Advisory ID: ngCERT-2026-010002
SUMMARY/DESCRIPTION
ngCERT alerts organisations and users to an actively exploited zero-day vulnerability affecting Microsoft Windows Desktop Window Manager (DWM). DWM is a core Windows service responsible for managing visual effects, window composition, and graphical rendering in the operating system. The Vulnerability tracked as CVE-2026-20805 arises from improper handling of Advanced Local Procedure Call (ALPC) messages within the DWM service. An attacker with local access can send crafted ALPC requests that trigger memory disclosure, returning internal pointers and heap/base address details. While it does not directly permit remote code execution or privilege escalation in isolation, it can be leveraged to bypass core exploit mitigations such as Address Space Layout Randomization (ASLR). This significantly increases the reliability of subsequent exploit chains. This advisory provides details on the issue, its impact and recommended solutions.
Damage: Critical
Probability: High
Platform(s): Windows
CONSEQUENCES
Successful exploitation of this vulnerability could lead to:
- SLR Bypass: Leaking memory layout information directly undermines ASLR, a fundamental memory-hardening technique used to defend against buffer overflows and ROP attacks.
- Facilitated Exploitation: By revealing internal addresses, attackers can craft reliable exploits for other locally or remotely accessible vulnerabilities, increasing the likelihood of full system compromise.
- Exploit Chaining: It initiates multi-stage exploit chains, particularly in post-compromise lateral movement, privilege escalation, or persistence scenarios.
- Enterprise Risk: In corporate environments where attackers may already have footholds (e.g., via phishing or compromised credentials), this vulnerability strengthens the adversary’s ability to deepen access.
- Active Exploitation: Public reporting confirms active exploitation in the wild before patch deployment, underscoring real-world risk.
SOLUTION/MITIGATION
The following are recommended:
- Apply security updates immediately: Microsoft’s January 2026 Patch Tuesday updates for CVE-2026-20805 should be applied immediately to remediate the flaw.
- Restrict Local Access: Limit user accounts with local login to trusted personnel and use endpoint access controls to reduce exploit opportunities.
- Harden Processes: Employ Endpoint Detection and Response (EDR) with ALPC/DWM monitoring rules to detect suspicious interactions with DWM.
- Least Privilege: Review and enforce least privilege for all user accounts and services.
- Behavioural Monitoring: Monitor systems for unusual ALPC traffic patterns or unauthorized inter-process communications with dwm.exe
- ASLR-Aware Protections: Ensure other Microsoft security features, such as Virtualisation-Based Security (VBS) and Hypervisor Enforcement Code Integrity (HVCI), are enabled where supported.
- Patch Management: Incorporate timely patch deployment and vulnerability scanning into standard operations.
HYPERLINK
Advisory ID: NCC-CSIRT-2026-006
Summary:
Security researchers have identified an active spearphishing campaign in which threat actors are using Windows screensaver (.scr) files as delivery mechanisms to install legitimate Remote Monitoring & Management (RMM) tools for covert remote access and persistent control. The campaign begins with business-themed phishing (e.g., invoice or project summaries) that directs users to download and execute a .scr file from cloud storage. Because .scr screensavers are portable executable (PE) binaries that can run arbitrary code but are often overlooked by defenders, this vector allows attackers to bypass traditional detection controls and deploy RMM software to maintain access.
Once executed, the malicious screensaver silently installs the RMM agent, which establishes an encrypted remote connection to attacker-controlled infrastructure, enabling interactive remote sessions. Follow-on actions may include credential theft, lateral movement, data exfiltration, and staging for ransomware or other high-impact malware.
Damage/Probability: High/High
Product(s):
- Microsoft Windows operating systems and endpoints
- Remote Monitoring & Management (RMM) tools and agents (e.g., JWrapper-based SimpleHelp or similar)
- Cloud storage hosting services used to deliver malicious files
Version(s):
Not version-specific, affects Windows installations where users are tricked into executing Windows screensaver file types (.scr) without appropriate controls or restrictions.
Platform(s):
- Enterprise and corporate Windows workstations
- Laptops
- Servers with user-interactive endpoints capable of executing screensaver files.
Description:
Windows screensaver files (.scr) are portable executables capable of running arbitrary code, yet are often perceived by users as harmless. In the observed campaign, attackers embed remote monitoring and management (RMM) installers within .scr files hosted on trusted cloud platforms and distribute them via phishing emails using business-themed lures (e.g., “InvoiceDetails.scr”), increasing the likelihood of execution.
When run, the .scr file installs an RMM agent, establishes persistence in system directories, and initiates outbound connections to attacker-controlled servers for remote access. Because RMM tools are commonly used for legitimate administration, their activity blends into normal network behavior, making detection difficult; researchers note this technique is highly adaptable across cloud providers, lures, and RMM variants, limiting the effectiveness of signature-based defenses alone.
Threat Types:
- Spearphishing & social engineering: phishing emails with links to .scr files disguised as benign documents.
- Abuse of executable screensaver files: .scr files executing arbitrary code to install RMM software.
- RMM tool deployment for access & persistence: use of legitimate remote administration software as covert remote access tools.
- Living-off-the-land & defense evasion: use of trusted tools and filetypes to lower detection and raise stealth.
Impacts:
- Attackers gain persistent remote access and control over compromised hosts.
- Remote access allows capture of sensitive user credentials and intellectual property.
- With RMM agents in place, threat actors can propagate to adjacent systems and escalate privileges.
- The foothold may be used to position ransomware, RATs, or other destructive payloads.
- Because scouting and execution leverage legitimate infrastructure and filetypes, traditional signature-based tools may fail to alert.
Solutions:
NCC-CSIRT recommends the following mitigation steps:
- Block .scr execution via AppLocker/WDAC.
- Quarantine endpoints with unauthorized RMM tools.
- Filter and inspect suspicious cloud-hosted email links.
- Scan and hunt for rogue RMM services and processes.
- Train users on .scr and uncommon-extension phishing.
- Enforce least-privilege to prevent unauthorized installs.
- Detect living-off-the-land abuse with behavior analytics.
References:
Advisory ID: NCC-CSIRT-2026-005
Summary:
Cybersecurity researchers have uncovered a stealthy tactic employed by ransomware operators that involves abusing ISPsystem VMmanager virtual machines. Threat actors, including operators of major ransomware families such as LockBit, Qilin, BlackCat/ALPHV, WantToCry, and Ursnif-linked campaigns, are arming Windows VMs via hosting providers that use VMmanager. Because early templates of these VMs reuse identical hostnames and system identifiers, attackers can camouflage malicious servers among legitimate ones and evade detection and takedown efforts. This infrastructure is then used to host and deliver ransomware payloads at scale.
Damage/Probability: Critical/High
Product(s):
- ISPsystem VMmanager platform, virtualization management software used by hosting providers to deploy Windows/Linux virtual machines (VMs).
- Bulletproof hosting providers that deploy VMmanager-provisioned VMs.
- Ransomware payload delivery infrastructure using ISPsystem VMs for hosting and C2.
Version(s):
Affects default ISPsystem VMmanager Windows VM templates that reuse static hostnames and system identifiers, later updated to randomize hostnames.
Platform(s):
Internet-facing virtual machines provided by hosting services leveraging ISPsystem VMmanager, used as infrastructure for ransomware and malware distribution.
Description:
Sophos researchers observed that threat actors are using VMs provisioned via ISPsystem’s Vmmanager, a legit virtualization management platform, to host ransomware payloads and command-and-control (C2) services. The underlying issue exploited is a design weakness in default VM templates, where every new Windows VM receives the same hostname and system identifiers. This uniformity enables ransomware operators to scale infrastructure quickly while making malicious VMs appear consistent with benign ones from an automated monitoring perspective.
Attackers rent these VMs through bulletproof hosting providers that are known to tolerate or actively support cybercriminal operations. These providers often ignore law enforcement or abuse reports, further complicating disruption efforts. Once provisioned, these VMs serve as a stable platform that hosts ransomware payloads, staging scripts, or C2 endpoints for major ransomware families like LockBit, Qilin, BlackCat/ALPHV, WantToCry, and Ursnif-related campaigns.
The misuse of commodity infrastructure highlights a shift in how ransomware gangs manage their infrastructure: rather than building bespoke botnets, they leverage accessible, high-bandwidth cloud resources, effectively “blending in” with legitimate network traffic.
Threat Types:
- Infrastructure abuse: Leveraging legitimately provisioned virtual machines for malicious payload hosting.
- Evasion: Blending criminal infrastructure with legitimate cloud services to complicate detection and forensic attribution.
- Ransomware delivery: Hosting and distribution of ransomware installers and C2 infrastructure.
- Defense evasion: Use of bulletproof hosting providers that ignore abuse takedown requests.
Impacts:
- Ransomware campaigns gain persistent delivery infrastructure that may bypass security filters due to association with legitimate hosting platforms.
- Shared static identifiers and broad use by multiple threat actors make it harder for defenders to rapidly identify and remove malicious VMs.
- Ransomware operators operate a more resiliently distributed infrastructure, increasing the volume and scale of ransomware attacks globally.
- The method supports not just ransomware but adjacent campaigns involving info-stealers and other malware families.
Solutions:
NCC-CSIRT recommends the following mitigation steps:
- Block traffic to known malicious hosts using threat intel.
- Quarantine VMs with static or suspicious ISPsystem hostnames.
- Alert on ransomware IOCs and identical-hostname VM activity.
- Restrict outbound traffic to bulletproof hosts and unvetted VPNs.
- Hunt for ransomware infrastructure across network logs.
- Report abuse to hosting providers to limit malicious VMs.
- Block ransomware-linked VM instances.
- Detect cloud-based payload delivery via enhanced SIEM rules.
- Coordinate with cloud providers for VM randomization and fast takedowns.
References:
Advisory ID: NCC-CSIRT-2026-004
Summary:
Cybersecurity firm Mandiant, part of Google Cloud threat intelligence, has identified an active and escalating vishing (voice phishing) campaign attributed to threat actors associated with the ShinyHunters criminal syndicate and related clusters (tracked as UNC6661, UNC6671, UNC6240). These actors impersonate internal IT staff via telephone calls and direct employees to victim-branded credential harvesting sites, convincing them to enter single sign-on (SSO) credentials and multi-factor authentication (MFA) codes. Attackers then register their own devices, bypass MFA protections, and gain unauthorized access to corporate SaaS platforms, where they harvest sensitive data for extortion and financial gain. This campaign does not exploit software vulnerabilities in SaaS products but relies on advanced social engineering and real-time credential relaying.
Damage/Probability: Critical/High
Product(s):
- Identity Providers and Single Sign-On (SSO) Systems (e.g., Okta, Microsoft Entra/Azure AD, Google Workspace SSO).
- Cloud-based Software-as-a-Service (SaaS) Platforms (email, file storage, CRM, collaboration suites).
- Multi-Factor Authentication (MFA) mechanisms in enterprise environments.
Version(s):
Not product/version-specific, impacts any enterprise using SSO and MFA protections that rely on user-supplied codes, push approvals, SMS, or help-desk resets without phishing-resistant second factors.
Platform(s):
- Corporate identity systems
- Workforce SSO dashboards
- Cloud applications (Microsoft 365, Okta, Google Workspace, SharePoint, OneDrive, Salesforce, Slack, etc.).
Description:
Mandiant and related threat intelligence sources report that since early January 2026, sophisticated vishing operations have been targeting enterprise employees across sectors. Adversaries call targets impersonating legitimate IT support or security personnel, claiming an urgent need to update MFA or verify credentials. Victims are guided to company-branded phishing domains that imitate real SSO login portals. While still on the call, attackers capture single sign-on credentials and MFA codes, then immediately use them to authenticate on the legitimate SSO portal, effectively bypassing MFA protections and enrolling attacker-controlled devices for persistent access.
Once access is achieved, threat actors can traverse the SaaS environment, including email, file shares, collaboration tools and CRM systems, to exfiltrate sensitive data and internal communications. In many cases, attackers export data and later contact organizations with extortion demands or harass personnel to pressure compliance.
This activity is tracked under multiple clusters (UNC6661, UNC6671, UNC6240) and appears to be an evolution of ShinyHunters-brand extortion operations, expanding across SaaS ecosystems and leveraging social engineering tradecraft rather than technical exploits.
Threat Types:
- Vishing: Calls posing as IT/help desk to steal credentials and MFA codes.
- Credential phishing + MFA bypass: Real-time phishing sites capture logins and MFA tokens.
- SSO compromise & Cloud pivoting: Stolen identities used to access SaaS and linked services.
- Data theft & Extortion: Exfiltrated data used for ransom and follow-on phishing.
Impacts:
- Unauthorized access to identity/SSO systems, bypassing MFA.
- Sensitive data stolen from connected cloud apps (email, files, CRM, chat).
- Hijacked accounts used for internal phishing or lateral movement.
- Ransom extortion, staff harassment, and operational disruption.
- Data breaches cause fines, reputational damage, and loss of trust.
Solutions:
NCC-CSIRT recommends the following mitigation steps:
- Use phishing-resistant MFA (FIDO2 keys/passkeys), not SMS, push, or email codes.
- Run targeted vishing and social-engineering simulation training.
- Enforce strict MFA request verification, including supervisor call-backs.
- Review MFA enrollments, remove suspicious devices, and apply conditional access.
- Use SIEM and UEBA to detect suspicious cross-platform access.
- Apply least-privilege access and segment cloud environments.
- Enable detailed identity audit logs and retain them for forensics.
- If compromised, revoke sessions/devices and reissue credentials with strong MFA.
- Investigate lateral movement and data exfiltration (API/OAuth activity) after compromise.
References:
-
https://cybernews.com/cybercrime/shinyhunters-link-sso-vishing-attacks-okta-paywall/
-
https://www.computerweekly.com/news/366637762/Wave-of-ShinyHunters-vishing-attacks-spreading-fast
-
https://www.redsecuretech.co.uk/blog/post/shinyhunters-ramp-up-vishing-attacks-on-saas-platforms/853
-
https://kbi.media/press-release/mandiant-warns-of-active-shinyhunters-vishing-campaign-targeting-enterprise-identity-systems/
-
https://thehackernews.com/2026/01/mandiant-finds-shinyhunters-using.html
Advisory ID: NCC-CSIRT-2026-003
Summary:
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2024-37079, a critical heap-overflow vulnerability in VMware vCenter Server, to its Known Exploited Vulnerabilities (KEV) catalogue following confirmed evidence of active exploitation in the wild. This vulnerability allows a remote attacker with network access to send specially crafted packets that trigger a remote code execution (RCE) condition on vulnerable vCenter systems.
VMware originally released a patch for this flaw in June 2024, but recent security advisory updates by Broadcom confirm that exploitation has been observed in operational environments in early 2026. This context elevates the urgency for organizations relying on VMware virtual infrastructure to remediate without delay.
Damage/Probability: Critical/High
Product(s):
- Broadcom VMware vCenter Server
- Centralized management platform for VMware ESXi hosts
- Virtual machines
Version(s):
VMware vCenter Server versions before patched releases (patched in June 2024), CVE-2024-37079 remains a risk where updates have not been fully applied.
Platform(s):
Virtualization management infrastructures across enterprise, cloud, government, and telecommunication data centers.
Description:
CVE-2024-37079 is a heap-overflow vulnerability in VMware vCenter Server’s DCE/RPC protocol implementation. When a specially crafted network packet is sent to a vulnerable vCenter instance, the flaw may allow execution of arbitrary code in the context of the vCenter Server process, essentially enabling an attacker to gain unauthenticated remote code execution without the need for valid credentials.
Broadcom’s updated advisory now confirms that CVE-2024-37079 is being exploited in real-world environments, prompting CISA to add it to the KEV catalogue and to require immediate action by relevant agencies and enterprises. Previously, the vulnerability was patched in June 2024, along with related heap-overflow issues affecting the same service.
There are no known effective workarounds that fully mitigate this RCE outside patching and network access restrictions; therefore, patch application and protective segmentation are paramount.
Threat Types:
- Critical Remote Code Execution (RCE) via heap overflow in the DCERPC (Distributed Computing Environment / Remote Procedure Call) protocol implementation.
- Unauthorized virtual environment compromise, vCenter Server typically runs with elevated privileges and controls ESXi hosts, making this attack vector especially high-impact.
- Potential lateral movement, virtual machine manipulation, and denial-of-service following successful exploit.
Impacts:
- Exploitation grants attackers high-privilege code execution on vCenter, enabling control over hosts, clusters, virtual machines, and permissions.
- With control over vCenter, adversaries can pivot within virtualized environments and deploy additional malicious payloads.
- vCenter Server is central to operations; compromise may lead to service outages, data loss, and administrative lockout.
- Attackers could access sensitive configuration and credential data stored within the virtual management plane.
Solutions:
NCC-CSIRT recommends the following mitigation steps:
- Update all VMware vCenter Server instances to the patched builds specified by Broadcom, consult the latest VMware advisory (VMSA-2024-0012.1 or later) to confirm exact target versions.
- Restrict network access to vCenter management interfaces — only trusted management hosts should have connectivity.
- Limit exposure of critical vCenter ports and services to internal networks; isolate management plane from general production traffic.
- Enable deep logging and review access logs for anomalous DCERPC traffic or exploit indicators; correlate events with external threat intelligence.
- Prepare playbooks for virtualization layer compromise; maintain backups of vCenter configurations and ensure out-of-band recovery options.
- Treat VMware vCenter Server as a top-priority asset for patching in the next maintenance window.
- Validate that all instances, including test, staging, and disaster-recovery nodes, are updated.
- Enforce MFA for administrative access to vCenter and related infrastructure.
- Deploy network IDS/IPS signatures tuned to identify crafted DCERPC exploit attempts.
- Inform virtualization service providers and cloud tenants if vCenter infrastructure is shared or outsourced.
References:
-
https://thehackernews.com/2026/01/cisa-adds-actively-exploited-vmware.htmlw
-
https://www.thaicert.or.th/en/2026/01/26/cisa-adds-vmware-vcenter-vulnerability-cve-2024-37079-to-kev-catalog-after-active-exploitation/
-
https://cybersecuritynews.com/vmware-vcenter-rce-vulnerability/
-
https://ilja-schlak.de/en/cisa-adds-vmware-vcenter-flaw-cve-2024-37079-to-the-kev-catalog/
- Automated FortiGate Attacks Exploit FortiCloud SSO to Alter Firewall Configurations
- Hackers Use LinkedIn Messages to Spread Remote Access Trojan (RAT) Malware Through DL Sideloader
- TLP:CLEAR-[ngCERT Security Advisory on Critical NI8MARE Vulnerability Affecting N8n Workflow Automation Platform]
- ZnDoor Malware Exploiting React2Shell Vulnerability to Compromise Network Devices