Threat Actors
The latest Threat Actors coverage — news, analysis, and updates from the WindowsNews.AI desk.
Pure Crypter: How This Advanced Malware Loader Evades Windows 11 24H2 Security
A new malware loader called Pure Crypter has emerged as a significant threat to Windows 11 systems, demonstrating sophisticated techniques to bypass even the enhanced security features in the...
Microsoft Exposes Void Blizzard: Russia’s Stealthy Spy Campaign Targets Defense, Bypasses MFA
A Russian state-backed cyberespionage group has been quietly breaching critical organizations across NATO countries and Ukraine since at least April 2024. Dubbed Void Blizzard and tracked as LAUNDRY...
Critical Windows Media Vulnerability (CVE-2025-29963) Exploited in Wild - Patch Now
A newly disclosed critical vulnerability in Windows Media components is actively being exploited in the wild, allowing attackers to seize full control of unpatched systems through seemingly innocent...
CISA Alerts on Critical ICS Flaws in Energy and Industrial Systems
Introduction The security of critical infrastructure is paramount to national safety and economic stability. Industrial Control Systems (ICS), which manage essential services like energy, water, and...
NTLM hash leak CVE-2025-24054 exploited within days of March 2025 patch
Overview In March 2025, Microsoft released a security update addressing a critical vulnerability in the Windows NT LAN Manager (NTLM) authentication protocol, identified as CVE-2025-24054. Despite...
Understanding CVE-2025-27475: Windows Update Stack Vulnerability Explained
In the ever-evolving landscape of cybersecurity, even the most fundamental components of operating systems can become prime targets for exploitation. A recent example is the Windows Update Stack...
CVE-2025-24983: Persistent Windows Kernel Vulnerability Exploited Since 2023
Overview In March 2025, Microsoft addressed a critical security flaw, CVE-2025-24983, in its Patch Tuesday updates. This vulnerability, a use-after-free issue in the Windows Win32 Kernel Subsystem,...
Russian APT group APT28 weaponizes OAuth 2.0 against Ukraine, NGOs
In a chilling reminder of the evolving landscape of cyber warfare, Russian state-sponsored hackers have been exploiting vulnerabilities in OAuth 2.0 to conduct sophisticated cyber espionage campaigns...
Messaging Apps as Cyberattack Vectors: Protecting Microsoft 365 Credentials
In an era where remote work and digital communication dominate the corporate landscape, hackers have found a new gateway to infiltrate systems and steal sensitive information: messaging apps....
Russian State Hackers Weaponize Microsoft 365 OAuth Tokens in 2023 Campaigns
Introduction In 2023, cybersecurity researchers identified a series of sophisticated cyber attacks orchestrated by Russian state-sponsored actors targeting Microsoft 365 environments. These...
Russian Hackers Exploit OAuth to Target Ukraine NGOs via Microsoft 365
In a chilling reminder of the persistent dangers lurking in the digital realm, Russian threat actors have been reported to exploit OAuth vulnerabilities to compromise Microsoft 365 accounts,...
OAuth Phishing in Microsoft 365: A Growing Cybersecurity Threat for Windows Users
In the ever-evolving landscape of cybersecurity, a particularly insidious threat has emerged, targeting the trust users place in familiar platforms like Microsoft 365. Cybercriminals are increasingly...