Signed software abused to deploy antivirus-killing scripts

2026-04-15T19:23:28Z81bdda596d62e4c00a2fb90416664963aabce03818ce40a91127352b9b2c28cd
.rdp hardeningBitLockerCISA advisoryChrome Web StoreKB5082052KB5082063KB5082200KB5083769Kraken extortion','fake-mac-apps','crypto-theft'],OAuth token theftRDP protectionsSalesforce misconfigurationWindows Server 2019/2022/2025Windows Task Hostadwareantivirus disablingcode-signing abusedata-breachextortionmalicious-browser-extensionspatch-tuesdayprivilege escalationsigned-softwaresupply-chainzero-day

What happened

A range of high-impact incidents and Microsoft security developments: a digitally signed adware tool deployed SYSTEM‑level payloads that disabled antivirus protections on thousands of endpoints across education, utilities, government and healthcare; CISA warned of a Windows Task Host privilege‑escalation being exploited to gain SYSTEM; Microsoft issued April 2026 Patch Tuesday fixes for 167 flaws (including two zero‑days) and multiple KB updates for Windows 10/11/Server though some updates (KB5082063) caused BitLocker recovery prompts. Other notable items: over 100 malicious Chrome extensions—

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
81bdda596d62e4c00a2fb90416664963aabce03818ce40a91127352b9b2c28cd
Enrichment time
2026-04-15T19:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.