Microsoft has added new Windows protections to blunt phishing attacks that use malicious Remote Desktop connection (.rdp) files to connect victims to attacker-controlled systems and expose local resources. The changes, delivered through recent cumulative updates for Windows 10 and Windows 11, introduce clearer security warnings, display publisher and remote system details, and alert users when RDP files are unsigned before a connection is established.
The updated behavior also disables risky redirected local resource options by default when users open .rdp files directly, limiting abuse of shared drives, clipboard access, and other redirections that can be used to steal files, credentials, or authentication data. Microsoft said the protections target a technique long used in phishing campaigns, including by APT29, though they do not apply when connections are launched from the Windows Remote Desktop client itself; administrators can temporarily turn the safeguards off through a Registry policy setting, but Microsoft recommends keeping them enabled.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
After shipping the April 14 Windows protections for malicious .rdp files, Microsoft disclosed a Known Issue causing the new warning dialog to render incorrectly, with overlapping text or partially hidden buttons, especially on multi-monitor systems with mixed display scaling. Microsoft said the issue is largely cosmetic and will be fixed in a future Windows update.
Microsoft released new Windows 10 and Windows 11 protections in the April 2026 cumulative updates to reduce phishing attacks that abuse Remote Desktop connection (.rdp) files. The changes add user warnings, show publisher and remote connection details, and disable redirected local resources by default before a connection is established.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcego.theregister.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourcelearn.microsoft.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.