Elastic Security Labs identified four REVSTEALER-associated programs that disable Windows Update and Defender to deploy a cryptocurrency miner, persisting even after the main stealer removes itself.
Researchers identify BraZetsu, a Python-based Windows malware that enables Initial Access Brokers to commercialize compromised systems as marketplace inventory.
An Akira ransomware affiliate bypassed endpoint detection by rebooting the infected system into Safe Mode with Networking to disable the EDR solution, stealing data without encrypting files.
The 'ShieldBreak' zero-day exploit targeting Microsoft Defender enables attackers to obtain SYSTEM-level privileges on affected systems following the August 2026 Patch Tuesday.
A malvertising campaign on Bing promotes a fake Claude desktop app from a legitimate domain to deliver SectopRAT malware, posing a threat to affected systems.