Patch for Windows Defender 0-day could allow attac
2026年07月10日 04:522,625 次阅读
AI导读
A patch Microsoft released on Wednesday to fix a zero-day vulnerability in its Defender security engine may cause Windows machines to write files large enough to completely consume available disk space, the researcher who discovered the flaw said.
RoguePlanet, tracked as CVE-2026-50656, came to publ...
A patch Microsoft released on Wednesday to fix a zero-day vulnerability in its Defender security engine may cause Windows machines to write files large enough to completely consume available disk space, the researcher who discovered the flaw said.
RoguePlanet, tracked as CVE-2026-50656, came to public notice in June when NightmareEclipse, the pseudonymous name used by a researcher, disclosed it along with code for exploiting it. The vulnerability allows remote attackers to gain administrative control of Windows 10 and Windows 11 machines, even when real-time protection has been disabled. Over the past few months, the anonymous researcher has published a handful of other zero-days that have sent Microsoft scrambling to develop patches.
Writing files of unlimited size
Microsoft said Wednesday that it patched RoguePlanet with an update to the Microsoft Malware Protection Engine, which is used by the Defender antivirus app. The fix will automatically be downloaded and installed without users having to take any action. Wednesday’s update also includes “defense-in-depth updates to help improve security-related features.”Read full article
Comments
Dutch officials have warned that a high-severity macOS vulnerability that allows attackers to execute malicious code is under active exploitation.
“The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was acc...
OpenAI近日重申其Zero Data Retention政策,确保合格API客户的数据在处理后立即删除,不长期存储,以降低数据泄露风险。同时预览Private Safety Processing技术,实现高级安全检查如风险监控,而不损害用户数据隐私。此举回应了全球对AI数据隐私的关注,符合GDPR等法规要求,可能为AI行业树立新标准,增强客户信任并推动安全创新,促进负责任AI发展。