Close Menu
trendyfii.comtrendyfii.com

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    ‘SNL’ spoofs NYC mayoral candidates debating each other

    November 2, 2025

    Christians ‘face persecution’ in the first Christian country | Politics | News

    November 2, 2025

    LaZona Pictures Secures Spain on ‘Chopin, Chopin!’ From Playtime

    November 2, 2025
    Facebook X (Twitter) Instagram
    Trending
    • ‘SNL’ spoofs NYC mayoral candidates debating each other
    • Christians ‘face persecution’ in the first Christian country | Politics | News
    • LaZona Pictures Secures Spain on ‘Chopin, Chopin!’ From Playtime
    • Measles outbreak investigation in Utah blocked by patient who refuses to talk
    • I’m an American Living in Paris and This Is My No. 1 Travel Tip for Anyone Visiting
    • 43 Soup Recipes You’ll Crave Year-Round
    • Workers face worsening inequality without urgent reforms, UN agency warns
    • Vitor Pereira sacked as Wolves manager just weeks after signing new contract, as club remains winless and bottom of the Premier League | UK News
    Facebook X (Twitter) Instagram Pinterest Vimeo
    trendyfii.comtrendyfii.com
    • Home
    • World News
    • Travel & Culture
    • Lifestyle Tips
    • UK Updates
    • US & Canada
    • Tech Trends
      • Health & Wellness
      • Entertainment
    trendyfii.comtrendyfii.com
    Home»Tech Trends»Two Windows vulnerabilities, one a 0-day, are under active exploitation
    Tech Trends

    Two Windows vulnerabilities, one a 0-day, are under active exploitation

    techmanager291@gmail.comBy techmanager291@gmail.comNovember 2, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Two Windows vulnerabilities, one a 0-day, are under active exploitation
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Two Windows vulnerabilities—one a zero-day that has been known to attackers since 2017 and the other a critical flaw that Microsoft initially tried and failed to patch recently—are under active exploitation in widespread attacks targeting a swath of the Internet, researchers say.

    The zero-day went undiscovered until March, when security firm Trend Micro said it had been under active exploitation since 2017, by as many as 11 separate advanced persistent threats (APTs). These APT groups, often with ties to nation-states, relentlessly attack specific individuals or groups of interest. Trend Micro went on to say that the groups were exploiting the vulnerability, then tracked as ZDI-CAN-25373, to install various known post-exploitation payloads on infrastructure located in nearly 60 countries, with the US, Canada, Russia, and Korea being the most common.

    A large-scale, coordinated operation

    Seven months later, Microsoft still hasn’t patched the vulnerability, which stems from a bug in the Windows Shortcut binary format. The Windows component makes opening apps or accessing files easier and faster by allowing a single binary file to invoke them without having to navigate to their locations. In recent months, the ZDI-CAN-25373 tracking designation has been changed to CVE-2025-9491.

    On Thursday, security firm Arctic Wolf reported that it observed a China-aligned threat group, tracked as UNC-6384, exploiting CVE-2025-9491 in attacks against various European nations. The final payload is a widely used remote access trojan known as PlugX. To better conceal the malware, the exploit keeps the binary file encrypted in the RC4 format until the final step in the attack.

    “The breadth of targeting across multiple European nations within a condensed timeframe suggests either a large-scale coordinated intelligence collection operation or deployment of multiple parallel operational teams with shared tooling but independent targeting,” Arctic Wolf said. “The consistency in tradecraft across disparate targets indicates centralized tool development and operational security standards even if execution is distributed across multiple teams.”

    0day active exploitation vulnerabilities Windows
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHawai’i Tourism Faces Shift: Fewer Visitors, Higher Spending, and Shorter Stays
    Next Article Miles Teller hosts for second time with Brandi Carlile as musical guest
    techmanager291@gmail.com
    • Website

    Related Posts

    Tech Trends

    Measles outbreak investigation in Utah blocked by patient who refuses to talk

    November 2, 2025
    Tech Trends

    Ayaneo’s first smartphone could have physical shoulder buttons

    November 2, 2025
    Tech Trends

    Best Home Pet Cams of 2025: Tested with Our Pets

    November 2, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Woman ‘faked entire pregnancy with silicone doll’ before claiming ‘child’ had died

    October 22, 20251 Views

    Supporters Cheer After Indigenous Land Defenders Avoid Jail

    October 20, 20251 Views

    Government looks utterly weak on Maccabi Tel Aviv fan ban – and Tories have smelt blood | Politics News

    October 19, 20251 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    World News

    Why Liverpool are feeling the effects of Trent Alexander-Arnold’s absence this season

    techmanager291@gmail.comOctober 19, 2025
    UK Updates

    The return of ‘Tescopoly’? How Britain’s biggest retailer dominates everyday life | Tesco

    techmanager291@gmail.comOctober 19, 2025
    US & Canada

    Beto O’Rourke ‘proud’ to join Austin ‘No Kings’ protest

    techmanager291@gmail.comOctober 19, 2025

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Why Liverpool are feeling the effects of Trent Alexander-Arnold’s absence this season

    October 19, 20250 Views

    The return of ‘Tescopoly’? How Britain’s biggest retailer dominates everyday life | Tesco

    October 19, 20250 Views

    Beto O’Rourke ‘proud’ to join Austin ‘No Kings’ protest

    October 19, 20250 Views
    Our Picks

    ‘SNL’ spoofs NYC mayoral candidates debating each other

    November 2, 2025

    Christians ‘face persecution’ in the first Christian country | Politics | News

    November 2, 2025

    LaZona Pictures Secures Spain on ‘Chopin, Chopin!’ From Playtime

    November 2, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact us
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2025 trendyfii. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.