Advanced Persistent Threats
The latest Advanced Persistent Threats coverage — news, analysis, and updates from the WindowsNews.AI desk.
Critical Windows Kernel Flaw CVE-2025-29970: Privilege Escalation Threat Analysis
A critical security flaw designated as CVE-2025-29970 has been confirmed in Microsoft's core file system components, enabling attackers to bypass critical security barriers and gain administrative...
Marbled Dust's Exploitation of Output Messenger's Zero-Day Vulnerability: A Deep Dive into Cyber-Espionage Tactics
In the ever-evolving realm of cyber-espionage, the recent exploitation of a zero-day vulnerability in Output Messenger by the threat actor known as Marbled Dust underscores the escalating...
Critical ICS Vulnerabilities in 2025: CISA Advisories and Strategies to Secure Critical Infrastructure
Overview of CISA's 2025 ICS Vulnerabilities Advisory In 2025, the Cybersecurity and Infrastructure Security Agency (CISA) has intensified its efforts in highlighting vulnerabilities within Industrial...
CVE-2025-24054: Exploitation of Windows NTLM Hash Leak Vulnerability Highlights Urgent Need for Patch Management
Overview In March 2025, Microsoft addressed a critical security vulnerability, CVE-2025-24054, within its Windows operating system. This flaw, involving the NT LAN Manager (NTLM) authentication...
Exploitation of Windows NTLM Vulnerability CVE-2025-24054 in Widespread Cyberattacks
Overview In March 2025, Microsoft released a security update addressing a critical vulnerability in the Windows NT LAN Manager (NTLM) authentication protocol, identified as CVE-2025-24054. Despite...
Surge in Microsoft & Apple Vulnerability Exploits: Accelerated Threat Landscape Analysis
The digital battleground has intensified dramatically in recent months, with security researchers and IT departments worldwide scrambling to contain an alarming surge in the exploitation of critical...
Fast Flux DNS Evasion: A Critical Threat to Windows Users and How to Defend
Fast Flux DNS evasion represents one of the most insidious and elusive tactics in the modern cybersecurity landscape, posing a unique challenge to Windows users and IT professionals alike. This...
Understanding RESURGE Malware and CVE-2025-0282: Implications and Defense Strategies
In March 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released a Malware Analysis Report (MAR) detailing a new malware variant named RESURGE. This malware exploits the critical...
Hacktivists now share C2 servers and tools to target Windows systems in 2024.
Introduction The cyber threat landscape is undergoing rapid transformation, with hacktivist groups adopting increasingly sophisticated methods to compromise Windows systems. In 2024, these groups...
CVE-2025-24983: Persistent Windows Kernel Vulnerability Exploited Since 2023
Overview In March 2025, Microsoft addressed a critical security flaw, CVE-2025-24983, in its Patch Tuesday updates. This vulnerability, a use-after-free issue in the Windows Win32 Kernel Subsystem,...
Massive Botnet Exploits Microsoft 365 Vulnerabilities in Large-Scale Password Spraying Attacks
Overview A sophisticated cyber threat has emerged, involving a botnet comprising over 130,000 compromised devices. This botnet is executing large-scale password spraying attacks targeting Microsoft...
Russian Cyber-Espionage Targets Ukrainian NGOs with OAuth Attacks on Microsoft 365
In the ever-evolving landscape of cyber warfare, a disturbing trend has emerged targeting Ukrainian non-governmental organizations (NGOs) through sophisticated OAuth attacks as part of Russian...