Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Stop Hard Coding Certs, Tokens And Other Authorization In Your VS Code Extensions!

    November 2, 2025

    This smart ring brings vibration alerts, elegant design together

    November 2, 2025

    Sam Altman wants a refund for his $50,000 Tesla Roadster deposit

    November 2, 2025
    Facebook X (Twitter) Instagram
    Sunday, November 2
    Facebook X (Twitter) Instagram YouTube Mastodon Tumblr Bluesky LinkedIn Threads
    ToolcomeToolcome
    • Technology & Startups

      Sam Altman wants a refund for his $50,000 Tesla Roadster deposit

      November 2, 2025

      Inside the marketplace for vaccine medical exemptions

      November 1, 2025

      Research roundup: 6 cool science stories we almost missed

      November 1, 2025

      Wireless Charging a 2026 Porsche Cayenne Electric

      November 1, 2025

      Gear News of the Week: Withings Launches Its Pee Scanner, and Samsung Shows Off a Trifold Phone

      November 1, 2025
    • Science & Education

      In 1925, seven students went 60 hours without sleep—for science

      November 1, 2025

      Food scraps could power future airplanes

      November 1, 2025

      We sharpened the James Webb telescope’s vision from a million miles away. Here’s how.

      November 1, 2025

      A toxicologist explains when you can safely cut the moldy part off food, and when it’s best to toss it

      November 1, 2025

      Chimps ‘think about thinking’ in order to weigh evidence and plan their actions, new research suggests

      November 1, 2025
    • Mobile Phones

      This smart ring brings vibration alerts, elegant design together

      November 2, 2025

      Gboard helps you find that trendy GIF you’re looking for

      November 1, 2025

      Honor and BYD partner to advance AI-driven phone-to-car integration

      November 1, 2025

      Vivo X300 series India launch timeframe leaked

      November 1, 2025

      Alleged Honor 500, Honor 500 Pro bag important certification, November launch expected

      November 1, 2025
    • Gadgets

      Pentagon will reportedly award SpaceX a $2 billion contract to help develop the ‘Golden Dome’

      November 1, 2025

      A deep dive into humankind’s search for alien life

      November 1, 2025

      Ayaneo’s first smartphone could have physical shoulder buttons

      November 1, 2025

      Italy will be the latest country to require age verification for porn sites

      November 1, 2025

      How to watch the 2025 MLB World Series without cable

      November 1, 2025
    • Gaming

      New Hades 2 Patch Expands The Ending

      November 2, 2025

      Typing Games Are Cool Again Thanks To Wildly Unexpected Twists

      November 1, 2025

      Xbox Elite Series 2 Controller On Sale For Lowest Price This Year

      November 1, 2025

      Fortnite – New Weapons In The Simpsons Season

      November 1, 2025

      Everything New In Fortnite’s The Simpsons Season

      November 1, 2025
    • Cars

      Access Denied

      November 2, 2025

      Access Denied

      November 1, 2025

      Subaru Just Unveiled a Pair of STI Concepts and Now We're Getting Our Hopes Up

      November 1, 2025

      Access Denied

      November 1, 2025

      Here's What We Think About Some of the Cars in Our One-Year Road Test Fleet

      November 1, 2025
    • PC Accessories

      Stop Hard Coding Certs, Tokens And Other Authorization In Your VS Code Extensions!

      November 2, 2025

      Forgot Your Gmail Password? Time To Phone A Friend!

      November 1, 2025

      The Antec C8 Curve Wood Full Tower Doesn’t Bend But It Is Very Wide

      November 1, 2025

      AWS and the Terrible, Horrible, No Good, Very Bad Day

      November 1, 2025

      Minisforum N5 Pro, An Impressive Zen 5 Based NAS

      November 1, 2025
    ToolcomeToolcome
    Home»Technology & Startups»Two Windows vulnerabilities, one a 0-day, are under active exploitation
    Technology & Startups

    Two Windows vulnerabilities, one a 0-day, are under active exploitation

    November 1, 2025No Comments2 Mins Read1 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Two Windows vulnerabilities—one a zero-day that has been known to attackers since 2017 and the other a critical flaw that Microsoft initially tried and failed to patch recently—are under active exploitation in widespread attacks targeting a swath of the Internet, researchers say.

    The zero-day went undiscovered until March, when security firm Trend Micro said it had been under active exploitation since 2017, by as many as 11 separate advanced persistent threats (APTs). These APT groups, often with ties to nation-states, relentlessly attack specific individuals or groups of interest. Trend Micro went on to say that the groups were exploiting the vulnerability, then tracked as ZDI-CAN-25373, to install various known post-exploitation payloads on infrastructure located in nearly 60 countries, with the US, Canada, Russia, and Korea being the most common.

    A large-scale, coordinated operation

    Seven months later, Microsoft still hasn’t patched the vulnerability, which stems from a bug in the Windows Shortcut binary format. The Windows component makes opening apps or accessing files easier and faster by allowing a single binary file to invoke them without having to navigate to their locations. In recent months, the ZDI-CAN-25373 tracking designation has been changed to CVE-2025-9491.

    On Thursday, security firm Arctic Wolf reported that it observed a China-aligned threat group, tracked as UNC-6384, exploiting CVE-2025-9491 in attacks against various European nations. The final payload is a widely used remote access trojan known as PlugX. To better conceal the malware, the exploit keeps the binary file encrypted in the RC4 format until the final step in the attack.

    “The breadth of targeting across multiple European nations within a condensed timeframe suggests either a large-scale coordinated intelligence collection operation or deployment of multiple parallel operational teams with shared tooling but independent targeting,” Arctic Wolf said. “The consistency in tradecraft across disparate targets indicates centralized tool development and operational security standards even if execution is distributed across multiple teams.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    mehedihasan9992
    • Website

    Related Posts

    Sam Altman wants a refund for his $50,000 Tesla Roadster deposit

    November 2, 2025

    Inside the marketplace for vaccine medical exemptions

    November 1, 2025

    Research roundup: 6 cool science stories we almost missed

    November 1, 2025

    Wireless Charging a 2026 Porsche Cayenne Electric

    November 1, 2025

    Gear News of the Week: Withings Launches Its Pee Scanner, and Samsung Shows Off a Trifold Phone

    November 1, 2025

    The ‘10 Martini’ Proof Connects Quantum Mechanics With Infinitely Intricate Mathematical Structures

    November 1, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Samsung promises the Galaxy S26 with more AI, a custom chip, and new camera sensors

    October 30, 202514 Views

    Lab monkeys on the loose in Mississippi don’t have herpes, university says. But are they dangerous?

    October 30, 202513 Views

    Are you a YouTube TV subscriber looking for ESPN and ABC? Here are your options

    October 31, 202511 Views
    Don't Miss

    Stop Hard Coding Certs, Tokens And Other Authorization In Your VS Code Extensions!

    November 2, 2025

    Bad Coder!  Stop It! It may be convenient, but if you are designing custom VS…

    This smart ring brings vibration alerts, elegant design together

    November 2, 2025

    Sam Altman wants a refund for his $50,000 Tesla Roadster deposit

    November 2, 2025

    Access Denied

    November 2, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    8.9

    Review: Dell’s New Tablet PC Can Survive -20f And Drops

    January 15, 2021

    Review: Kia EV6 2022 The Best Electric Vehicle Ever?

    January 14, 2021
    72

    Review: Animation Software Business Share, Market Size and Growth

    January 14, 2021
    Most Popular

    Samsung promises the Galaxy S26 with more AI, a custom chip, and new camera sensors

    October 30, 202514 Views

    Lab monkeys on the loose in Mississippi don’t have herpes, university says. But are they dangerous?

    October 30, 202513 Views

    Are you a YouTube TV subscriber looking for ESPN and ABC? Here are your options

    October 31, 202511 Views
    Our Picks

    Stop Hard Coding Certs, Tokens And Other Authorization In Your VS Code Extensions!

    November 2, 2025

    This smart ring brings vibration alerts, elegant design together

    November 2, 2025

    Sam Altman wants a refund for his $50,000 Tesla Roadster deposit

    November 2, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Toolcome
    Facebook X (Twitter) Instagram YouTube
    • Home
    • Technology
    • Gaming
    • Mobile Phones
    • Cars
    • PC Accessories
    © 2025 Tolcome. Designed by Aim Digi Ltd.

    Type above and press Enter to search. Press Esc to cancel.