discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have disclosed new 'Plug and Pwn' attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges.

By Lawrence Abrams·Aug 12·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Image: bleepingcomputer.com

Security researchers have found a way to exploit Windows' Plug and Play feature to install vulnerable software and gain SYSTEM privileges. This can be done with fake USB devices and no user interaction.

Why it matters

This vulnerability affects Windows users and can be exploited to gain SYSTEM privileges, which is a significant security risk.

Imagine you plug a fake USB device into your computer, and it tricks Windows into installing bad software that lets hackers take control of your computer. This is called a Plug and Pwn attack, and it's a serious security risk.

Analysis

Plug and Pwn Attack Overview

The Plug and Pwn attack is a new type of attack that exploits the Windows Plug and Play feature to install vulnerable or insecure vendor software and gain SYSTEM privileges. This attack was presented at DEF CON 34 by security researchers Alejandro Hernando and Borja Martínez.

Abusing Windows Plug and Play

Windows supports a feature called co-installers, which automatically downloads and installs vendor software and drivers when a new USB device is inserted into a computer. In 2021, BleepingComputer reported on how this feature was abused along with a Razer Synapse vulnerability to give a standard Windows user SYSTEM privileges simply by plugging in a Razer mouse or keyboard.

The Research

The researchers used FaceDancer with Cynthion and GreatFET hardware connected to a small Linux computer to emulate USB devices. FaceDancer is a software framework for emulating USB devices, allowing researchers to define the descriptors, interfaces, device classes, and endpoints that a computer uses to identify connected devices.

The Attack Chain

The researchers demonstrated a zero-click physical attack that exploited behavior in Sierra Wireless and Sony FeliCa installation packages. The attack first impersonates a Sierra Wireless device, causing Windows to install software that can be abused to change the computer's DNS settings. The researchers then impersonate a Sony FeliCa device, which causes Windows to install additional Sony software that downloads files over an unencrypted connection.

Implications

The Plug and Pwn attack has significant implications for Windows users. It can be exploited to gain SYSTEM privileges, which is a significant security risk. The attack can be conducted with fake USB devices and no user interaction, making it a serious threat to Windows users.

Key points

  • Security researchers have disclosed new 'Plug and Pwn' attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges.
  • The attack can be conducted with fake USB devices and no user interaction.
  • The vulnerability affects Windows users and can be exploited to gain SYSTEM privileges, which is a significant security risk.
The Upside

If this vulnerability is patched quickly, Windows users can rest assured that their systems are secure. Additionally, the research behind this attack can help improve the security of Windows and prevent similar vulnerabilities in the future.

The Downside

If the vulnerability is not patched quickly, Windows users are at risk of being exploited by hackers. This could lead to significant security risks and potentially even data breaches.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritywindowsplug-and-playvulnerabilityexploit

Author

Lawrence Abrams

Intelligence analysis by

Llama

Published

Aug 12, 2026

Source

bleepingcomputer.com

Share

Topics

securitywindowsplug-and-playvulnerabilityexploit

Related

More from this desk

Aug 13·bleepingcomputer.com

WhatsApp rolls out new feature that flags potential scam messages

WhatsApp has started rolling out a new optional feature called Scam Alert, which uses a local machine learning model to warn users about potential scam messages. The model is trained on scam conversations reported by users and checks incoming messages from non-contacts fo…

Aug 13·wired.com

CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues

Internal records obtained by WIRED reveal how US Customs and Border Protection employees and contractors were accused of abusing sensitive government databases for personal reasons. The records contain hundreds of allegations of misuse of law enforcement databases, includ…

Aug 13·thehackernews.com

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Attackers have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040, which refers to a critical security feature bypass that stems from weak authentica…

Aug 12·bleepingcomputer.com

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

Researchers say a single IP is running an ongoing campaign that steals data exposed to guest users in Salesforce Experience Cloud and ServiceNow portals.