Cybersecurity Incident: Passwords, Cookies and Login Tokens Stolen in Exploited Windows Bug January 26, 2024 – Posted in: Cyber Security, IT Support – Tags: , , , , ,

If you’re here to find out if you’re at risk there is one simple question to answer to find out – is your computer fully updated? If the answer is yes, you’re fine. If the answer is no, you could be vulnerably. Run the updates now.

The vulnerability is CVE-2023-36025 which was patched by Microsoft in November. It is a flaw in Windows Defender SmartScreen which allows criminals and malicious actors to infect PCs with a piece of malware called Phemedrone Stealer. This software trawls your computer for sensitive information including passwords, cookies and authentication tokens to steal.

Some software flaws or bugs are found by the good guys and patched before they are ever taken advantage of. But others are found by the bad guys before they can be fixed – in this case when the fix was first issued they warned that the bug was already being actively exploited by malicious actors. On top of this, shortly after Microsoft patched the vulnerability the patch was reverse-engineered so researchers could work out how the flaw might have been exploited – this proof-of-concept exploit has been published so anyone can now access and use it.

This is an example of why patching your computer – running updates and restarting – is so important. For more information on patching take a look at our infographic. If you have any concerns about cybersecurity, or would like to discuss any other IT Support needs you might have just give us a call on 01245 265100.