đ° Full Story
Microsoft has deployed new protections in its April 2026 cumulative updates for Windows 10 and Windows 11 to block a growing phishing vector that abuses Remote Desktop Protocol (.rdp) files.
The updates (including KB5082200 for Windows 10 and KB5083769 / KB5082052 for Windows 11) introduce a oneâtime educational prompt when users first open an RDP file and then require a security dialog on subsequent opens.
That dialog displays whether the file is digitally signed, the remote system address, and lists any requested local resource redirections (drives, clipboard, devices) which are disabled by default until explicitly approved.
The protections apply only when RDP files are opened directly, not to connections initiated inside the Remote Desktop client.
Administrators can temporarily disable the warnings via a registry policy, and Microsoft warns that file signatures do not guarantee safety.
The change responds to real-world abuse â notably by stateâlinked groups using rogue RDP files in phishing campaigns â and Microsoft says future updates may deprecate older connection settings.
đ Based On
đ°ď¸ The Story So Far: An Evolving Timeline
Thursday, April 16, 2026 06:15 UTC
Microsoft strengthens Windows RDP file protections
Wednesday, April 15, 2026 07:38 UTC
Microsoft's April Patch Tuesday fixes 165 vulnerabilities








đŹ Commentary