About this tag
The tag 'compromise' on WindowsForum.com covers cybersecurity topics related to system and network intrusions, including indicators of compromise (IOCs), post-compromise threat detection, and eviction strategies. Discussions include CISA tools like CHIRP for finding IOCs, eviction strategies for removing adversaries, and advisories on APT groups such as APT40 and APT29. Users also report personal experiences with compromised systems, such as strange files or altered graphics after a new Windows install, and issues with Remote Desktop app security. The content emphasizes practical steps for identifying and responding to compromises, with a focus on enterprise IT and government advisories.
  1. WindowsForum AI

    CISA’s Eviction Strategies Tool: A Game-Changer for Incident Response and Cyber Defense

    Every cybersecurity professional understands that the crucial moments following the discovery of a network intrusion can determine whether an organization successfully mitigates damage—or sustains irreversible loss. In these moments, the difference between success and failure hinges on having...
  2. News

    AA21-321A: Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activi

    Original release date: November 17, 2021 Summary Actions to Take Today to Protect Against Iranian State-Sponsored Malicious Cyber Activity • Immediately patch software affected by the following vulnerabilities: CVE-2021-34473, 2018-13379, 2020-12812, and 2019-5591. • Implement Link Removed. •...
  3. S

    Windows 10 Possible OS Hacked- Strange Folder and Files after new install

    I have been having strange computer problems for some time. I notice that the pictures and graphics are either morphed, altered or exact pictures of people I know, my friends, or other notable people that seem to be fit into the advertisements, pop ups or substituted for the regular images that...
  4. News

    AA21-200A: Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department

    Original release date: July 19, 2021 Summary This Joint Cybersecurity Advisory was written by the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) to provide information on a Chinese Advanced Persistent Threat (APT) group known in open-source...
  5. News

    AA21-148A: Sophisticated Spearphishing Campaign Targets Government Organizations, IGOs, and NGOs

    Original release date: May 28, 2021 Summary The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) are responding to a spearphishing campaign targeting government organizations, intergovernmental organizations (IGOs), and non-governmental...
  6. News

    VIDEO AA21-077A: Detecting Post-Compromise Threat Activity Using the CHIRP IOC Detection Tool

    Original release date: March 18, 2021 Summary This Alert announces the CISA Hunt and Incident Response Program (CHIRP) tool. CHIRP is a forensics collection tool that CISA developed to help network defenders find indicators of compromise (IOCs) associated with activity detailed in the following...
  7. News

    AA20-099A: COVID-19 Exploited by Malicious Cyber Actors

    Original release date: April 8, 2020 Summary This is a joint alert from the United States Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC). This alert provides information on...
  8. S

    Windows 8 Windows Remote Desktop app hacked

    I have got a second computer in my house and was going to have it up as much as possible for a Minecraft server. Both PCs Win 10 Pro x64 1809. I installed from the windows store the remote desktop app and started noticing Kaspersky blocking some attacks. (attached picture, mid-Oct) I...
  9. kemical

    Care needed with Classic Shell

    It has been reported that classic shell or associated files can or could be infected: Link Removed For an uninfected copy, download the utility directly from the author's website here.
  10. News

    TA14-353A: Targeted Destructive Malware

    Original release date: December 19, 2014 Systems Affected Microsoft Windows Overview US-CERT was recently notified by a trusted third party of cyber threat actors using a Server Message Block (SMB) Worm Tool to conduct cyber exploitation activities recently targeting a major entertainment...
  11. News

    MS14-085 - Important: Vulnerability in Microsoft Graphics Component Could Allow Information...

    Severity Rating: Important Revision Note: V1.0 (December 9, 2014): Bulletin published. Summary: This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow information disclosure if a user browses to a website containing specially crafted...
  12. News

    TA14-329A: Regin Malware

    Original release date: November 25, 2014 Systems Affected Microsoft Windows NT, 2000, XP, Vista, and 7 Overview On November 24, 2014, Symantec released a report on Regin, a sophisticated backdoor Trojan used to conduct intelligence-gathering campaigns. At this time, the Regin campaign has...
  13. News

    Untrusted Certificate Store to be updated

    Hi everyone, This post is to notify customers that Microsoft will revoke trust in an Intermediate Certificate Authority, DigiCert Sdn. Bhd. (Digicert Malaysia) in an update to be released through Windows Update. DigiCert Sdn. Bhd is a Malaysian subordinate CA under Entrust and Verizon (GTE...
  14. News

    MS11-049 - Important : Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure

    Severity Rating: Important Revision Note: V2.0 (August 9, 2011): Bulletin rereleased to announce a detection change to the update for Microsoft Visual Studio 2005 Service Pack 1 (KB2251481) to add detection for related software listed in the update FAQ. There were no changes to the...
  15. JMH

    Windows 7 Facebook Launches Bug Bounty Program

    Facebook Launches Bug Bounty Program | threatpost
  16. JMH

    Windows 7 Toshiba website hacked - email addresses and passwords exposed

    Toshiba website hacked – email addresses and passwords exposed | Naked Security
  17. reghakr

    Windows 7 Man infects college PCs to steal huge database

    A former college student has admitted taking part in a criminal scheme that used malware to steal and sell large databases of faculty and alumni, change grades, and siphon funds from other students' accounts. He used thumbdrives with malware he created to compromise the machines. At first, I...
  18. kemical

    Windows 7 Codemasters been hacked?

    Guy's check your email accounts. Today I received an email from codemasters: Keep safe!
  19. Super Sarge

    Windows 7 Thousands of Web Sites Hit With New Twist on Old SQL

    Thousands of Web Sites Hit With New Twist on Old SQL Injection Hack Thousands of Web Sites Hit With New Twist on Old SQL Injection Hack | Arik Hesseldahl | NewEnterprise | AllThingsD A relatively simple hack has been used to compromise at least 500,000 Web sites, and perhaps as many as 1.5...
  20. M

    The Windows Boot Process Can Be Killed by New Yonsole.A Backdoor According to Microsoft

    A new piece of malware is capable of killing the Windows boot process, according to Microsoft. Win32/Yonsole.A is a backdoor Trojan, a term that defines a piece of malicious code designed to compromise computers and subsequently connect to a server controlled by the attacker, receive and execute...