Microsoft adds Windows protections for malicious Remote Desktop files
ID: b33d1f92-3139-5dd8-9014-6b2b9482d184
STIX ID: report--b33d1f92-3139-5dd8-9014-6b2b9482d184
Feed Name: Bleeping Computer
Microsoft's April 2026 cumulative updates for Windows 10 and 11 add new protections against malicious RDP (.rdp) connection files: a one-time educational prompt, a security dialog that displays publisher verification and the remote address, and all local resource redirections disabled by default. The report warns that threat actors—including the Russian state-sponsored APT29—have abused preconfigured RDP files in phishing campaigns to redirect drives, capture clipboard data, and hijack authentication to steal files and credentials, and notes administrators can temporarily disable the new protections via a registry setting (though keeping them enabled is recommended).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
