New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
2026-06-21T07:23:33Z•9eb11736b21ece4cdd76343af10cec70f5894e4d0506dffb473024a48b70695b
ChinaClickOnce abuseCrowdStrikeai securityclickoncecontinuous identityexposure managementidentity managementmicrosoft vulnerabilitiespatch tuesdaypersistenceruntime securitysoftware deploymentthird-party riskthreat landscapevulnerabilitieszero-day
What happened
CrowdStrike blog feed (mid‑June 2026) highlighting multiple security topics: a two‑part series on new abuse of Microsoft ClickOnce deployment (techniques for persistence and malicious delivery), the June 2026 Patch Tuesday covering 206 Microsoft vulnerabilities including three publicly disclosed zero‑days, guidance and product announcements for AI and identity (Continuous Identity for AI Agents), Falcon Exposure Management for third‑party environments, and the 2026 Technology Threat Landscape report focusing on China‑linked activity. Overall content calls attention to active attack techniques,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- crowdstrike_blog
- Record identifier
- 9eb11736b21ece4cdd76343af10cec70f5894e4d0506dffb473024a48b70695b
- Enrichment time
- 2026-06-21T07:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.