Skip to content

Airvers Tech News

Focus on science and technology.

Primary Menu
  • Home
  • Technology
  • Science
  • Movie
  • Music
  • Game
  • Comic
  • Anecdote
  • Software
  • Home
  • Technology
  • Security researchers successfully hijack Windows 11’s Power Automate tool
  • Technology

Security researchers successfully hijack Windows 11’s Power Automate tool

Andrew 09/03/2022 2 min read

A research firm recently revealed that attackers hijackedWindows11 methods that come with automated tools to spread malware and steal data on the web. This process requires some permission conditions to be met, but it marks another area of ​​concern for IT security.

The vulnerabilities focus on Power Automate, a tool Microsoft has packaged in Windows 11 that lets users automate tedious or repetitive actions in various programs. Users can automatically back up files, convert to batch files, move data between programs, and more, with the option to automate cross-group operations through cloud computing.

Power Automate comes with many pre-built functions, but users can create new ones by recording their actions, which the tool can repeat later. The program can be widely used because it requires almost no programming knowledge.

Attackers can use Power Automate to spread malware payloads more quickly, according to Michael Bargury, CTO of security firm Zenity, who explained how in a June Defcon presentation. He released the attack code called Power Pwn in August.

The biggest obstacle to hacking with Power Automate is that the attacker needs to have full access to the target computer, or penetrate the network through other methods. If an attacker then created a Microsoft cloud account with administrative privileges, they could use an automated process to push ransomware or steal authentication tokens, Bargury told WIRED. Attacks using Power Automate can be harder to spot because it’s not technically malware and comes with an official signature from Microsoft.

An incident in 2020 saw attackers use a company’s automated tools against it. Windows 11 and Power Automate weren’t around at the time, but the case provides a real-world example of the same basic technology.

Microsoft claims that any fully updated system is immune to such threats, such as the ability to isolate compromised systems with registry keys. However, these safeguards, like all others, require some basic knowledge that users and companies don’t always have.

Related

Continue Reading

Previous: Three new features of the AirPods Pro 2 charging case revealed in leaked renderings
Next: Newly Discovered Browser Vulnerability Allows Overwriting Clipboard Content Could Seriously Affect Cryptocurrency Security

Read More

“League of Legends” S12 semi-finals are all confirmed: LPL only has JDG left to open the semi-finals on October 30
1 min read
  • Technology

“League of Legends” S12 semi-finals are all confirmed: LPL only has JDG left to open the semi-finals on October 30

10/23/2022
Tesla Model 3, Y slashed prices! Car owners collectively come to their homes to defend their rights, and some sales have been hit
1 min read
  • Technology

Tesla Model 3, Y slashed prices! Car owners collectively come to their homes to defend their rights, and some sales have been hit

10/23/2022
New Zealand’s plan to levy burp fees for cattle and sheep is blocked: farmers drive tractors to the streets to protest
1 min read
  • Technology

New Zealand’s plan to levy burp fees for cattle and sheep is blocked: farmers drive tractors to the streets to protest

10/23/2022

Archives

  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • “League of Legends” S12 semi-finals are all confirmed: LPL only has JDG left to open the semi-finals on October 3010/23/2022
  • Tesla Model 3, Y slashed prices! Car owners collectively come to their homes to defend their rights, and some sales have been hit10/23/2022
  • The world’s first phase 3 psychedelic clinical trial is about to begin10/23/2022
  • New Zealand’s plan to levy burp fees for cattle and sheep is blocked: farmers drive tractors to the streets to protest10/23/2022
  • Study: Newly discovered protein could help save lives10/23/2022

Newest

“League of Legends” S12 semi-finals are all confirmed: LPL only has JDG left to open the semi-finals on October 30
1 min read
  • Technology

“League of Legends” S12 semi-finals are all confirmed: LPL only has JDG left to open the semi-finals on October 30

10/23/2022
Tesla Model 3, Y slashed prices! Car owners collectively come to their homes to defend their rights, and some sales have been hit
1 min read
  • Technology

Tesla Model 3, Y slashed prices! Car owners collectively come to their homes to defend their rights, and some sales have been hit

10/23/2022
The world’s first phase 3 psychedelic clinical trial is about to begin
4 min read
  • Science

The world’s first phase 3 psychedelic clinical trial is about to begin

10/23/2022
New Zealand’s plan to levy burp fees for cattle and sheep is blocked: farmers drive tractors to the streets to protest
1 min read
  • Technology

New Zealand’s plan to levy burp fees for cattle and sheep is blocked: farmers drive tractors to the streets to protest

10/23/2022
  • Home
  • Technology
  • Science
  • Movie
  • Music
  • Game
  • Comic
  • Anecdote
  • Software
Copyright © All rights reserved.