GKRootWire
AI Stripe's OpenRouter Buy Is About Payments, Not the SingularityGadgets Amazon Sets Sights on 500 Neighborhoods for Drone Delivery by 2026Security Kansas Police Department Pulls the Plug on Flock License Plate CamerasAI ChatGPT Goes Down Hard as Logins and Signups BreakDev Tools New Algorithm Speeds Up Day-of-Week CalculationsDev Tools Why 'Turns' Might Beat Radians for Angle Math in CodeAI Stripe's OpenRouter Buy Is About Payments, Not the SingularityGadgets Amazon Sets Sights on 500 Neighborhoods for Drone Delivery by 2026Security Kansas Police Department Pulls the Plug on Flock License Plate CamerasAI ChatGPT Goes Down Hard as Logins and Signups BreakDev Tools New Algorithm Speeds Up Day-of-Week CalculationsDev Tools Why 'Turns' Might Beat Radians for Angle Math in Code
Security

CISA Confirms Ransomware Gangs Now Exploiting Windows Task Host Bug

A high-severity flaw flagged in April as actively exploited has spread to ransomware operators' toolkits.

CISA has updated its guidance on a high-severity Windows Task Host vulnerability, confirming that ransomware groups are now weaponizing the flaw in real-world attacks. The bug was first added to CISA's Known Exploited Vulnerabilities catalog back in April after evidence surfaced that attackers were already abusing it, though details at the time suggested more targeted use.

The agency's latest warning signals a shift from limited exploitation to broader adoption by financially motivated ransomware crews, who tend to move quickly once a working exploit proves reliable. Windows Task Host handles scheduled and background tasks system-wide, making it an attractive target for attackers seeking to execute malicious code or escalate privileges on compromised machines.

Organizations that haven't yet applied Microsoft's patch for this vulnerability are urged to do so immediately, as federal agencies face mandatory deadlines under CISA directives.

Why it matters: When CISA reclassifies a vulnerability from 'actively exploited' to 'exploited by ransomware,' it usually means the exploit has been commoditized and shared across criminal groups, sharply raising the odds any unpatched system gets hit. Sysadmins should treat this as a signal to prioritize patching over routine maintenance windows.

Sources: BleepingComputer