Security news aggregator

Latest coverage for PowerShell

Stay updated on PowerShell security with the latest news, insights, and expert analyses. Guard your systems effectively with our PowerShell security tag.

146 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

PowerShell

PowerShell is a cross-platform task automation solution consisting of a command-line shell, a scripting language, and a configuration management framework. Initially developed by Microsoft for Windows OS, it has since expanded to include support for Linux and macOS systems, making it a versatile tool in various IT environments.

In the context of information security, PowerShell plays a dual role. On one hand, it is a powerful tool for system administrators and security professionals for automation of administrative tasks, including security monitoring, log analysis, and the enforcement of security policies. PowerShell's advanced scripting capabilities allow for the creation of complex scripts that can streamline security processes, manage system configurations, and automate responses to security incidents. This helps in maintaining a strong security posture with efficiency and precision.

On the other hand, PowerShell is also known to be utilized by malicious actors. Due to its deep integration with the Windows operating system and its powerful capabilities, it can be used to carry out a variety of cyber attacks and malicious activities. Malware developers and attackers harness PowerShell to execute code remotely, escalate privileges, move laterally across a network, and even bypass security controls, as it allows the execution of commands without triggering traditional antivirus solutions. Understanding PowerShell's potential misuse is vital for the development of countermeasures such as restricting its usage, monitoring scripts and commands, and employing appropriate logging to detect and respond to malicious PowerShell activities.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 146 Filtered view
Bank Info Security 2 weeks, 1 day ago

Legacy Microsoft Utility Fuels New Wave of Malware

Researchers Link MSHTA Windows Utility to Lumma Stealer, ClickFix CampaignsCybercriminals continue abusing Microsoft’s legacy MSHTA utility to deliver malware, with researchers saying that the default-enabled Windows component remains a favored living-off-the-land tool for PowerShell attacks, info stealers and multi-stage malware loaders.

In Your Biggest Security Risk Isn't Malware — It's What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks like administration. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities your IT team uses every day are also the preferred toolkit of modern threat actors. Bitdefender's analysis

The North Korean threat actor known as Konni has been observed using PowerShell malware generated using artificial intelligence (AI) tools to target developers and engineering teams in the blockchain sector

The threat actor known as Storm-0249 is likely shifting from its role as an initial access broker to adopt a combination of more advanced tactics like domain spoofing, DLL side-loading, and fileless PowerShell execution to facilitate ransomware attacks

The threat actor known as Water Saci is actively evolving its tactics, switching to a sophisticated, highly layered infection chain that uses HTML Application (HTA) files and PDFs to propagate a worm that deploys a banking trojan via WhatsApp in attacks targeting users in Brazil

Bank Info Security 7 months, 1 week ago

Russia's Coldriver Revamps Malware to Evade Detection

Russian Intel Hackers Flexible in Face of DetectionRussia-linked threat group COLDRIVER rapidly replaced its exposed malware with a stealthier PowerShell variant, using fake CAPTCHA prompts and cryptographic key-splitting to evade detection and escalate surveillance on NGOs, dissidents and policy experts, according to new research.

Loading more headlines...