SecBriefs
← All briefs

CISA says a Windows Task Host flaw is now being used by ransomware gangs

The vulnerability has moved from technical warning to observed criminal use.

Hand-drawn SecBriefs editorial illustration: CISA says a Windows Task Host flaw is now being used by ransomware gangsSOURCE · BleepingComputer
© 2026 SecBriefs · Original illustration

THE BRIEF

CISA added a Windows Task Host vulnerability to its exploited-warning process after evidence that ransomware operators were using it in attacks. That changes the priority from theoretical exposure to an incident path already in use.

WHY IT MATTERS

Ransomware groups combine public vulnerabilities with stolen access and social engineering. A single unpatched endpoint can become the point from which credentials are taken, security tools are disabled and encryption spreads.

WHO SHOULD CARE

Windows administrators, vulnerability teams, managed service providers and incident responders.

WHAT TO DO NOW

  • Apply Microsoft’s current security update to affected systems.
  • Look for suspicious Task Host activity and related privilege changes.
  • Prioritise internet-facing and privileged devices first.

VERIFICATION NOTE

Source basis: BleepingComputer reporting, with exploitation status attributed to CISA.

Read original at BleepingComputer

SecBriefs adds context and practical guidance. Reporting remains credited and linked to the original publisher.