Microsoft observed ClickFix attacks using browser cache smuggling to execute cached VBScript and launch a credential-targeting malware chain.
Advances in technology have given us more powerful and versatile scripting languages, such as PowerShell and JavaScript. These languages offer broader capabilities and are better suited for modern web ...
2026年9月第三週的資安新聞熱點,聚焦歐盟CRA通報義務上路、AI安全爭議升溫與個資保護監管強化;針對網路、應用程式與端點的漏洞利用攻擊持續頻傳,國內外亦接連傳出企業遭駭,特別是義大利醫療機構遭勒索軟體攻擊造成多項醫療服務中斷近兩週,商周集團網站復原情形,亦突顯資安事件對營運韌性的實際衝擊 ...
この記事は会員限定です。会員登録(無料)すると全てご覧いただけます。 Microsoftは2024年5月22日(米国時間)、「VBScript」(Visual Basic Scripting Edition、VBS)について、廃止に向けたスケジュールを発表した。Microsoftは2023年10月に、WindowsクライアントでVBScriptを ...
An old Windows tool called MSHTA is being exploited by hackers to infect systems with malware, reveals the latest research from Bitdefender. Reportedly, this tool, which was created to work with ...
A surge in cyberattacks exploiting the Microsoft HTML Application Host (MSHTA), which is a legacy Windows utility, attackers continue to abuse it as aLiving-off-the-Land binary (LOLBIN) to execute ...
Attackers are increasingly abusing Microsoft’s decades-old MSHTA utility to stealthily deliver stealers, loaders, and persistent malware through phishing, fake software downloads, and LOLBIN-based ...
Bitdefender security researchers have discovered that attackers continue to exploit Microsoft HTML Application Host (MSHTA), a legacy utility available by default on Windows systems that can execute ...
Microsoft’s aging “mshta.exe” utility, a leftover component from Internet Explorer, is still being actively abused in modern malware campaigns years after the browser itself was retired. According to ...
Microsoft Defender Experts observed a campaign beginning in late February 2026 that uses WhatsApp messages to deliver malicious Visual Basic Script (VBS) files. Once executed, these scripts initiate a ...