Skip to content
Threat Feed

Product

Visual Studio

6 briefs RSS
high advisory

New Abuse of ClickOnce Technology for Malware Distribution

Threat actors are actively abusing Microsoft's ClickOnce technology, a legitimate application deployment mechanism, to spread malware by leveraging its user-friendly deployment process, often without requiring administrative privileges, enabling easy installation and persistence of malicious applications once a user initiates the deployment.

ClickOnce technology +1 clickonce malware application-deployment windows initial-access execution
3r 3t
high advisory

CVE-2026-41109: Improper Neutralization of Special Elements in GitHub Copilot and Visual Studio

CVE-2026-41109 describes an improper neutralization of special elements in output used by a downstream component ('injection') vulnerability in GitHub Copilot and Visual Studio, allowing an unauthorized attacker to bypass a security feature over a network.

GitHub Copilot +1 injection cve github visual studio
2r 1t 1c
high advisory

Suspicious MSBuild Spawned by WMI Provider Process

The analytic identifies instances where wmiprvse.exe spawns msbuild.exe, an unusual process relationship indicative of potential COM object misuse and unauthorized code execution on Windows systems.

Splunk Enterprise +3 living-off-the-land defense-evasion msbuild
2r 1t
high advisory

Microsoft Devtunnels Execution for Covert Communication

The execution of Microsoft devtunnels.exe can be abused by attackers to expose compromised systems to the internet, establish covert communication channels, and bypass network security measures, facilitating data exfiltration or command-and-control.

Visual Studio +3 devtunnels reverse-proxy command-and-control defense-evasion windows
2r 1t
low advisory

Windows Scheduled Task Creation for Persistence

Adversaries may create scheduled tasks on Windows systems to establish persistence, move laterally, or escalate privileges, and this detection identifies such activity by monitoring Windows event logs for scheduled task creation events, excluding known benign tasks and those created by system accounts.

OneDrive +5 persistence scheduled-task windows
3r 1t
medium advisory

Microsoft Devtunnels Image Load Detection

This detection identifies potential misuse of Microsoft Devtunnels within Visual Studio by detecting image load events, indicating that an attacker could expose a compromised system or service to the internet for covert communication and data exfiltration.

Visual Studio +3 devtunnels reverse-proxy command-and-control data-exfiltration windows
2r 2t