Reading view
How We Added WebAuthn to a Browser-Based RDP Client
A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection.
The post How We Added WebAuthn to a Browser-Based RDP Client appeared first on Unit 42.

Microsoft confirms Office apps launch issues after June updates
Microsoft working on Defender patch for RoguePlanet zero-day
Hands on with Intelligent Terminal, an AI-powered Windows Terminal
Microsoft Threatening Security Researcher
An anonymous security researcher called โNightmare Eclipseโ has been publishing a series of significant security exploits against Microsoft Windowsโincluding one that breaks BitLocker. Microsoft has threatened legal action against the researcher. Lots of recriminations are being traded back and forth.
Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days
The bugs could be exploited to elevate privileges to System or create a denial-of-service (DoS) condition.
The post Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days appeared first on SecurityWeek.
Microsoft warns of new Defender zero-days exploited in attacks
Fake malware-signing service Fox Tempest dismantled by Microsoft
Microsoft says it dismantled a malware-signing-as-a-service (MSaaS) called Fox Tempest, which helped cybercriminals make malware appear legitimate.
The service let customers submit malicious files to be digitally signed with short-lived Microsoft-issued certificates, making the malware look legitimate and more likely to bypass security checks.
Fox Tempestโs service was built around a customer-facing signing workflow where cybercriminals could upload malicious binaries to a portal, have them signed with certificates valid for only 72 hours, and then receive files that appeared to come from a trusted software source.
Microsoft explicitly says this approach allowed malware to evade security controls and bypass defenses that would otherwise flag suspicious unsigned code. Many security tools treat signed binaries as more trustworthy than unsigned ones, especially in environments that rely on allow-lists and publisher reputation. Fox Tempest abused that assumption by using fraudulently obtained certificates to make malware blend in as legitimate software, increasing the likelihood of execution and successful delivery.
A trusted-looking certificate can help malware get past initial scrutiny, especially when paired with social engineering, paid ads, SEO poisoning, or fake download pages.ย In this campaign, the signing layer helped malicious installers masquerade as products like AnyDesk, Teams, PuTTY, and Webex, which is exactly the kind of abuse that can slip through control frameworks built around reputation and trust.
The fraudulent certificates were used to spread ransomware and infostealers. The effects of these malware campaigns were broad, with attacks affecting healthcare, education, government, and financial services across multiple countries.
How to stay safe
Microsoftโs disclosure shows how cybercrime has evolved beyond โmalware authorsโ into a service economy where one group specializes in producing trust and others monetize it.
For defenders, the strongest lesson is not to treat code signing as a standalone security control.ย
For consumers:
- Remember to only download software from the official vendor site, the Microsoft Store, or another source you already trust. Avoid download buttons on links sent via social media posts, direct messages or email.
- Be skeptical of โsponsoredโ search results and advertisements for popular apps.
- Use an up-to-date, real-time anti-malware solution that looks for malicious behavior rather than just signatures.

We donโt just report on threatsโwe remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices byย downloading Malwarebytes today.
Fake malware-signing service Fox Tempest dismantled by Microsoft
Microsoft says it dismantled a malware-signing-as-a-service (MSaaS) called Fox Tempest, which helped cybercriminals make malware appear legitimate.
The service let customers submit malicious files to be digitally signed with short-lived Microsoft-issued certificates, making the malware look legitimate and more likely to bypass security checks.
Fox Tempestโs service was built around a customer-facing signing workflow where cybercriminals could upload malicious binaries to a portal, have them signed with certificates valid for only 72 hours, and then receive files that appeared to come from a trusted software source.
Microsoft explicitly says this approach allowed malware to evade security controls and bypass defenses that would otherwise flag suspicious unsigned code. Many security tools treat signed binaries as more trustworthy than unsigned ones, especially in environments that rely on allow-lists and publisher reputation. Fox Tempest abused that assumption by using fraudulently obtained certificates to make malware blend in as legitimate software, increasing the likelihood of execution and successful delivery.
A trusted-looking certificate can help malware get past initial scrutiny, especially when paired with social engineering, paid ads, SEO poisoning, or fake download pages.ย In this campaign, the signing layer helped malicious installers masquerade as products like AnyDesk, Teams, PuTTY, and Webex, which is exactly the kind of abuse that can slip through control frameworks built around reputation and trust.
The fraudulent certificates were used to spread ransomware and infostealers. The effects of these malware campaigns were broad, with attacks affecting healthcare, education, government, and financial services across multiple countries.
How to stay safe
Microsoftโs disclosure shows how cybercrime has evolved beyond โmalware authorsโ into a service economy where one group specializes in producing trust and others monetize it.
For defenders, the strongest lesson is not to treat code signing as a standalone security control.ย
For consumers:
- Remember to only download software from the official vendor site, the Microsoft Store, or another source you already trust. Avoid download buttons on links sent via social media posts, direct messages or email.
- Be skeptical of โsponsoredโ search results and advertisements for popular apps.
- Use an up-to-date, real-time anti-malware solution that looks for malicious behavior rather than just signatures.

We donโt just report on threatsโwe remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices byย downloading Malwarebytes today.
Microsoft shares mitigation for YellowKey Windows zero-day
Microsoft Self-Service Password Reset abused in Azure data theft attacks
Microsoft plans to improve Windows 11 driver quality in 2026
Microsoft blames macOS update for undismissible Teams location prompts
Microsoft Disrupts Malware-Signing Service Run by โFox Tempestโย
โฏFox Tempest provides a service that cybercriminals use to distribute ransomware and other malware disguised as legitimate software.
The post Microsoft Disrupts Malware-Signing Service Run by โFox Tempestโย appeared first on SecurityWeek.