Close Menu
trendyfii.comtrendyfii.com

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    The One Cocktail Science Says Tastes Better on a Flight

    November 3, 2025

    Even Rihanna Can’t Resist the Ease of the Boat and Tote

    November 3, 2025

    Nigel Farage to promise business deregulation in economic policy speech | Reform UK

    November 3, 2025
    Facebook X (Twitter) Instagram
    Trending
    • The One Cocktail Science Says Tastes Better on a Flight
    • Even Rihanna Can’t Resist the Ease of the Boat and Tote
    • Nigel Farage to promise business deregulation in economic policy speech | Reform UK
    • Kamila Davies Heats Up the Internet with Her Smokin’ Hot Pics
    • SanDisk’s microSD Express card for the Switch 2 is cheaper than ever thanks to this early Black Friday deal
    • How to Coordinate Bedding Colors and Patterns (2025)
    • Australia politics live: question time under way; Labor still has no ‘preferred partner’ to help pass nature laws reforms, Watt says | Australian politics
    • Hamas hands over three coffins it says contain bodies of Gaza hostages
    Facebook X (Twitter) Instagram Pinterest Vimeo
    trendyfii.comtrendyfii.com
    • Home
    • World News
    • Travel & Culture
    • Lifestyle Tips
    • UK Updates
    • US & Canada
    • Tech Trends
      • Health & Wellness
      • Entertainment
    trendyfii.comtrendyfii.com
    Home»Tech Trends»Two Windows vulnerabilities, one a 0-day, are under active exploitation
    Tech Trends

    Two Windows vulnerabilities, one a 0-day, are under active exploitation

    techmanager291@gmail.comBy techmanager291@gmail.comNovember 2, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Two Windows vulnerabilities, one a 0-day, are under active exploitation
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Two Windows vulnerabilities—one a zero-day that has been known to attackers since 2017 and the other a critical flaw that Microsoft initially tried and failed to patch recently—are under active exploitation in widespread attacks targeting a swath of the Internet, researchers say.

    The zero-day went undiscovered until March, when security firm Trend Micro said it had been under active exploitation since 2017, by as many as 11 separate advanced persistent threats (APTs). These APT groups, often with ties to nation-states, relentlessly attack specific individuals or groups of interest. Trend Micro went on to say that the groups were exploiting the vulnerability, then tracked as ZDI-CAN-25373, to install various known post-exploitation payloads on infrastructure located in nearly 60 countries, with the US, Canada, Russia, and Korea being the most common.

    A large-scale, coordinated operation

    Seven months later, Microsoft still hasn’t patched the vulnerability, which stems from a bug in the Windows Shortcut binary format. The Windows component makes opening apps or accessing files easier and faster by allowing a single binary file to invoke them without having to navigate to their locations. In recent months, the ZDI-CAN-25373 tracking designation has been changed to CVE-2025-9491.

    On Thursday, security firm Arctic Wolf reported that it observed a China-aligned threat group, tracked as UNC-6384, exploiting CVE-2025-9491 in attacks against various European nations. The final payload is a widely used remote access trojan known as PlugX. To better conceal the malware, the exploit keeps the binary file encrypted in the RC4 format until the final step in the attack.

    “The breadth of targeting across multiple European nations within a condensed timeframe suggests either a large-scale coordinated intelligence collection operation or deployment of multiple parallel operational teams with shared tooling but independent targeting,” Arctic Wolf said. “The consistency in tradecraft across disparate targets indicates centralized tool development and operational security standards even if execution is distributed across multiple teams.”

    0day active exploitation vulnerabilities Windows
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHawai’i Tourism Faces Shift: Fewer Visitors, Higher Spending, and Shorter Stays
    Next Article Miles Teller hosts for second time with Brandi Carlile as musical guest
    techmanager291@gmail.com
    • Website

    Related Posts

    Tech Trends

    SanDisk’s microSD Express card for the Switch 2 is cheaper than ever thanks to this early Black Friday deal

    November 3, 2025
    Tech Trends

    Today’s NYT Connections Hints, Answers for Nov. 3 #876

    November 3, 2025
    Tech Trends

    LiberNovo Omni Review: A Motorized Office Chair

    November 3, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Woman ‘faked entire pregnancy with silicone doll’ before claiming ‘child’ had died

    October 22, 20251 Views

    Supporters Cheer After Indigenous Land Defenders Avoid Jail

    October 20, 20251 Views

    Government looks utterly weak on Maccabi Tel Aviv fan ban – and Tories have smelt blood | Politics News

    October 19, 20251 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    World News

    Why Liverpool are feeling the effects of Trent Alexander-Arnold’s absence this season

    techmanager291@gmail.comOctober 19, 2025
    UK Updates

    The return of ‘Tescopoly’? How Britain’s biggest retailer dominates everyday life | Tesco

    techmanager291@gmail.comOctober 19, 2025
    US & Canada

    Beto O’Rourke ‘proud’ to join Austin ‘No Kings’ protest

    techmanager291@gmail.comOctober 19, 2025

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Why Liverpool are feeling the effects of Trent Alexander-Arnold’s absence this season

    October 19, 20250 Views

    The return of ‘Tescopoly’? How Britain’s biggest retailer dominates everyday life | Tesco

    October 19, 20250 Views

    Beto O’Rourke ‘proud’ to join Austin ‘No Kings’ protest

    October 19, 20250 Views
    Our Picks

    The One Cocktail Science Says Tastes Better on a Flight

    November 3, 2025

    Even Rihanna Can’t Resist the Ease of the Boat and Tote

    November 3, 2025

    Nigel Farage to promise business deregulation in economic policy speech | Reform UK

    November 3, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2025 trendyfii. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.