Windows 10: Google discovers a Windows exploit that points to distribution of spyware

Discus and support Google discovers a Windows exploit that points to distribution of spyware in Windows 10 News to solve the problem; Google’s in-house Threat Analysis Group has recently uncovered an exploit framework that takes advantage of vulnerabilities in web browsers and other... Discussion in 'Windows 10 News' started by GHacks, Dec 1, 2022.

  1. GHacks
    GHacks New Member

    Google discovers a Windows exploit that points to distribution of spyware


    Google’s in-house Threat Analysis Group has recently uncovered an exploit framework that takes advantage of vulnerabilities in web browsers and other system utilities. TAG has also linked the exploit framework to a Spanish software company based in Barcelona. The exploit framework is known to target vulnerabilities in Microsoft Defender, Google Chrome, and Mozilla Firefox.

    TAG is primarily one of Google’s expert-led lines of defense against state-sponsored attacks. However, TAG also keeps tabs on companies that let governments spy on political and moral opponents, dissidents, and journalists using tools of the surveillance trade. Officially, the Barcelona-based company claims to be nothing more than a custom security solution provider. However, the truth seems to be much more sinister. According to Google, this Spanish software company is one such commercial vendor of surveillance.

    ‘Continuing this work, today, we're sharing findings on an exploitation framework with likely ties to Variston IT, a company in Barcelona, Spain that claims to be a provider of custom security solutions.’

    These are the sentiments of TAG’s Benoit Sevens and Clement Lecigne who recently addressed the team’s findings. TAG also stated that ‘Their Heliconia framework exploits n-day vulnerabilities in Chrome, Firefox and Microsoft Defender and provides all the tools necessary to deploy a payload to a target device.’

    Google discovers a Windows exploit that points to distribution of spyware Google-unmasks-Windows-exploit-scaled.jpg

    As TAG found, the exploit framework has three main components:

    • Heliconia Noise: A Web framework that deploys renderer bug exploits. The framework then installs malevolent agents on the target system by deploying a Chrome sandbox escape.
    • Heliconia Soft: A second web framework that carries a PDF payload that contains the Windows Defender exploit currently tracked as CVE-2021-42298.
    • Heliconia Files: A set of exploits for Windows and Linux that target Firefox. One of these is currently being tracked as CVE-2022-26485.

    Yesterday, TAG stated that The growth of the spyware industry puts users at risk and makes the Internet less safe, and while surveillance technology may be legal under national or international laws; they are often used in harmful ways to conduct digital espionage against a range of groups. These abuses represent a serious risk to online safety, which is why Google and TAG will continue to take action against, and publish research about, the commercial spyware industry.’

    In other related news, Google is apparently developing tech to replace internet cookies.

    Thank you for being a Ghacks reader. The post Google discovers a Windows exploit that points to distribution of spyware appeared first on gHacks Technology News.

    read more...
     
    GHacks, Dec 1, 2022
    #1

  2. Security Flaw Discovered in Google Toolbar

    A security flaw has been discovered in Google's Toolbar which could allow criminals to steal data or install malicious software onto people’s computers. The flaw works by exploiting the toolbar’s ability to install new buttons, and allows a hacker to potentially disguise malicious code as a legitimate button due to the fact that the toolbar does not perform adequate checks when buttons are being installed. To become a victim of the vulnerability, a user would have to be tricked into clicking a link which would open a new popup window asking them to install a custom button, which appears to be installed from a legitimate site such as Google. It then needs to be run from the toolbar, and a user would have to agree to downloading and running an executable. Given the number of steps involved, the flaw is not being treated as critical, and Google is already working on a fix for the problem.

    Source: Yahoo! News
     
    Jimmy 2004, Dec 1, 2022
    #2
  3. Brink Win User
    How Windows was exploited in 2014


    Read more:
     
    Brink, Dec 1, 2022
    #3
  4. Google discovers a Windows exploit that points to distribution of spyware

    distribution lists

    What are the Third Party Apps you would suggest? Would they work with Outlook App on an Android?

    I'm looking to set up distribution lists on my cell phone.
     
    thinkingal, Dec 1, 2022
    #4
Thema:

Google discovers a Windows exploit that points to distribution of spyware

Loading...
  1. Google discovers a Windows exploit that points to distribution of spyware - Similar Threads - Google discovers exploit

  2. Do OSD deployments require an SCCM distribution point to be on-site?

    in Windows 10 Gaming
    Do OSD deployments require an SCCM distribution point to be on-site?: Hi I want to know, if I want to deploy operating systems through SCCM, should the SCCM distribution point be in the site where I intend to deploy the operating systems. Thanks...
  3. Do OSD deployments require an SCCM distribution point to be on-site?

    in Windows 10 Software and Apps
    Do OSD deployments require an SCCM distribution point to be on-site?: Hi I want to know, if I want to deploy operating systems through SCCM, should the SCCM distribution point be in the site where I intend to deploy the operating systems. Thanks...
  4. Do OSD deployments require an SCCM distribution point to be on-site?

    in Windows 10 Installation and Upgrade
    Do OSD deployments require an SCCM distribution point to be on-site?: Hi I want to know, if I want to deploy operating systems through SCCM, should the SCCM distribution point be in the site where I intend to deploy the operating systems. Thanks...
  5. Spyware

    in Windows 10 Software and Apps
    Spyware: I was just browsing the internet when an icon showed up on the taskbar, I hover onto it, it says "your location has recently been accessed", several minutes later, a window opened saying "Adding snap in to console" now that kinda scared me. Yes, it might be my little brother...
  6. Microsoft discovers SolarWinds Serv-U software 0-day exploit

    in Windows 10 News
    Microsoft discovers SolarWinds Serv-U software 0-day exploit: Microsoft has detected a 0-day remote code execution exploit being used to attack SolarWinds Serv-U FTP software in limited and targeted attacks. The Microsoft Threat Intelligence Center (MSTIC) attributes this campaign with high confidence to DEV-0322, a group operating out...
  7. Can Windows 10 deploy as SCCM Distribution Point?

    in Windows 10 Installation and Upgrade
    Can Windows 10 deploy as SCCM Distribution Point?: Hi,I will like some help on the below question if i turn Windows 10 as SCCM Distribution Point.1. How many concurrent connection it can connect up to?2. Any connectivity limitation?3. Are there any features or capabilities that we will miss if we use Windows 10 as a SCCM...
  8. spyware

    in AntiVirus, Firewalls and System Security
    spyware: While on my laptop I received a message stating that my computer was infected with "**** spy ware" and to call 1-888-561-9111 to get it removed. I was also asked for my Windows register key. The message stated that if I chose to close the screen, they would disable my...
  9. Google Feed updated and renamed to Discover

    in Windows 10 News
    Google Feed updated and renamed to Discover: Last year we introduced the Google feed to surface relevant content to you, even when you’re not searching. It’s grown dramatically over the past year: more than 800 million people use the feed each month to stay up to date on their interests. Today—as a part of three...
  10. spyware

    in AntiVirus, Firewalls and System Security
    spyware: I keep getting a thing that says my computer has spyware. I run the Windows Defender scan and it never finds anything. https://answers.microsoft.com/en-us/protect/forum/protect_other-protect_scanning-windows_10/spyware/c2b5d597-bd8d-4f26-8ccf-c9d15ec59500