Windows exploits unpatched vulnerabilities, attack risk increases

Cát Tiên |

Windows faces security risks when hackers exploit unpatched vulnerabilities, after the attack code was made public online in a short time.

Hackers are taking advantage of unpatched security vulnerabilities in the Microsoft Windows operating system to infiltrate organizational systems, raising concerns about a new wave of cyber attacks when exploit codes are publicly available on the internet.

According to the US cybersecurity company Huntress, their experts have detected at least one organization being hacked through three vulnerabilities named BlueHammer, UnDefend and RedSun.

Notably, these vulnerabilities were announced with exploitation codes in just the past two weeks, allowing hackers to quickly take advantage of them to attack.

Among the three vulnerabilities, only BlueHammer has been patched by Microsoft earlier this week. The remaining two vulnerabilities have not been fully fixed, increasing risks for users and businesses.

Experts believe that the public disclosure of the exploitation code has significantly shortened the time from detecting the error to being exploited in practice.

The origin of the exploit codes is believed to be from a security researcher using the nickname Chaotic Eclipse.

Earlier this month, this person posted a clip exploiting an unpatched vulnerability on his personal blog, alluding to a conflict with Microsoft. Then, they continued to publish two other vulnerabilities with the same exploit code on the GitHub platform.

All three vulnerabilities are related to Windows Defender, which is a security software integrated in Windows.

If exploited, hackers can gain high-level access, even administrator rights on the affected system. This allows them to control devices, steal data or deploy deeper attacks.

A Microsoft representative said that the company supports disclosing the vulnerability according to a coordination process, in which researchers report the error to the manufacturer before making it public.

This approach helps ensure that the vulnerability is handled promptly, limiting risks for users. However, in this case, the coordination process did not seem to go smoothly.

In the cybersecurity industry, publicizing vulnerabilities with exploit codes is often called "comprehensive publicity".

Although it can help the community clearly recognize the seriousness of the problem, this approach also creates conditions for cybercriminals to quickly take advantage of available tools to attack.

According to Mr. John Hammond, a researcher at Huntress, the accessibility of mining tools is pushing security experts into a race against hackers.

When the attack code is made public, organizations are forced to urgently update the system and deploy defensive measures to minimize damage.

This incident shows the dangerous gap between the speed of technology development and the ability to protect the system.

In the context that vulnerabilities can be exploited almost immediately after being leaked, software updates and increased network security are no longer an option, but have become mandatory requirements for all organizations.

Cát Tiên
RELATED NEWS

Google launches its own AI application for Windows, integrating comprehensive search

|

Google launches new desktop application for Windows, taking artificial intelligence as the center of experience.

Familiar features of Windows 10 return on Windows 11

|

Microsoft reveals Windows 11 will allow taskbar movement, meeting long-awaited expectations and improving the personalized experience for users.

Da Nang establishes grassroots trade union of An Duc Phat Windows Joint Stock Company

|

Da Nang - Thang An Commune Trade Union, Da Nang City established the grassroots Trade Union of An Duc Phat Windows Joint Stock Company.

Salary reform from the Central to local levels, implemented in all 3 blocs

|

The Ministry of Home Affairs is assigned to carefully prepare the reform of salaries, allowances and other regimes from the Central to local levels, implemented in all 3 blocs.

Forecast of the risk of receiving strong storms and super typhoons in 2026

|

According to a representative of the meteorological agency, ENSO phase transition along with the impact of climate change leads to the risk of strong storms and super typhoons in 2026.

Designer Duc Hung: For me, ao dai is perfectly beautiful, it needs to be promoted all over the world

|

In the program "Saturday Afternoon Coffee", designer Duc Hung shared his perspective on Vietnamese fashion in the context of cultural industry development.

Clean water brings many positive changes to rural people

|

Hanoi - After a few years of using clean water, the worries and hardships in daily life of people in Phong Trieu village, Phu Xuyen commune have been improved.

Central Highlands Regional General Hospital has not completed legal procedures, infrastructure is degraded

|

Dak Lak - Despite operating for nearly 7 years, the Central Highlands Regional General Hospital has not yet completed legal documents, while the infrastructure has seriously deteriorated.

Google launches its own AI application for Windows, integrating comprehensive search

QUANG MINH |

Google launches new desktop application for Windows, taking artificial intelligence as the center of experience.

Familiar features of Windows 10 return on Windows 11

Cát Tiên |

Microsoft reveals Windows 11 will allow taskbar movement, meeting long-awaited expectations and improving the personalized experience for users.

Da Nang establishes grassroots trade union of An Duc Phat Windows Joint Stock Company

Tường Minh |

Da Nang - Thang An Commune Trade Union, Da Nang City established the grassroots Trade Union of An Duc Phat Windows Joint Stock Company.