Threat Actors
The latest Threat Actors coverage — news, analysis, and updates from the WindowsNews.AI desk.
ESET Exposes GhostRedirector: China-Aligned Hackers Deploy IIS SEO Fraud and Custom Backdoor on 65 Windows Servers
In June 2025, ESET researchers unearthed a previously unknown threat actor they call GhostRedirector, which had compromised at least 65 Windows servers around the globe. The attackers deployed two...
CVE-2025-53740: Urgent Patch Needed as Office Use-After-Free RCE Threatens Enterprise Security
Microsoft has confirmed a critical use-after-free vulnerability in Microsoft Office, tracked as CVE-2025-53740, that could let attackers run arbitrary code when a user opens a maliciously crafted...
The Phishing Pipeline: How Attackers Weaponize Microsoft 365 Direct Send to Evade Every Defense
Microsoft 365’s Direct Send feature has become a double-edged sword. Designed to let printers, scanners, and applications relay mail without a dedicated mailbox, it now enables attackers to slip...
Critical Microsoft SharePoint Zero-Day Vulnerability: Risks, Impact, and Security Best Practices
A new zero-day vulnerability in Microsoft SharePoint has starkly underscored the persistent risks facing enterprise IT infrastructure, especially as organizations continue to lean heavily on digital...
CVE-2025-32726: Critical Visual Studio Code Privilege Escalation Vulnerability Explained
Visual Studio Code (VS Code), Microsoft's wildly popular open-source code editor, has recently come under scrutiny due to a critical privilege escalation vulnerability designated as CVE-2025-32726....
File upload bugs let hackers plant web shells on Windows and Linux—attacks up 47% in 2023.
Cybercriminals are exploiting file upload vulnerabilities in both Windows and Linux servers to deploy malicious web shells, creating persistent backdoors for data theft and network infiltration....
Microsoft 365 Direct Send Abuse: How to Protect Against Phishing Attacks
Microsoft 365's Direct Send feature, designed to simplify internal email routing, has become an unexpected security vulnerability. Recent research reveals how threat actors exploit this legitimate...
June 2025 Windows Patch Tuesday: Critical Zero-Day Fixes and Legacy Protocol Risks
Microsoft's June 2025 Patch Tuesday arrived with urgent security updates, addressing 67 newly discovered vulnerabilities—including two actively exploited zero-day flaws and multiple critical remote...
June 2025 Patch Tuesday fixes 78 flaws, 3 zero-days exploited in legacy SMB and WebDAV
June’s Patch Tuesday has become a pivotal moment for Windows system administrators, threat researchers, and IT professionals alike. Microsoft’s June 2025 security update underlines why: it...
Cyber Threat Actor Naming Chaos Undermines Intelligence Sharing and Response
The cybersecurity landscape is a battleground of ever-evolving threats, where threat actors operate under a dizzying array of names—Cozy Bear, Midnight Blizzard, APT29, UNC2452, Voodoo Bear—each...
Microsoft & CrowdStrike's Unified Threat Naming: A Game-Changer for Cybersecurity
In a landmark move for the cybersecurity industry, Microsoft and CrowdStrike have announced a joint initiative to standardize threat actor naming conventions, addressing one of the most persistent...
Dadsec and Tycoon2FA: The Growing Danger of Phishing-as-a-Service Platforms
The cybersecurity landscape is witnessing an alarming rise in Phishing-as-a-Service (PhaaS) platforms, with Dadsec and Tycoon2FA emerging as two of the most sophisticated threats. These platforms...