About this tag
The tag 'compromise' on WindowsForum.com covers cybersecurity topics related to system and network intrusions, including indicators of compromise (IOCs), post-compromise threat detection, and eviction strategies. Discussions include CISA tools like CHIRP for finding IOCs, eviction strategies for removing adversaries, and advisories on APT groups such as APT40 and APT29. Users also report personal experiences with compromised systems, such as strange files or altered graphics after a new Windows install, and issues with Remote Desktop app security. The content emphasizes practical steps for identifying and responding to compromises, with a focus on enterprise IT and government advisories.
-
CISA’s Eviction Strategies Tool: A Game-Changer for Incident Response and Cyber Defense
Every cybersecurity professional understands that the crucial moments following the discovery of a network intrusion can determine whether an organization successfully mitigates damage—or sustains irreversible loss. In these moments, the difference between success and failure hinges on having...- WindowsForum AI
- Thread
- cisa compromise coun7er cyber defense cyber incident cyber threats cyberattack prevention cybersecurity eviction incident management incident response mitre att&ck network security open source security operational security playbook-ng security automation security frameworks security software threat intelligence
- Replies: 0
- Forum: Security Alerts
-
AA21-321A: Iranian Government-Sponsored APT Cyber Actors Exploiting Microsoft Exchange and Fortinet Vulnerabilities in Furtherance of Malicious Activi
Original release date: November 17, 2021 Summary Actions to Take Today to Protect Against Iranian State-Sponsored Malicious Cyber Activity • Immediately patch software affected by the following vulnerabilities: CVE-2021-34473, 2018-13379, 2020-12812, and 2019-5591. • Implement Link Removed. •...- News
- Thread
- apt authentication cisa compromise cybersecurity data exfiltration exchange server exploitation fbi fortinet indicator infrastructure iran malware mitigation patch management protection ransomware threat actors vulnerability
- Replies: 0
- Forum: Security Alerts
-
S
Windows 10 Possible OS Hacked- Strange Folder and Files after new install
I have been having strange computer problems for some time. I notice that the pictures and graphics are either morphed, altered or exact pictures of people I know, my friends, or other notable people that seem to be fit into the advertisements, pop ups or substituted for the regular images that...- shooterd
- Thread
- compromise corruption data manipulation dll exe files folders graphics hacked installation internet issues malware oem screenshots security troubleshooting user support windows
- Replies: 1
- Forum: Windows Upgrade and Installation
-
AA21-200A: Tactics, Techniques, and Procedures of Indicted APT40 Actors Associated with China’s MSS Hainan State Security Department
Original release date: July 19, 2021 Summary This Joint Cybersecurity Advisory was written by the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) to provide information on a Chinese Advanced Persistent Threat (APT) group known in open-source...- News
- Thread
- apt40 china compromise compromised credentials credential access cyber threats cybersecurity exfiltration hainan indicator information security intellectual property lateral movement malware mitre network defense state security tactics threat actors vulnerability
- Replies: 0
- Forum: Security Alerts
-
AA21-148A: Sophisticated Spearphishing Campaign Targets Government Organizations, IGOs, and NGOs
Original release date: May 28, 2021 Summary The Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) are responding to a spearphishing campaign targeting government organizations, intergovernmental organizations (IGOs), and non-governmental...- News
- Thread
- apt29 cisa cobalt strike compromise cybersecurity detection email security emerging threats fbi government incident response indicator iso malware mitigation phishing risk management spear phishing threat actors user training
- Replies: 0
- Forum: Security Alerts
-
VIDEO AA21-077A: Detecting Post-Compromise Threat Activity Using the CHIRP IOC Detection Tool
Original release date: March 18, 2021 Summary This Alert announces the CISA Hunt and Incident Response Program (CHIRP) tool. CHIRP is a forensics collection tool that CISA developed to help network defenders find indicators of compromise (IOCs) associated with activity detailed in the following...- News
- Thread
- apt chirp cisa communication companion tool compromise forensics guidance incident response indicators of compromise malware network defense security siem solarwinds threat activity threat detection windows yara
- Replies: 0
- Forum: Security Alerts
-
AA20-099A: COVID-19 Exploited by Malicious Cyber Actors
Original release date: April 8, 2020 Summary This is a joint alert from the United States Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC). This alert provides information on...- News
- Thread
- apt cisa compromise covid 19 credential theft cybersecurity email security indicator malicious actors malware mitigation ncsc phishing ransomware remote access scam teleconferencing telework vpn
- Replies: 0
- Forum: Security Alerts
-
S
Windows 8 Windows Remote Desktop app hacked
I have got a second computer in my house and was going to have it up as much as possible for a Minecraft server. Both PCs Win 10 Pro x64 1809. I installed from the windows store the remote desktop app and started noticing Kaspersky blocking some attacks. (attached picture, mid-Oct) I...- spook84
- Thread
- antivirus attack compromise computer issues encryption hacks home server kaspersky malware minecraft network security reformat remote desktop rsa-2048 security teamviewer user concerns windows 10
- Replies: 3
- Forum: Windows Help and Support
-
Care needed with Classic Shell
It has been reported that classic shell or associated files can or could be infected: Link Removed For an uninfected copy, download the utility directly from the author's website here.- kemical
- Thread
- audacity boot record compromise computer safety download file security forum fosshub infection installation malware mbr repair security shell system repair testdisk update utility windows
- Replies: 1
- Forum: Windows Security
-
TA14-353A: Targeted Destructive Malware
Original release date: December 19, 2014 Systems Affected Microsoft Windows Overview US-CERT was recently notified by a trusted third party of cyber threat actors using a Server Message Block (SMB) Worm Tool to conduct cyber exploitation activities recently targeting a major entertainment...- News
- Thread
- antivirus backdoor c2 infrastructure compromise cybersecurity data loss destruction exploit hard drive indicator malware mitigation network propagation proxy security smb threats worm
- Replies: 0
- Forum: Security Alerts
-
MS14-085 - Important: Vulnerability in Microsoft Graphics Component Could Allow Information...
Severity Rating: Important Revision Note: V1.0 (December 9, 2014): Bulletin published. Summary: This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow information disclosure if a user browses to a website containing specially crafted...- News
- Thread
- aslr attack browser bulletin compromise graphics important information information disclosure jpeg microsoft patch public revision security system update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
TA14-329A: Regin Malware
Original release date: November 25, 2014 Systems Affected Microsoft Windows NT, 2000, XP, Vista, and 7 Overview On November 24, 2014, Symantec released a report on Regin, a sophisticated backdoor Trojan used to conduct intelligence-gathering campaigns. At this time, the Regin campaign has...- News
- Thread
- analysis attack components compromise cybersecurity encryption indicator intelligence malware network prevention rat regin remote access security trojan update user guide windows
- Replies: 0
- Forum: Security Alerts
-
Untrusted Certificate Store to be updated
Hi everyone, This post is to notify customers that Microsoft will revoke trust in an Intermediate Certificate Authority, DigiCert Sdn. Bhd. (Digicert Malaysia) in an update to be released through Windows Update. DigiCert Sdn. Bhd is a Malaysian subordinate CA under Entrust and Verizon (GTE...- News
- Thread
- authentication ca security certificate compromise digicert encryption intermedia malicious software malware microsoft response revocation root program security threats trust update vulnerability weak keys
- Replies: 0
- Forum: Security Alerts
-
MS11-049 - Important : Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure
Severity Rating: Important Revision Note: V2.0 (August 9, 2011): Bulletin rereleased to announce a detection change to the update for Microsoft Visual Studio 2005 Service Pack 1 (KB2251481) to add detection for related software listed in the update FAQ. There were no changes to the...- News
- Thread
- 2011 affected software compromise detection change disco file extended security updates information disclosure kb2251481 microsoft privately reported security security bulletin service pack update faq user rights visual studio vulnerability web services xml
- Replies: 0
- Forum: Security Alerts
-
Windows 7 Facebook Launches Bug Bounty Program
Facebook Launches Bug Bounty Program | threatpost- JMH
- Thread
- announcement bug bounty code injection compromise ddos facebook flaw hacking incentives information privacy programs report rumors script error security third party vulnerability
- Replies: 0
- Forum: Windows Security
-
Windows 7 Toshiba website hacked - email addresses and passwords exposed
Toshiba website hacked – email addresses and passwords exposed | Naked Security- JMH
- Thread
- compromise cybersecurity data breach electronics email exposure hacking information security password personal data phone privacy risk management sales security incident toshiba user data web server
- Replies: 0
- Forum: Windows Security
-
Windows 7 Man infects college PCs to steal huge database
A former college student has admitted taking part in a criminal scheme that used malware to steal and sell large databases of faculty and alumni, change grades, and siphon funds from other students' accounts. He used thumbdrives with malware he created to compromise the machines. At first, I...- reghakr
- Thread
- alumni awareness college compromise computer criminal scheme cybercrime data theft database ethics faculty funds grades hacking investigation it department malware security technology thumb drive
- Replies: 0
- Forum: Windows Security
-
Windows 7 Codemasters been hacked?
Guy's check your email accounts. Today I received an email from codemasters: Keep safe!- kemical
- Thread
- account security codemasters compromise customer service cyberattack data breach email estore game companies hacked intrusion investigation notifications password privacy safety scam security user data website
- Replies: 1
- Forum: Windows Games
-
Windows 7 Thousands of Web Sites Hit With New Twist on Old SQL
Thousands of Web Sites Hit With New Twist on Old SQL Injection Hack Thousands of Web Sites Hit With New Twist on Old SQL Injection Hack | Arik Hesseldahl | NewEnterprise | AllThingsD A relatively simple hack has been used to compromise at least 500,000 Web sites, and perhaps as many as 1.5...- Super Sarge
- Thread
- compromise cyberattack data breach fake software hackers internet lizamoon malware online safety redirect research security security industry sql sql injection virus vulnerability web security website
- Replies: 0
- Forum: Windows Security
-
M
The Windows Boot Process Can Be Killed by New Yonsole.A Backdoor According to Microsoft
A new piece of malware is capable of killing the Windows boot process, according to Microsoft. Win32/Yonsole.A is a backdoor Trojan, a term that defines a piece of malicious code designed to compromise computers and subsequently connect to a server controlled by the attacker, receive and execute...- Mitchell_A
- Thread
- antivirus backdoor boot process boot record compromise computer issues cybersecurity infection malicious software malware mbr microsoft protection remote server security trojan user control virus windows yonsole
- Replies: 0
- Forum: Windows News