Cyberattackers Exploit Microsoft SmartScreen Bug in Stealer Campaign

July 24, 2024 at 03:11PM A critical Microsoft Defender SmartScreen vulnerability (CVE-2024-21412) patched in February is still exploited in infostealing attacks globally. Exploiting SmartScreen’s security bypass allows attackers to disguise malicious code in images and trigger downloads, compromising data from various applications. Organizations with delayed Microsoft patch cycles are particularly vulnerable, emphasizing the need for … Read more

Microsoft Defender Flaw Exploited to Deliver ACR, Lumma, and Meduza Stealers

July 24, 2024 at 03:04AM A Microsoft Defender SmartScreen security flaw, CVE-2024-21412, was exploited in a campaign targeting Spain, Thailand, and the U.S. to deliver ACR Stealer, Lumma, and Meduza. Attackers use booby-trapped files to drop malicious payloads, bypassing SmartScreen protection. This highlights the ongoing threat of information stealers and the need for vigilance in … Read more