New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

2026-06-21T07:23:33Z9eb11736b21ece4cdd76343af10cec70f5894e4d0506dffb473024a48b70695b
ChinaClickOnce abuseCrowdStrikeai securityclickoncecontinuous identityexposure managementidentity managementmicrosoft vulnerabilitiespatch tuesdaypersistenceruntime securitysoftware deploymentthird-party riskthreat landscapevulnerabilitieszero-day

What happened

CrowdStrike blog feed (mid‑June 2026) highlighting multiple security topics: a two‑part series on new abuse of Microsoft ClickOnce deployment (techniques for persistence and malicious delivery), the June 2026 Patch Tuesday covering 206 Microsoft vulnerabilities including three publicly disclosed zero‑days, guidance and product announcements for AI and identity (Continuous Identity for AI Agents), Falcon Exposure Management for third‑party environments, and the 2026 Technology Threat Landscape report focusing on China‑linked activity. Overall content calls attention to active attack techniques,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
crowdstrike_blog
Record identifier
9eb11736b21ece4cdd76343af10cec70f5894e4d0506dffb473024a48b70695b
Enrichment time
2026-06-21T07:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.