Hunting CVE-2026-41096 (Windows DNS Client RCE, CVSS 9.8) in Advanced Hunting?

DeviceProcessEvents
| where Timestamp > ago(7d)
| where InitiatingProcessFileName =~ "svchost.exe"
| where InitiatingProcessCommandLine has_any ("dnscache", "NetworkService")
| where FileName !in~ ("conhost.exe", "WerFault.exe", "wermgr.exe")
| project Timestamp, DeviceName, FileName, ProcessCommandLine
| order by Timestamp desc

#CVE202641096 #KQL #ThreatHunting #MDE

Running Ubuntu 26.04 LTS as a daily driver, enrolled in Microsoft Intune with MDE, and it just works.

Linux endpoint management has come a long way. Zero friction, full compliance.

#Ubuntu #Intune #MDE #Linux #EndpointSecurity #Microsoft

📣📢 Announcing the 1st edition of the #workshop on #Quantum #Modeling, co-located with MODELS'26

Join us to explore the combination of quantum for model-driven engineering and #MDE for the development of quantum #hybrid systems

Beyond paper presentations, we plan to have a session to discuss and write down together a roadmap for this exciting area! 🤯

Details: ➡️ ➡️➡️ https://quantum-modeling-workshop.github.io/

QMod – 1st Workshop on Quantum Modeling – MODELS 2026

QMod 2026 — the 1st Workshop on Quantum Modeling, co-located with MODELS 2026. Bringing together model-driven engineering and quantum computing communities.

Payload: luad.exe (family: Alevaul)
SHA256: 88ec32a311b56441cfe6126b7780f073f36dfb8808de0dab9219d1a0be9c01ac
VT: https://www.virustotal.com/gui/file/88ec32a311b56441cfe6126b7780f073f36dfb8808de0dab9219d1a0be9c01ac
#MDE #Malware #IOC
VirusTotal

VirusTotal

⚠️ Heads up #infosec community
Found a malicious GitHub repo posing as a curated list of cybersecurity Telegram channels.
Every link in the README points to the same ZIP payload containing luad.exe (malware family: Alevaul). Detected by Microsoft Defender before execution.
VT 0/91 on URL but MDE flagged it as True Positive. Classic evasion.
🔗 https://github.com/simplefastfunnels254/tg-cybersec
Reported to GitHub under Active Malware / DSA Article 16.
#CyberSecurity #ThreatIntel #MDE #Malware #GitHub #OSINT

#WOBSGE – Überraschung

Bin ein bisschen müde. Müde über den Trainer zu lesen und auch müde über den Trainer zu schreiben. Aus diesem Grund versuche ich es heute weitestgehend zu vermeiden.

Auswärts in Wolfsburg also. Die Ausgangslage: Einzig realistisches Ziel in dieser Saison: Verteidigung von Platz 7. Aktuell zwei Punkte auf den, sehr manierlich auf drei Hoch

https://maintracht.blog/2026/04/11/wobsge-ueberraschung/

#Bundesliga #MMV #Auswrts #Mentalitt #Mde #Plan #Startpltze

Update 🧵
Rules ARE active, Event ID 1121 confirms blocking (WmiPrvSE → HPFirmwareInstaller blocked, LSASS protection firing daily).
But Get-MpPreference returns empty, registry key missing. TVM can't detect them → Secure Score stuck at 22/22 exposed.
Anyone seen this before? #MDE #Intune #DefenderForEndpoint
Weird Intune/MDE issue 🧵
ASR policy (Block PSExec/WMI) shows 38 Succeeded in Intune, but Get-MpPreference returns empty on endpoints and registry key doesn't exist.
AttackSurfaceReductionRules_ProviderSet = 1 in PolicyManager but no actual rule values written anywhere.
Cloud-only, no SCCM. Anyone seen this? #MicrosoftDefender #Intune #MDE
From PDF to LMS-Ready Assessments: Combining LLMs and Model-Driven Engineering

A PDF to QTI pipeline that leverages LLMs and model-driven engineering to genearate content for Learning Management Systems

Modeling Languages

Endpoints are where real work happens—and where most attacks begin. Laptops, desktops, and mobile devices sit at the intersection of users, data, and the internet, making them prime targets for attackers. With the rise of remote work, cloud-first strategies, and BYOD policies, the traditional network perimeter has all but disappeared.

Microsoft Defender for Endpoint (MDE) is designed for this reality. #defender #MDE #ThreatProtection

https://azuretracks.com/?p=2945