources: [Phoronix](<https://devfeed.tech/sources/phoronix.md>)

Topics: [Compression](<https://devfeed.tech/topics/compression.md>), [bug](<https://devfeed.tech/topics/bug.md>), [file](<https://devfeed.tech/topics/file.md>), [Decoding](<https://devfeed.tech/topics/decoding.md>)

Tags: [announcement](<https://devfeed.tech/tags/announcement.md>), [buffer-overflow](<https://devfeed.tech/tags/buffer-overflow.md>), [bug](<https://devfeed.tech/tags/bug.md>), [compression](<https://devfeed.tech/tags/compression.md>), [desktop-linux](<https://devfeed.tech/tags/desktop-linux.md>), [freebsd](<https://devfeed.tech/tags/freebsd.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-benchmarking](<https://devfeed.tech/tags/linux-benchmarking.md>), [linux-hardware-benchmarks](<https://devfeed.tech/tags/linux-hardware-benchmarks.md>), [linux-hardware-reviews](<https://devfeed.tech/tags/linux-hardware-reviews.md>), [linux-how-to](<https://devfeed.tech/tags/linux-how-to.md>), [linux-performance](<https://devfeed.tech/tags/linux-performance.md>), [linux-server-benchmarks](<https://devfeed.tech/tags/linux-server-benchmarks.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [open-source-graphics](<https://devfeed.tech/tags/open-source-graphics.md>), [phoronix](<https://devfeed.tech/tags/phoronix.md>), [phoronix-test-suite](<https://devfeed.tech/tags/phoronix-test-suite.md>), [release](<https://devfeed.tech/tags/release.md>), [ubuntu-benchmarks](<https://devfeed.tech/tags/ubuntu-benchmarks.md>), [ubuntu-hardware](<https://devfeed.tech/tags/ubuntu-hardware.md>)

### AI overview

Gzip 1.15 is a release focused on more than one hundred commits of bug fixes. It addresses file-handling errors, uninitialized memory, buffer overflows, decompression corruption, streamed ZIP compatibility, temporary-file races, and locale handling. The release also drops support for several older platforms.

### Source excerpt

Gzip 1.15 is out today for succeeding the Gzip 1.14 release from April 2025. With this release comes a number of fixes for bugs present since the beginning of Gzip...

## Toy Ghouls Deploy Backdoors Using HiveMQ MQTT and Element Messenger

DevFeed: [Toy Ghouls Deploy Backdoors Using HiveMQ MQTT and Element Messenger](<https://devfeed.tech/articles/angry-birds-toy-ghouls-new-toys-48829.md>)

Original publisher: [Read original article](<https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/>)

Author: Kaspersky GERT, Kaspersky Security Services

Published: 2026-09-04T10:00:05Z

Content type: news

Language: en

Sources: [Securelist](<https://devfeed.tech/sources/securelist.md>)

Topics: [MQTT](<https://devfeed.tech/topics/mqtt.md>), [C2](<https://devfeed.tech/topics/c2.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Matrix](<https://devfeed.tech/topics/matrix-org.md>), [ChaCha](<https://devfeed.tech/topics/chacha-cipher.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Kimwolf v7](<https://devfeed.tech/topics/kimwolf-v7.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c2](<https://devfeed.tech/tags/c2.md>), [command-and-control](<https://devfeed.tech/tags/command-and-control.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [encrypted](<https://devfeed.tech/tags/encrypted.md>), [full](<https://devfeed.tech/tags/full.md>), [github](<https://devfeed.tech/tags/github.md>), [kaspersky](<https://devfeed.tech/tags/kaspersky.md>), [large](<https://devfeed.tech/tags/large.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-descriptions](<https://devfeed.tech/tags/malware-descriptions.md>), [malware-technologies](<https://devfeed.tech/tags/malware-technologies.md>), [medium](<https://devfeed.tech/tags/medium.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [mqtt](<https://devfeed.tech/tags/mqtt.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [soc-ti-and-ir-posts](<https://devfeed.tech/tags/soc-ti-and-ir-posts.md>), [targeted-attacks](<https://devfeed.tech/tags/targeted-attacks.md>), [thumbnail](<https://devfeed.tech/tags/thumbnail.md>), [toy-ghouls](<https://devfeed.tech/tags/toy-ghouls.md>), [windows-malware](<https://devfeed.tech/tags/windows-malware.md>)

### AI overview

Kaspersky researchers identified two Toy Ghouls backdoors used against Russian organizations. One uses the HiveMQ MQTT broker for command and control, while the other uses the Matrix-based Element messenger. The article examines their delivery, persistence, configuration, and communication mechanisms.

### Source excerpt

Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.

## Exploits and vulnerabilities in Q2 2026

DevFeed: [Exploits and vulnerabilities in Q2 2026](<https://devfeed.tech/articles/exploits-and-vulnerabilities-in-q2-2026-48832.md>)

Original publisher: [Read original article](<https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/>)

Author: Alexander Kolesnikov

Published: 2026-08-26T10:00:04Z

Content type: article

Language: en

Sources: [Securelist](<https://devfeed.tech/sources/securelist.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability-research](<https://devfeed.tech/topics/vulnerability-research.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [adaptixc2](<https://devfeed.tech/tags/adaptixc2.md>), [ai](<https://devfeed.tech/tags/ai.md>), [apt](<https://devfeed.tech/tags/apt.md>), [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [cvss](<https://devfeed.tech/tags/cvss.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [full](<https://devfeed.tech/tags/full.md>), [havoc](<https://devfeed.tech/tags/havoc.md>), [large](<https://devfeed.tech/tags/large.md>), [linux](<https://devfeed.tech/tags/linux.md>), [medium](<https://devfeed.tech/tags/medium.md>), [metasploit](<https://devfeed.tech/tags/metasploit.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [report](<https://devfeed.tech/tags/report.md>), [sliver](<https://devfeed.tech/tags/sliver.md>), [thumbnail](<https://devfeed.tech/tags/thumbnail.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerabilities-and-exploits](<https://devfeed.tech/tags/vulnerabilities-and-exploits.md>), [vulnerability-reports](<https://devfeed.tech/tags/vulnerability-reports.md>), [vulnerability-statistics](<https://devfeed.tech/tags/vulnerability-statistics.md>)

### AI overview

This Q2 2026 report analyzes trends in registered vulnerabilities, critical vulnerabilities, publicly available exploits, and C2 frameworks. It attributes rising vulnerability discovery partly to the use of AI tools and highlights vulnerabilities found in AI-related projects and development tools.

### Source excerpt

This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.

## APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

DevFeed: [APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit](<https://devfeed.tech/articles/apt-group-honeymyte-upgrades-coolclient-the-backdoor-gets-a-kernel-level-windows-rootkit-48825.md>)

Original publisher: [Read original article](<https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/>)

Author: Fareed Radzi

Published: 2026-08-14T09:00:14Z

Content type: article

Language: en

Sources: [Securelist](<https://devfeed.tech/sources/securelist.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [apt-reports](<https://devfeed.tech/tags/apt-reports.md>), [apt-targeted-attacks](<https://devfeed.tech/tags/apt-targeted-attacks.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [dll-sideloading](<https://devfeed.tech/tags/dll-sideloading.md>), [full](<https://devfeed.tech/tags/full.md>), [great-research](<https://devfeed.tech/tags/great-research.md>), [honeymyte](<https://devfeed.tech/tags/honeymyte.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [large](<https://devfeed.tech/tags/large.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-descriptions](<https://devfeed.tech/tags/malware-descriptions.md>), [malware-technologies](<https://devfeed.tech/tags/malware-technologies.md>), [medium](<https://devfeed.tech/tags/medium.md>), [microsoft-defender](<https://devfeed.tech/tags/microsoft-defender.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [rootkits](<https://devfeed.tech/tags/rootkits.md>), [security](<https://devfeed.tech/tags/security.md>), [shellcode](<https://devfeed.tech/tags/shellcode.md>), [targeted-attacks](<https://devfeed.tech/tags/targeted-attacks.md>), [thumbnail](<https://devfeed.tech/tags/thumbnail.md>), [windows](<https://devfeed.tech/tags/windows.md>), [windows-malware](<https://devfeed.tech/tags/windows-malware.md>)

### AI overview

Security researchers analyzed a newer CoolClient backdoor variant attributed to the HoneyMyte APT group. The variant deploys a signed kernel-mode driver as a Windows service, communicating through IOCTL requests to hide the malware process, files, registry entries, and network connections.

### Source excerpt

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

## How a Compromised Terminal Server Became a Phishing Stager

DevFeed: [How a Compromised Terminal Server Became a Phishing Stager](<https://devfeed.tech/articles/the-devil-eight-million-emails-and-a-whole-lot-of-milk-phishing-stager-exposed-54584.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/terminal-server-phishing-stager-exposed>)

Author: Josh Kiriakoff

Published: 2026-06-15T14:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [incident](<https://devfeed.tech/topics/incident.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [Security](<https://devfeed.tech/topics/security.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>)

Tags: [edr](<https://devfeed.tech/tags/edr.md>), [incident](<https://devfeed.tech/tags/incident.md>), [login](<https://devfeed.tech/tags/login.md>), [logs](<https://devfeed.tech/tags/logs.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Huntress analyzes an intrusion in which a publicly exposed Windows terminal server was compromised and used as a phishing stager. The campaign used a fake Boots survey targeting 8.9 million inboxes, with its payload hosted on a hacked Bolivian government site.

### Source excerpt

A compromised terminal server became a phishing stager. A fake Boots survey aimed at 8.9 million inboxes, with the payload on a hacked Bolivian government site.

## Threat actors exploit a remote code execution vulnerability in Microsoft WSUS

DevFeed: [Threat actors exploit a remote code execution vulnerability in Microsoft WSUS](<https://devfeed.tech/articles/exploitation-of-windows-server-update-services-remote-code-huntress-54333.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/exploitation-of-windows-server-update-services-remote-code-execution-vulnerability>)

Author: Chad Hudson; James Maclachlan; Jai Minton; John Hammond; Lindsey O'Donnell-Welch

Published: 2025-10-24T04:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [PowerShell](<https://devfeed.tech/topics/powershell.md>), [Process](<https://devfeed.tech/topics/process.md>), [HTTP](<https://devfeed.tech/topics/http.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [http](<https://devfeed.tech/tags/http.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [payload](<https://devfeed.tech/tags/payload.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [rce](<https://devfeed.tech/tags/rce.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [tcp](<https://devfeed.tech/tags/tcp.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [windows](<https://devfeed.tech/tags/windows.md>), [windows-server](<https://devfeed.tech/tags/windows-server.md>), [wsus](<https://devfeed.tech/tags/wsus.md>)

### AI overview

Huntress reports that threat actors exploited CVE-2025-59287, a deserialization-based remote code execution vulnerability in Microsoft Windows Server Update Services. The observed activity targeted publicly exposed WSUS instances and included PowerShell payload execution and data exfiltration.

### Source excerpt

Huntress has observed threat actors exploiting a Microsoft Windows Server Update Services (WSUS) vulnerability (CVE-2025-59287).

## Kali Vagrant Rebuilt: Out With Packer, In With DebOS

DevFeed: [Kali Vagrant Rebuilt: Out With Packer, In With DebOS](<https://devfeed.tech/articles/kali-vagrant-rebuilt-out-with-packer-in-with-debos-47148.md>)

Original publisher: [Read original article](<https://www.kali.org/blog/kali-vagrant-rebuilt/>)

Published: 2025-08-21T00:00:00Z

Content type: release

Language: en

Sources: [Kali Linux](<https://devfeed.tech/sources/kali-linux.md>)

Topics: [Vagrant](<https://devfeed.tech/topics/vagrant.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [hyper-v](<https://devfeed.tech/topics/hyper-v.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Script](<https://devfeed.tech/topics/script.md>)

Tags: [advanced](<https://devfeed.tech/tags/advanced.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [distribution](<https://devfeed.tech/tags/distribution.md>), [hyper-v](<https://devfeed.tech/tags/hyper-v.md>), [kali](<https://devfeed.tech/tags/kali.md>), [kalilinux](<https://devfeed.tech/tags/kalilinux.md>), [linux](<https://devfeed.tech/tags/linux.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [penetration](<https://devfeed.tech/tags/penetration.md>), [penetration-testing](<https://devfeed.tech/tags/penetration-testing.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [template](<https://devfeed.tech/tags/template.md>), [testing](<https://devfeed.tech/tags/testing.md>), [vagrant](<https://devfeed.tech/tags/vagrant.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

Kali explains that it rebuilt its Vagrant VM images using DebOS instead of Packer. The new process builds stock and Vagrant virtual machines automatically in the same Linux-based infrastructure, while addressing Vagrant base-box requirements and compatibility with Hyper-V exports on Windows.

### Source excerpt

Vagrant files, *.box, are pre-configured Virtual Machines (VM) VM images, which when imported into HashiCorp's Vagrant, allow for VMs to be interacted with via the command line. You create, start, interact, stop, destroy VMs all without leaving the terminal. Think containers (Docker/Podman), but for VMs. Previously we have been using HashiCorp's Packer to generate our HashiCorp's Vagrant images. Packer is a wrapper, around whatever hypervisor you wish, and it will automate installing the OS (unattended setup via preseeding), run any commands or scripts, export the VM and finally compress it. The down-side to Packer is that you need to have the chosen hypervisor installed on the host OS, you can't cross-build. If you use Linux, you can't build Window's Hyper-V. For a few years now , we have been using DebOS, to automate building our VMs. This has been working great for us. Recently we realized: "Why do we have two different systems, for the same purpose?". A little bit of digging into "how to make a vagrant base box VM" boils down to just a few requirements: Fix username (vagrant) Fix/Known pubic SSH keys (default/standard insecure keypairs) Able to perform superuser actions (sudo) Simple really, just need to make sure that Vagrant can easy access the VM! Optional items (and recommended), as it helps benefits user's rather than Vagrant: Known/Fix credentials (vagrant everywhere) SSH tweaks (speed up for airgap networks) All of this can be handled in a post-install step, which we have put into our Kali-VM build-script. Now, we are building all of our VMs, automatically, in the same matter (Stock and Vagrant), all in the same infrastructure setup (Linux!). Since Microsoft Windows 10 1607 / Server 2016, when exporting VMs, there would be 3 additional "binary" files, *.vmcx/*.vmrs included as well as an *.xml. As we were no longer exporting the VM from Hyper-V, but generating it outside of, we do not have these files. Now, we could create a "template" binary which would

## Akira Ransomware Indicators | Huntress

DevFeed: [Akira Ransomware Indicators | Huntress](<https://devfeed.tech/articles/akira-ransomware-indicators-huntress-54196.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/akira-ransomware-indicators>)

Author: Harlan Carvey

Published: 2024-09-20T00:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [account](<https://devfeed.tech/topics/account.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Server](<https://devfeed.tech/topics/server.md>), [Network](<https://devfeed.tech/topics/network.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [akira](<https://devfeed.tech/tags/akira.md>), [analysts](<https://devfeed.tech/tags/analysts.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [network](<https://devfeed.tech/tags/network.md>), [passwords](<https://devfeed.tech/tags/passwords.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [software](<https://devfeed.tech/tags/software.md>), [user](<https://devfeed.tech/tags/user.md>)

### AI overview

Huntress analysts describe indicators linked to Akira ransomware attacks, including new or compromised accounts, lateral movement, exposed MSSQL servers, RDP access, hidden Windows accounts, and incomplete security-agent coverage. Earlier detection of these indicators may help organizations prevent ransomware deployment and file encryption.

### Source excerpt

Tracking various indicators associated with different attacks, Huntress analysts have been able to identify specific indicators (threat actor workstation names, passwords associated with new user account creation or current account modification, CloudFlare tunnel tokens) that are associated with Akira ransomware infections. By detecting these indicators much earlier in the attack chain, organizations can inhibit or even obviate file encryption malware deployment.

## Kernel ETW is the best ETW

DevFeed: [Kernel ETW is the best ETW](<https://devfeed.tech/articles/kernel-etw-is-the-best-etw-48915.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/blog/kernel-etw-best-etw>)

Author: John Uhlmann

Published: 2024-09-13T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Kernel](<https://devfeed.tech/topics/kernel.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Security](<https://devfeed.tech/topics/security.md>), [hooks](<https://devfeed.tech/topics/hooks.md>), [reliability-engineering](<https://devfeed.tech/topics/reliability-engineering.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Process](<https://devfeed.tech/topics/process.md>)

Tags: [audit](<https://devfeed.tech/tags/audit.md>), [endpoint-protection-security](<https://devfeed.tech/tags/endpoint-protection-security.md>), [endpoint-security](<https://devfeed.tech/tags/endpoint-security.md>), [hooks](<https://devfeed.tech/tags/hooks.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [logging](<https://devfeed.tech/tags/logging.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [process](<https://devfeed.tech/tags/process.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

This research explains why secure-by-design software should favor kernel-level Event Tracing for Windows (ETW) telemetry over user-mode hooks. It compares the anti-tamper properties and reliability of ETW providers, including process-creation events and security event logging.

### Source excerpt

This research focuses on the importance of native audit logs in secure-by-design software, emphasizing the need for kernel-level ETW logging over user-mode hooks to enhance anti-tamper protections.

## Huntress Identifies INC Ransomware Activity and a Repeated Attack Pattern

DevFeed: [Huntress Identifies INC Ransomware Activity and a Repeated Attack Pattern](<https://devfeed.tech/articles/lolbin-to-inc-ransomware-54460.md>)

Original publisher: [Read original article](<https://www.huntress.com/blog/lolbin-to-inc-ransomware>)

Author: Harlan Carvey

Published: 2024-05-01T00:00:00Z

Content type: article

Language: en

Sources: [Huntress Blog](<https://devfeed.tech/sources/huntress-blog.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Security](<https://devfeed.tech/topics/security.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [analysts](<https://devfeed.tech/tags/analysts.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [defender](<https://devfeed.tech/tags/defender.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [huntress](<https://devfeed.tech/tags/huntress.md>), [incident](<https://devfeed.tech/tags/incident.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Huntress describes INC ransomware activity observed in a customer environment and identifies a repeated pattern in the threat actor's intermediate attack stages. Analysts used that pattern to find potentially affected endpoints before ransomware deployment.

### Source excerpt

Huntress has observed INC ransomware deployed in the past but recent activity indicates a possible continued shift in/or improvement of tactics employed by these threat actors.

## Doubling Down: Detecting In-Memory Threats with Kernel ETW Call Stacks

DevFeed: [Doubling Down: Detecting In-Memory Threats with Kernel ETW Call Stacks](<https://devfeed.tech/articles/doubling-down-detecting-in-memory-threats-with-kernel-etw-call-stacks-49021.md>)

Original publisher: [Read original article](<https://www.elastic.co/security-labs/threat-command/doubling-down-etw-callstacks>)

Author: John Uhlmann,Samir Bousseaden

Published: 2024-01-09T00:00:00Z

Content type: article

Language: en

Sources: [Elastic Security Labs](<https://devfeed.tech/sources/elastic-security-labs.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Security Information and Event Management (SIEM)](<https://devfeed.tech/topics/siem-security.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [detection-engineering](<https://devfeed.tech/tags/detection-engineering.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-windows](<https://devfeed.tech/tags/microsoft-windows.md>), [security](<https://devfeed.tech/tags/security.md>), [siem](<https://devfeed.tech/tags/siem.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [threat-intelligence](<https://devfeed.tech/tags/threat-intelligence.md>), [tracing](<https://devfeed.tech/tags/tracing.md>)

### AI overview

Elastic Security 8.11 adds kernel telemetry and ETW call stack-based detections to improve detection of in-memory threats. The article explains the security visibility provided by Windows ETW, the limitations of user-mode hooking, and the tradeoff between endpoint telemetry completeness and SIEM storage costs.

### Source excerpt

With Elastic Security 8.11, we added further kernel telemetry call stack-based detections to increase efficacy against in-memory threats.