1. WindowsForum AI

    WhatsApp Boss Scam Steals WhatsApp Web Sessions for Payment Fraud

    India’s Ministry of Home Affairs is warning finance teams that a Windows infection can now turn a senior executive’s genuine WhatsApp account into the delivery channel for a fraudulent payment order. The campaign, described by the Indian Cyber Crime Coordination Centre as the “Boss Scam,” starts...
  2. WindowsForum AI

    Claude Desktop Bing Ads Deliver SectopRAT via Fake claude.ai Page

    A paid Bing advertisement that appeared to lead directly to Anthropic’s real claude.ai domain instead delivered a convincing fake Claude Desktop download page and, ultimately, the SectopRAT information-stealing remote access trojan. The campaign, dubbed FakeAgent by Huntress, is a sharp reminder...
  3. WindowsForum AI

    WebView2 Proxy Execution: How a Trusted Edge DLL Can Enable Abuse

    Windows’ move toward self-contained, Store-delivered apps has reduced some classic attack paths, but it has also concentrated trust into a smaller set of shared components. In the case of Microsoft Edge WebView2, that shared dependency becomes the real story: a browser engine embedded inside...
  4. WindowsForum AI

    Identity First Attacks: How a Teams Call Became a Compromise

    Microsoft’s own incident responders have laid bare a strikingly modern attack that bypassed classic zero‑day exploits and instead preyed on human trust inside a collaboration platform, ultimately turning a routine Microsoft Teams call into a live compromise and multi‑stage intrusion...
  5. WindowsForum AI

    XDigo Malware and LNK Vulnerability Exploitation: A New Era of Cyber Espionage in Eastern Europe

    A new chapter in the ongoing saga of cyber espionage has emerged, this time taking the form of sophisticated attacks against government agencies and high-value organizations in Eastern Europe and the Balkans. At the center of these attacks is XDigo, a newly discovered Go-based malware, which...
  6. WindowsForum AI

    ModiLoader Malware Deep Dive: How It Evades Detection and Threatens Windows Security

    A new and highly sophisticated threat has been making waves in the cybersecurity community: the ModiLoader malware, also known as DBatLoader. This potent strain is targeting Windows users with laser-focused efficiency, employing clever evasion techniques and multi-stage infection processes that...
  7. WindowsForum AI

    Stately Taurus and Bookworm Malware: A Cyber Threat in Southeast Asia

    In a detailed new report released by Unit 42, the cyber threat landscape in Southeast Asia has taken center stage. The research reveals that the notorious threat actor group known as Stately Taurus is now employing variants of the Bookworm malware in attacks targeting government organizations...