Related Threat Clusters
-
Armored Likho APT Targets Power Grids with BusySnake Stealer Malware
A newly identified APT group, Armored Likho, is conducting a phishing campaign targeting government agencies and electric power sectors in Russia, Brazil, and Kazakhstan. The group employs a sophisticated infostealer…
7 articles · Updated July 4, 2026 -
Multiple Critical Windows Vulnerabilities Discovered and Exploited
Three critical vulnerabilities in Windows systems have been reported, including CVE-2025-59230, which allows attackers to gain admin rights, and CVE-2025-54100, a PowerShell vulnerability requiring urgent patches.…
3 articles · Updated December 15, 2025 -
Critical RCE Vulnerability in Windows Server Update Services Actively Exploited
Microsoft has released an out-of-band security update for a critical vulnerability, CVE-2025-59287, in Windows Server Update Services (WSUS) that allows unauthenticated remote code execution. The vulnerability, stemming…
17 articles · Updated November 1, 2025 -
Chinese Hackers Exploit Windows Zero-Day to Target European Diplomats
A China-linked hacking group, UNC6384, has exploited a Windows zero-day vulnerability to conduct cyber espionage against European diplomats in Hungary, Belgium, and other nations. The attacks, which occurred in…
18 articles · Updated November 3, 2025 -
Chinese Hackers Exploit Windows Zero-Day Vulnerability Against European Diplomats
Chinese state-sponsored hackers are exploiting a Windows zero-day vulnerability (CVE-2025-9491) to target European diplomats. The exploit involves using unpatched Windows shortcut files to deploy PlugX spying software,…
2 articles · Updated November 3, 2025 -
Microsoft Mitigates Windows LNK Vulnerability Exploited in Zero-Day Attacks
Microsoft has mitigated a high-severity Windows LNK vulnerability, tracked as CVE-2025-9491, which has been exploited by state-backed and cybercrime groups in zero-day attacks. This flaw allows attackers to hide…
3 articles · Updated December 3, 2025 -
Chinese Hackers Exploit Windows Zero-Day to Target European Diplomats
Chinese hackers are exploiting a Windows zero-day vulnerability (CVE-2025-9491) to conduct espionage against European diplomats. The flaw allows the installation of PlugX spying software, granting attackers extensive…
2 articles · Updated November 3, 2025 -
New Techniques Discovered for Abusing Windows LNK Files
Security researcher Wietze Beukema disclosed four new techniques for manipulating Windows LNK shortcut files, allowing attackers to hide malicious targets from users. These methods can facilitate phishing, USB-borne…
4 articles · Updated February 13, 2026 -
Chinese Hackers Exploit Windows Vulnerability to Target European Diplomats
A Chinese-linked hacking group, UNC6384, has been exploiting a Windows shortcut vulnerability to conduct cyber espionage against European diplomats in Hungary, Belgium, and other nations. The attacks involve spear…
4 articles · Updated October 31, 2025
Recent Intelligence Reports
- New APT Group Hits Power Grids in Three Countries with AI-Crafted Malware — Techtimes · July 4, 2026
- Windows LNK exploits allow malicious payload deployment — Scworld · February 13, 2026
- Four new reasons why Windows LNK files cannot be trusted — Csoonline · February 13, 2026
- Microsoft: New Windows LNK spoofing issues aren't vulnerabilities — Bleepingcomputer · February 12, 2026
- Microsoft "mitigates" Windows LNK flaw exploited as zero — Bleepingcomputer · December 3, 2025
- Windows LNK Vulnerabilities: Unpatched Flaws Exploited by Hackers Since 2017 — Webpronews · November 24, 2025
- Why LNK Files in Windows Are a Major Security Vulnerability and How to Stay Safe — Maketecheasier · November 11, 2025
- Chinese Hackers Exploit Unpatched Windows Zero — Winbuzzer · November 1, 2025