Microsoft adds Windows protections for malicious Remote Desktop files

2026-04-15T07:23:29Z8b1f7ad536ab7179433bbec76cae1c5b1a1412daee047e9e5bc5935f71a483ef
browser-extensioncertificate-forgerychromecode-signingcrypto-theftdata-breachextortionfbikrakenlaw-enforcementledgermacosmicrosoftoauth2patch-tuesdayphishingphishing-kitrdpremote-desktopsupply-chaintoken-theftw3llwindowswolfsslzero-day

What happened

A collection of April 2026 security news: Microsoft added protections for malicious Remote Desktop (.rdp) files and shipped April Patch Tuesday updates (Windows 10 KB5082200 and Windows 11 KB5083769/KB5082052) covering 167 flaws including two zero-days. Researchers found over 100 malicious Chrome Web Store extensions stealing Google OAuth2 bearer tokens and deploying backdoors, while a fake Ledger Live macOS app reportedly stole ~$9.5M. Critical vulnerabilities and incidents include a wolfSSL ECDSA verification flaw enabling forged certificates, an OpenAI code-signing certificate rotation tied

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
8b1f7ad536ab7179433bbec76cae1c5b1a1412daee047e9e5bc5935f71a483ef
Enrichment time
2026-04-15T07:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.