CISA: Windows Task Host flaw now exploited by ransomware gangs
CISA has confirmed that ransomware groups are actively exploiting a high-severity vulnerability in Windows Task Host, a flaw that was first flagged as under active exploitation in April. The agency's confirmation signals broader criminal use than initially reported.
Why this matters: Ransomware gangs do not wait for organizations to patch. They move fast, and CISA confirming active exploitation means the window to fix this is already closing. Windows Task Host runs on essentially every Windows machine, so the exposure here is wide. If your organization has not applied the patch, the question is not whether attackers know about this flaw. They clearly do. Slow patch cycles are a business risk with a price tag attached, and ransomware crews are the ones setting it.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.