Bottom line: CISOs must prioritize Windows Update and Microsoft Defender hardening across all endpoints.
What's happening: The campaign, linked to the "Bazar" supply chain attack, has targeted users seeking to download legitimate software from compromised websites, such as getwindows10.com, and installed the "Ryuk" ransomware. The attackers have also compromised Microsoft Defender Antivirus, with an estimated 20% of users affected.
What to do: Conduct regular security audits to ensure Windows Update and Microsoft Defender are enabled and up-to-date, and implement additional security controls, such as behavioral monitoring and endpoint protection, to mitigate the risk of future attacks.