Live
ESET Exposes GhostRedirector: China-Aligned Hackers Deploy IIS SEO Fraud and Custom Backdoor on 65 Windows Servers·MSFT +2.1%CVE-2025-53740: Urgent Patch Needed as Office Use-After-Free RCE Threatens Enterprise Security·NVDA +0.2%The Phishing Pipeline: How Attackers Weaponize Microsoft 365 Direct Send to Evade Every Defense·GOOGL +1.7%Critical Microsoft SharePoint Zero-Day Vulnerability: Risks, Impact, and Security Best Practices·AMZN +1.1%CVE-2025-32726: Critical Visual Studio Code Privilege Escalation Vulnerability Explained·MSFT +2.1%File upload bugs let hackers plant web shells on Windows and Linux—attacks up 47% in 2023.·NVDA +0.2%Microsoft 365 Direct Send Abuse: How to Protect Against Phishing Attacks·GOOGL +1.7%June 2025 Windows Patch Tuesday: Critical Zero-Day Fixes and Legacy Protocol Risks·AMZN +1.1%ESET Exposes GhostRedirector: China-Aligned Hackers Deploy IIS SEO Fraud and Custom Backdoor on 65 Windows Servers·MSFT +2.1%CVE-2025-53740: Urgent Patch Needed as Office Use-After-Free RCE Threatens Enterprise Security·NVDA +0.2%The Phishing Pipeline: How Attackers Weaponize Microsoft 365 Direct Send to Evade Every Defense·GOOGL +1.7%Critical Microsoft SharePoint Zero-Day Vulnerability: Risks, Impact, and Security Best Practices·AMZN +1.1%CVE-2025-32726: Critical Visual Studio Code Privilege Escalation Vulnerability Explained·MSFT +2.1%File upload bugs let hackers plant web shells on Windows and Linux—attacks up 47% in 2023.·NVDA +0.2%Microsoft 365 Direct Send Abuse: How to Protect Against Phishing Attacks·GOOGL +1.7%June 2025 Windows Patch Tuesday: Critical Zero-Day Fixes and Legacy Protocol Risks·AMZN +1.1%

Threat Actors

The latest Threat Actors coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 1:02 AM
Latest Most Read Breaking
Sort
Backdoor · C2

ESET Exposes GhostRedirector: China-Aligned Hackers Deploy IIS SEO Fraud and Custom Backdoor on 65 Windows Servers

In June 2025, ESET researchers unearthed a previously unknown threat actor they call GhostRedirector, which had compromised at least 65 Windows servers around the globe. The attackers deployed two...

Advertisement
Code Editor Security · Cve-2025-32726

CVE-2025-32726: Critical Visual Studio Code Privilege Escalation Vulnerability Explained

Visual Studio Code (VS Code), Microsoft's wildly popular open-source code editor, has recently come under scrutiny due to a critical privilege escalation vulnerability designated as CVE-2025-32726....

SE Security Desk·54w ago
Command And Control · Cyber Threats

File upload bugs let hackers plant web shells on Windows and Linux—attacks up 47% in 2023.

Cybercriminals are exploiting file upload vulnerabilities in both Windows and Linux servers to deploy malicious web shells, creating persistent backdoors for data theft and network infiltration....

SE Security Desk·54w ago
Cloud Security · Cloud Threat Landscape

Microsoft 365 Direct Send Abuse: How to Protect Against Phishing Attacks

Microsoft 365's Direct Send feature, designed to simplify internal email routing, has become an unexpected security vulnerability. Recent research reveals how threat actors exploit this legitimate...

SE Security Desk·55w ago
Cve-2025-33053 · Cve-2025-33073

June 2025 Windows Patch Tuesday: Critical Zero-Day Fixes and Legacy Protocol Risks

Microsoft's June 2025 Patch Tuesday arrived with urgent security updates, addressing 67 newly discovered vulnerabilities—including two actively exploited zero-day flaws and multiple critical remote...

SE Security Desk·57w ago
Attack Surface · Cyber Threats

June 2025 Patch Tuesday fixes 78 flaws, 3 zero-days exploited in legacy SMB and WebDAV

June’s Patch Tuesday has become a pivotal moment for Windows system administrators, threat researchers, and IT professionals alike. Microsoft’s June 2025 security update underlines why: it...

SE Security Desk·57w ago
Cyber Defense · Cyber Incident

Cyber Threat Actor Naming Chaos Undermines Intelligence Sharing and Response

The cybersecurity landscape is a battleground of ever-evolving threats, where threat actors operate under a dizzying array of names—Cozy Bear, Midnight Blizzard, APT29, UNC2452, Voodoo Bear—each...

SE Security Desk·58w ago
Cyber Defense · Cyber Threat Frameworks

Microsoft & CrowdStrike's Unified Threat Naming: A Game-Changer for Cybersecurity

In a landmark move for the cybersecurity industry, Microsoft and CrowdStrike have announced a joint initiative to standardize threat actor naming conventions, addressing one of the most persistent...

SE Security Desk·58w ago
Anti-analysis Techniques · Credential Theft

Dadsec and Tycoon2FA: The Growing Danger of Phishing-as-a-Service Platforms

The cybersecurity landscape is witnessing an alarming rise in Phishing-as-a-Service (PhaaS) platforms, with Dadsec and Tycoon2FA emerging as two of the most sophisticated threats. These platforms...

SE Security Desk·59w ago
1 2 3