Microsoft says a Russian hacker group has been exploiting an old Windows Print Spooler issue


by Neowin

Neowin— Microsoft has announced that a Russian hacker group has been exploiting an old Windows Print Spooler issue for as long as four years in order to "steal credentials in compromised networks."

MSPoweruser—Microsoft warns that Russian hackers target Windows Print Spooler. Microsoft has issued a warning about a new tool used by a Russia-linked hacking group to exploit a vulnerability in Windows Print Spooler software. There has been a history between Russian hackers and Microsoft with this and this. The hacking group, known as Forest Blizzard (also referred to as APT28, Sednit, Sofacy, and Fancy Bear), […]

Ars Technica—Windows vulnerability reported by the NSA exploited to install Russian malware. Microsoft didn't disclose the in-the-wild exploits by Kremlin-backed group until now.

Neowin—Microsoft: KB5036909 Windows Server update causing tremendous NTLM traffic issues on DCs. Microsoft confirmed yesterday that a VPN bug is affecting Windows 10 and 11, as well as Servers. Alongside that, the company has also confirmed that Server systems are also having NTLM traffic spikes.