Threat Analysis: Windows Task Host Ransomware Exploitation and Microsoft Copilot Command Injection, What UK SMBs Need to Know

Threats & Attacks

Threat Analysis: Windows Task Host Ransomware Exploitation and Microsoft Copilot Command Injection, What UK SMBs Need to Know

Hello, Mauven here.

This is your Daily Threat Analysis for 18th August 2026.

Two items today. Both involve Microsoft. Both affect organisations running standard Windows and Microsoft 365 infrastructure, which is to say, the vast majority of UK SMBs. Neither should wait until your next scheduled IT review.

Windows Task Host: Ransomware Gangs Now Confirmed Active

CISA has updated its Known Exploited Vulnerabilities catalogue to confirm that ransomware operators are actively exploiting a high-severity privilege escalation vulnerability in Windows Task Host. The flaw was first flagged as actively exploited back in April. That original notification was serious enough on its own. The ransomware confirmation changes the risk calculation entirely.

Here is what that means in plain terms. Privilege escalation vulnerabilities are not the initial entry point. They are what an attacker uses after they are already inside. An employee clicks a phishing link, opens a malicious attachment, or reuses a credential that has been compromised elsewhere. The attacker gets a low-privilege foothold on one machine. Without this kind of vulnerability, that foothold is contained. With it, the attacker escalates to system-level privileges and moves laterally across your network. That is the difference between one compromised endpoint and a ransomware deployment affecting every device you own.

Ransomware groups are opportunistic in their tooling. When CISA adds a flaw to its KEV catalogue with an explicit ransomware attribution, it is because multiple incidents have been observed and confirmed. This is not theoretical. This is documented post-exploitation activity.

The advisory was published in April. We are now in August. If your Windows estate has not been patched in the intervening four months, the question is not whether this represents a risk, it is how long that window has been open.

Your IT provider should have acted on the April advisory. If they did not contact you about it then, ask them today what the patch status is across your Windows endpoints. If they cannot tell you immediately, that is a problem in itself.

CVE-2026-24301: Microsoft Copilot Command Injection

Microsoft disclosed CVE-2026-24301 today, a command injection vulnerability in Microsoft Copilot that enables information disclosure over a network. The classification is improper neutralisation of special elements used in a command. An unauthenticated attacker can exploit this remotely.

The advisory language is measured, as Microsoft advisories tend to be. What it does not spell out is the access context. Copilot in Microsoft 365 is not a siloed application. It is deeply integrated with your organisation’s data, emails, documents, SharePoint content, Teams conversations. The permissions model is a direct reflection of what each user can access. If a user has broad access to sensitive business data and Copilot can be manipulated through command injection to disclose information, the attack surface is not a single feature. It is your entire Microsoft 365 data estate as seen through that user’s permissions.

Researchers at The Register have separately reported that Copilot can be socially engineered through manipulation of its reasoning engine, tricked into providing information it should not. CVE-2026-24301 is the technical vulnerability layer sitting alongside that social engineering surface. The two are not the same attack, but they point to the same conclusion: Copilot’s integration with your business data creates a meaningful attack surface that most organisations have not evaluated.

Microsoft has been pushing Copilot adoption aggressively across its M365 customer base. Many UK SMBs will have it enabled by default through their licensing tier without having made an active decision to deploy it. If you are in that position, the question is not just whether you have patched, it is whether you have reviewed what data Copilot can access and through whose credentials.

The Wider Context: C2Looper and Ransomware Delivery Chains

One additional item worth noting. Zscaler’s ThreatLabz published research this week on C2Looper, a new Rust-based backdoor assessed with low-to-medium confidence to be delivered through ClickFix infection chains and linked to ransomware-affiliated threat actors. It uses GitHub for command-and-control, a technique designed to blend malicious traffic with legitimate service communication and evade standard filtering.

This is worth flagging alongside the Windows Task Host story because it illustrates the delivery pipeline. ClickFix-style lures, fake browser error messages instructing users to paste commands into their own terminals, have been a consistent and effective initial access technique throughout 2025 and 2026. The sophistication of C2Looper’s C2 infrastructure suggests this is not a casual operation. If ransomware groups are using this backdoor in the same campaigns where they are deploying the Task Host privilege escalation exploit, the kill chain becomes: ClickFix lure → initial access → C2Looper backdoor → Task Host escalation → ransomware deployment.

That is a complete, documented attack chain. Every element of it has been observed in the wild.

What To Do

If you are responsible for Windows endpoints:

  • Verify patch status on the Windows Task Host privilege escalation vulnerability today. Do not wait for a scheduled maintenance window.
  • If you are running Windows 10 or Windows 11 environments that are not on a managed patching cycle, this is the prompt to establish one.

If your organisation uses Microsoft Copilot:

  • Identify which users have Copilot enabled and what their data access permissions look like.
  • Apply Microsoft’s patch for CVE-2026-24301 as soon as it is available through your update channels.
  • Review whether Copilot access has been granted to accounts with broader-than-necessary permissions, if a Copilot-enabled account can see sensitive financial or HR data, that scope needs to be assessed.

On ClickFix specifically:

  • Brief your staff. The attack vector is a fake browser prompt telling them to copy and paste a command. It looks plausible. It has caught technically literate users. Make sure your team knows this technique exists.

Before the next story: if Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically. And if someone in your network, a business owner, an operations manager, an IT support contact, would benefit from having this in their inbox, pass it on. The people who most need this information are often the least likely to go looking for it.


Sources

SourceTitleURL
CISA KEV / BleepingComputerCISA: Windows Task Host flaw now exploited by ransomware gangshttps://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/
Microsoft Security Response CenterCVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerabilityhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24301
The RegisterCopilot tricked into telling researchers how to hack itselfhttps://www.theregister.com/research/2026/08/18/copilot-tricked-into-telling-reseachers-how-to-hack-itself/5288857
BleepingComputerMicrosoft starts removing WMIC tool used by cybercriminalshttps://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windows-11-beta-builds/
Zscaler ThreatLabzC2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2

Filed under

  • smb-security
  • uk-business
  • ransomware-groups
  • credential-theft
  • cloud-security
  • business-risk
  • incident-response