The campaign exploits an Office vulnerability to deliver the modular XWorm RAT, chaining HTA, PowerShell, and in-memory .NET execution to sidestep detection and expand post-compromise control.
Microsoft plans Windows 11 “secure by default” mode with signed apps only and Android-style permissions for files, camera, ...