Tuesday , December 3 2024
Microsoft

Microsoft Disables MSIX App installer protocol abused in attacks

Microsoft disables the ms-appinstaller protocol handler by default due to its misuse by several threat actors to spread malware.

“The observed threat actor activity abuses the current implementation of the ms-appinstaller protocol handler as an access vector for malware that may lead to ransomware distribution,” the Microsoft Threat Intelligence team said.

Cisco Confirms Active Exploitation Of Decade-Old WebVPN Vulnerability

Cisco has released an updated security advisory about CVE-2014-2120, a vulnerability in the WebVPN login page of Cisco Adaptive Security...
Read More
Cisco Confirms Active Exploitation Of Decade-Old WebVPN Vulnerability

TP-Link Archer Security Flaw Exposes Devices to Malicious Command Injection

A serious zero-day vulnerability has been found in TP-Link Archer, Deco, and Tapo routers, which could let attackers inject harmful...
Read More
TP-Link Archer Security Flaw Exposes Devices to Malicious Command Injection

IBM address multiple flaw in security verify access appliance

IBM revealed several critical vulnerabilities in its Security Verify Access Appliance, which could pose serious security risks to users identified...
Read More
IBM address multiple flaw in security verify access appliance

“Rockstar 2FA” Targets Microsoft 365 Users with AiTM Attacks

Cybersecurity researchers are alerting users about phishing email campaigns using a toolkit called "Rockstar 2FA" to steal Microsoft 365 account...
Read More
“Rockstar 2FA” Targets Microsoft 365 Users with AiTM Attacks

Workshop on “DDoS use cases & solutions for government & BFSI” held at BCS

A workshop on "DDoS use cases & solutions for government & BFSI" held at Bangladesh computer society premises on Saturday...
Read More
Workshop on “DDoS use cases & solutions for government & BFSI” held at BCS

Uganda confirms hack of central bank accounts, Refutes $17 Million Claim

Uganda’s finance ministry confirmed media reports that hackers breached the central bank’s systems and stole money, but refuted the claims...
Read More
Uganda confirms hack of central bank accounts, Refutes $17 Million Claim

CVE-2024-11667
Hackers actively exploiting Zyxel firewall to deploy Ransomware

CERT Germany and Zyxel have alerted about a serious vulnerability in Zyxel firewalls, identified as CVE-2024-11667. This flaw is being...
Read More
CVE-2024-11667  Hackers actively exploiting Zyxel firewall to deploy Ransomware

Daily Security Update Dated: 29.11.2024

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Update  Dated: 29.11.2024

CIRT-in flags Critical Flaw in Oracle Agile PLM Framework

CERT-In has flagged a security vulnerability in Oracle’s Agile Product Lifecycle Management (PLM) software, identified as CVE-2024-21287 and cataloged as...
Read More
CIRT-in flags Critical Flaw in Oracle Agile PLM Framework

Microsoft patches four vulnerabilities in its services

On November 26th, Microsoft patched four vulnerabilities detected in Dynamics 365 Sales, the Partner.Microsoft.Com portal, Microsoft Copilot Studio and Azure...
Read More
Microsoft patches four vulnerabilities in its services

ALSO READ:

India’s ISRO to launch AI enabled 50 Spy Satellites

Cybercriminals offer a malware kit that uses the MSIX file format and ms-appinstaller protocol handler. The changes are in effect in App Installer version 1.21.3421.0 or higher.

The attacks involve signed malicious MSIX application packages. These packages are distributed through Microsoft Teams or malicious ads for popular software on search engines like Google.

Since mid-November 2023, four different hacking groups have been exploiting the App Installer service for financial gain. In October 2023, Elastic Security Labs discovered a campaign involving fake MSIX Windows app package files for popular software like Google Chrome, Microsoft Edge, Brave, Grammarly, and Cisco Webex. These files were used to distribute a malware loader called GHOSTPULSE.

Microsoft disabled the MSIX ms-appinstaller protocol handler in Windows before, in February 2022, to block threat actors from using it to distribute harmful software like Emotet, TrickBot, and Bazaloader.

“Threat actors have likely chosen the ms-appinstaller protocol handler vector because it can bypass mechanisms designed to help keep users safe from malware, such as Microsoft Defender SmartScreen and built-in browser warnings for downloads of executable file formats,” Microsoft said.

Check Also

flowchart

Cloudflare logs faces major failure, losing 55% of user data

Cloudflare suffered an incident roughly 3.5 hours On November 14, 2024 impacting the majority of …

Leave a Reply

Your email address will not be published. Required fields are marked *