CISA says a Windows Task Host flaw is now being used by ransomware gangs
The vulnerability has moved from technical warning to observed criminal use.
SOURCE · BleepingComputerTHE BRIEF
CISA added a Windows Task Host vulnerability to its exploited-warning process after evidence that ransomware operators were using it in attacks. That changes the priority from theoretical exposure to an incident path already in use.
WHY IT MATTERS
Ransomware groups combine public vulnerabilities with stolen access and social engineering. A single unpatched endpoint can become the point from which credentials are taken, security tools are disabled and encryption spreads.
WHO SHOULD CARE
Windows administrators, vulnerability teams, managed service providers and incident responders.
WHAT TO DO NOW
- Apply Microsoft’s current security update to affected systems.
- Look for suspicious Task Host activity and related privilege changes.
- Prioritise internet-facing and privileged devices first.
VERIFICATION NOTE
Source basis: BleepingComputer reporting, with exploitation status attributed to CISA.
SecBriefs adds context and practical guidance. Reporting remains credited and linked to the original publisher.