HIGHAdvisorySep 03, 2026
Action required
Hunt for suspicious installer execution, disabled Windows Update services, and Defender configuration changes. Block known malicious domains and hash indicators of compromise. Scan endpoints for persistence mechanisms and verify Defender and Update services are running and functional.
Affected products
Microsoft