State Sponsored Attacks
The latest State Sponsored Attacks coverage — news, analysis, and updates from the WindowsNews.AI desk.
U.S.-China Cyber Warfare Escalation in 2025: Microsoft SharePoint Vulnerabilities at the Forefront
The escalating tensions between China and the United States in the realm of cyber warfare have become a defining feature of the global digital landscape, particularly in 2025. A recent and dramatic...
Secret Blizzard’s AiTM Cyber Espionage Campaign Targets Moscow Diplomatic Missions
Diplomatic missions in Moscow are now contending with a fresh and sophisticated cybersecurity threat: the rise of Secret Blizzard’s adversary-in-the-middle (AiTM) cyber espionage campaign. The...
Global SharePoint Zero-Day Cyberattack 2025: Analysis, Impact, and Security Best Practices
In the wake of a sweeping cyberattack that has compromised tens of thousands of Microsoft SharePoint servers worldwide, both U.S. government agencies and major energy corporations are reeling from...
North Korean IT Workers & AI Cyber Threats: How to Protect Your Business
North Korean remote IT workers, operating under the codename Jasper Sleet (formerly Storm-0287), represent a growing cybersecurity threat as state-sponsored actors increasingly leverage artificial...
Iranian Cyber Threats Escalate: How to Protect Critical Infrastructure Now
The cybersecurity landscape has never been more volatile, and few recent warnings have reflected this more acutely than the joint Fact Sheet released by the Cybersecurity and Infrastructure Security...
Microsoft 365 in 2025: AI Phishing, Ransomware & Zero Trust Fixes
As organizations increasingly rely on Microsoft 365 for productivity and collaboration, the platform has become a prime target for cybercriminals. By 2025, security threats are expected to evolve in...
Microsoft Exposes Void Blizzard: Russia’s Stealthy Spy Campaign Targets Defense, Bypasses MFA
A Russian state-backed cyberespionage group has been quietly breaching critical organizations across NATO countries and Ukraine since at least April 2024. Dubbed Void Blizzard and tracked as LAUNDRY...
The Evolving Threat of Russian Cyber Espionage Targeting Western Logistics and Technology Sectors
Russian state-sponsored cyber operations have rapidly evolved into one of the most acute digital threats targeting critical sectors across North America and Europe. Over recent years, the Western...
State-Sponsored Hackers Exploit Messaging App Vulnerabilities in Cyber Warfare
The encrypted silence of secure messaging platforms is being shattered by a new wave of sophisticated cyber incursions, as state-sponsored hacking groups increasingly weaponize previously unknown...
Russian Hackers Exploit OAuth 2.0 in Microsoft 365 'Midnight Blizzard' Attack
The digital battlegrounds of cloud security witnessed a sophisticated escalation this summer as Russian state-sponsored hackers orchestrated a novel attack exploiting inherent weaknesses in OAuth 2.0...
Windows NTLM Hash Leak CVE-2025-24054 Exploited Rapidly After Patch Tuesday
Rapid Exploitation of CVE-2025-24054: NTLM Hash Leaking and Windows Security Risks Introduction On March 11, 2025, Microsoft released its monthly Patch Tuesday security updates, as part of its...
Microsoft Patch Tuesday: 6 Zero-Days Fixed, One Under Attack Since 2023
Overview In March 2025, both Microsoft and Apple released critical security updates to address multiple zero-day vulnerabilities actively exploited in the wild. These updates are essential for...