State Sponsored Attacks
The latest State Sponsored Attacks coverage — news, analysis, and updates from the WindowsNews.AI desk.
CISA flags actively exploited Ivanti 0-day; patch Connect Secure, Policy Secure, ZTA now
Overview of CVE-2025-22457 In early April 2025, the Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability, identified as CVE-2025-22457, to its Known Exploited...
Russian State Hackers Weaponize Microsoft 365 OAuth Tokens in 2023 Campaigns
Introduction In 2023, cybersecurity researchers identified a series of sophisticated cyber attacks orchestrated by Russian state-sponsored actors targeting Microsoft 365 environments. These...
Windows .lnk Shortcut Exploits: The Hidden Threat in Plain Sight
Windows users face an often-overlooked security threat hiding in plain sight: malicious .lnk shortcut files. These seemingly harmless icons have become a favorite weapon for state-sponsored hackers...
Microsoft Under Fire for 8-Year-Old .LNK Flaw Still Exploited in State Attacks
Microsoft is facing renewed scrutiny over its handling of a persistent Windows .LNK shortcut vulnerability that has been exploited for state-sponsored attacks since 2015. The flaw, which allows...