Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

    January 13, 2026

    Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

    January 13, 2026

    Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

    January 13, 2026
    Facebook X (Twitter) Instagram
    Wednesday, January 14
    Facebook X (Twitter) Instagram YouTube Mastodon Tumblr Bluesky LinkedIn Threads
    ToolcomeToolcome
    • Technology & Startups

      Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

      January 13, 2026

      Urevo SpaceWalk 5L Walking Pad Review: Compact and Affordable

      January 13, 2026

      Board Review: Tabletop Video Games With Physical Pieces

      January 13, 2026

      Atonemo Streamplayer Review: Make Old Speakers New Again

      January 13, 2026

      What to Do If ICE Invades Your Neighborhood

      January 13, 2026
    • Science & Education

      Hubble Nets Menagerie of Young Stellar Objects

      January 13, 2026

      Ötzi the Iceman mummy carried a high-risk strain of HPV, research finds

      January 13, 2026

      Can you eat too much protein?

      January 13, 2026

      NASA’s Webb Delivers Unprecedented Look Into Heart of Circinus Galaxy

      January 13, 2026

      Backcountry is blowing out hiking bags, backpacks, and luggage for up to 65% off during this clearance sale

      January 13, 2026
    • Mobile Phones

      Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

      January 13, 2026

      Motorola expands Android 16 beta program to 8 more devices

      January 13, 2026

      Motorola Introduces Moto Pen Ultra for Foldables and Moto Tag 2 Item Tracker

      January 13, 2026

      OnePlus Nord CE 5 Update Adds Video Editing Tools and January Security Patch

      January 13, 2026

      Vivo rolls out OriginOS 6 (Android 16) update to Vivo V40

      January 13, 2026
    • Gadgets

      Star Wars Outlaws developer Massive Entertainment and Ubisoft Stockholm face layoffs

      January 13, 2026

      Insta360 releases AI-powered follow-up to its Link webcams

      January 13, 2026

      Proton’s Lumo AI chatbot now has an encrypted space for your projects

      January 13, 2026

      The best streaming devices for 2026

      January 13, 2026

      UK regulator Ofcom opens a formal investigation into X over CSAM scandal

      January 13, 2026
    • Gaming

      Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

      January 13, 2026

      ASUS ROG Xbox Ally (2025 Ryzen Z2 A) Just Hit Its Lowest Price Ever With 3 Months of Game Pass Included

      January 13, 2026

      Samsung Goes All-In on Galaxy S25 Ultra Clearance at a Record Low as the New S26 Launch Approaches

      January 13, 2026

      This Great Switch 2 Handheld Controller Is On Sale For New Best Price At Amazon

      January 13, 2026

      Google Pixel 9a Drops to All-Time Low to Compete With Samsung Galaxy S25 Deals, Now the Cheapest Gemini-Powered Smartphone

      January 13, 2026
    • Cars

      Beyond Speed: A Deep Dive into the 6 Safety Features That Could Save Your Supercar in 2026

      January 13, 2026

      A Commercial Truck Caused a Hit-and-Run: Who Pays for the Damage?

      January 13, 2026

      Risk and reward: what driving teaches about smart decisions

      January 13, 2026

      How It’s Played Online on GameZone

      January 12, 2026

      How Dubai Became the Supercar Capital of the World

      January 12, 2026
    • PC Accessories

      A Kilowatt PSU Is So 2025, The Seasonic Prime PX-2200 Is The Future

      January 12, 2026

      CES 2026: The Good, Bad And Ugly

      January 12, 2026

      Hands-On With Samsung Galaxy Z TriFold: An Impressive New Take On Foldables

      January 11, 2026

      Edifier’s Funky Portable ES300 Wireless Speaker

      January 9, 2026

      Testing All The Features of AMD’s FSR Redstone

      January 9, 2026
    ToolcomeToolcome
    Home»Technology & Startups»Two Windows vulnerabilities, one a 0-day, are under active exploitation
    Technology & Startups

    Two Windows vulnerabilities, one a 0-day, are under active exploitation

    November 1, 2025No Comments2 Mins Read1 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Two Windows vulnerabilities—one a zero-day that has been known to attackers since 2017 and the other a critical flaw that Microsoft initially tried and failed to patch recently—are under active exploitation in widespread attacks targeting a swath of the Internet, researchers say.

    The zero-day went undiscovered until March, when security firm Trend Micro said it had been under active exploitation since 2017, by as many as 11 separate advanced persistent threats (APTs). These APT groups, often with ties to nation-states, relentlessly attack specific individuals or groups of interest. Trend Micro went on to say that the groups were exploiting the vulnerability, then tracked as ZDI-CAN-25373, to install various known post-exploitation payloads on infrastructure located in nearly 60 countries, with the US, Canada, Russia, and Korea being the most common.

    A large-scale, coordinated operation

    Seven months later, Microsoft still hasn’t patched the vulnerability, which stems from a bug in the Windows Shortcut binary format. The Windows component makes opening apps or accessing files easier and faster by allowing a single binary file to invoke them without having to navigate to their locations. In recent months, the ZDI-CAN-25373 tracking designation has been changed to CVE-2025-9491.

    On Thursday, security firm Arctic Wolf reported that it observed a China-aligned threat group, tracked as UNC-6384, exploiting CVE-2025-9491 in attacks against various European nations. The final payload is a widely used remote access trojan known as PlugX. To better conceal the malware, the exploit keeps the binary file encrypted in the RC4 format until the final step in the attack.

    “The breadth of targeting across multiple European nations within a condensed timeframe suggests either a large-scale coordinated intelligence collection operation or deployment of multiple parallel operational teams with shared tooling but independent targeting,” Arctic Wolf said. “The consistency in tradecraft across disparate targets indicates centralized tool development and operational security standards even if execution is distributed across multiple teams.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    mehedihasan9992
    • Website

    Related Posts

    Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

    January 13, 2026

    Urevo SpaceWalk 5L Walking Pad Review: Compact and Affordable

    January 13, 2026

    Board Review: Tabletop Video Games With Physical Pieces

    January 13, 2026

    Atonemo Streamplayer Review: Make Old Speakers New Again

    January 13, 2026

    What to Do If ICE Invades Your Neighborhood

    January 13, 2026

    Switching water sources improved hygiene of Pompeii’s public baths

    January 13, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Steam and Valve’s online games are down

    December 24, 2025129 Views

    773,000-year-old fossils found in Casablanca may be earliest common ancestor of modern humans and Neanderthals

    January 8, 202695 Views

    Get three months of Apple Music for only $1 right now

    December 5, 202542 Views
    Don't Miss

    Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

    January 13, 2026

    Reid Hoffman doesn’t do much in half measures. He cofounded LinkedIn, of course, and helped…

    Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

    January 13, 2026

    Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

    January 13, 2026

    Hubble Nets Menagerie of Young Stellar Objects

    January 13, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    8.9

    Review: Dell’s New Tablet PC Can Survive -20f And Drops

    January 15, 2021

    Review: Kia EV6 2022 The Best Electric Vehicle Ever?

    January 14, 2021
    72

    Review: Animation Software Business Share, Market Size and Growth

    January 14, 2021
    Most Popular

    Steam and Valve’s online games are down

    December 24, 2025129 Views

    773,000-year-old fossils found in Casablanca may be earliest common ancestor of modern humans and Neanderthals

    January 8, 202695 Views

    Get three months of Apple Music for only $1 right now

    December 5, 202542 Views
    Our Picks

    Reid Hoffman Wants Silicon Valley to ‘Stand Up’ Against the Trump Administration

    January 13, 2026

    Smartphone Camera Scores Explained: Are DxOMark Rankings Really Reliable?

    January 13, 2026

    Samsung Pushes Galaxy Watch 8 (2025) to Its Lowest Price in New Year Clearance, While Apple Watches Stay Full Price

    January 13, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Toolcome
    Facebook X (Twitter) Instagram YouTube Mastodon Bluesky
    • Home
    • Technology
    • Gaming
    • Mobile Phones
    • Cars
    • PC Accessories
    © 2026 Tolcome.

    Type above and press Enter to search. Press Esc to cancel.