Windows Defender patch may enable disk space exhaustion

A security update Microsoft released this week to address a zero-day flaw in Windows Defender could allow attackers to fill a computer's hard drive with data. The issue was identified by the researcher who originally disclosed the vulnerability.

Microsoft issued the patch on Wednesday for a flaw tracked as CVE-2026-50656. The update targets the Microsoft Malware Protection Engine used by Defender and installs automatically on affected systems.

Researcher NightmareEclipse reported on Thursday that the added protections can cause the mpengine.dll file to leak data. This occurs when the engine processes certain files through the SpyNet cloud service, bypassing normal size limits on quarantined content.

The researcher described a method using a custom SMB server to trigger the behavior. A malicious file paired with an oversized Zone.Identifier stream can lead Defender to hang while locking large amounts of disk space.

Microsoft has not yet confirmed the reported side effect. The disclosure continues an ongoing dispute between the researcher and the company that began earlier this year.

Makala yanayohusiana

A newly published zero-day exploit allows attackers with physical access to bypass BitLocker encryption on Windows 11 devices in seconds. The attack, named YellowKey, targets the default TPM-only configuration and grants full access to encrypted drives via a simple USB-based method.

Imeripotiwa na AI

Daemon Tools, a popular disk image mounting app, was compromised in a supply-chain attack starting April 8, delivering malware through official updates. Security firm Kaspersky reported infections on thousands of machines across over 100 countries. Users are urged to scan their systems immediately.

A ransomware group known as ShinyHunters exploited a critical zero-day flaw in Oracle’s PeopleSoft software to target about 100 organizations. The attackers stole gigabytes of data from victims, including the University of Nottingham, and issued extortion demands. Oracle has released a mitigation but not a full patch.

Imeripotiwa na AI

Google published proof-of-concept exploit code on Wednesday for a vulnerability in its Chromium browser that has gone unfixed for 29 months. The flaw affects Chrome, Microsoft Edge, and other Chromium-based browsers used by millions worldwide. It enables attackers to establish persistent connections for monitoring user activity and launching attacks.

Jumatatu, 27. Mwezi wa saba 2026, 10:16:43

Meccha Chameleon hit by malware in steam maps and discord hack

Jumamosi, 25. Mwezi wa saba 2026, 11:07:45

Meccha Chameleon Steam Workshop maps hit with malware

Alhamisi, 25. Mwezi wa sita 2026, 03:59:01

Microsoft extends Windows 10 Extended Security Updates to 2027

Jumatano, 10. Mwezi wa sita 2026, 05:54:08

Windows 11 June update adds low-latency mode and security fixes

Jumatatu, 8. Mwezi wa sita 2026, 12:50:36

Microsoft packages hit with credential-stealing malware for second time

Jumatano, 20. Mwezi wa tano 2026, 10:09:47

Microsoft warns of password reset exploits by hackers

Jumanne, 12. Mwezi wa tano 2026, 21:18:06

Bungie promises patch after marathon raid exploit griefing

Alhamisi, 7. Mwezi wa tano 2026, 00:48:14

Experts warn Microsoft Phone Link tool exploited by unknown threat

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa