Live
ESET Uncovers GhostRedirector: Silent IIS Backdoor Drives SEO Fraud on 65+ Windows Servers·MSFT +2.1%Google Rushes Chrome 140 Fix for CVE-2025-9864 V8 Memory Bug, Microsoft Edge Also Patched·NVDA +0.2%GhostRedirector Sneaks Native Backdoors Into IIS to Hijack SEO Rankings·GOOGL +1.7%Behind CVE-2025-55241: Why the MSRC Advisory Is Sparking a Hunt for Windows Exploit Defenses·AMZN +1.1%CISA Warns: Patch Linux Kernel, Android, and Sitecore Now as Active Attacks Confirmed·MSFT +2.1%ESET Exposes GhostRedirector: China-Aligned Hackers Deploy IIS SEO Fraud and Custom Backdoor on 65 Windows Servers·NVDA +0.2%Windows 10’s October 2025 End Sparks Heated Debate: Should Microsoft Open Legacy Drivers?·GOOGL +1.7%FreePBX Zero-Day Exploited in Wild: CISA Orders Emergency Patching for CVSS 10 RCE·AMZN +1.1%ESET Uncovers GhostRedirector: Silent IIS Backdoor Drives SEO Fraud on 65+ Windows Servers·MSFT +2.1%Google Rushes Chrome 140 Fix for CVE-2025-9864 V8 Memory Bug, Microsoft Edge Also Patched·NVDA +0.2%GhostRedirector Sneaks Native Backdoors Into IIS to Hijack SEO Rankings·GOOGL +1.7%Behind CVE-2025-55241: Why the MSRC Advisory Is Sparking a Hunt for Windows Exploit Defenses·AMZN +1.1%CISA Warns: Patch Linux Kernel, Android, and Sitecore Now as Active Attacks Confirmed·MSFT +2.1%ESET Exposes GhostRedirector: China-Aligned Hackers Deploy IIS SEO Fraud and Custom Backdoor on 65 Windows Servers·NVDA +0.2%Windows 10’s October 2025 End Sparks Heated Debate: Should Microsoft Open Legacy Drivers?·GOOGL +1.7%FreePBX Zero-Day Exploited in Wild: CISA Orders Emergency Patching for CVSS 10 RCE·AMZN +1.1%

Threat Intelligence

The latest Threat Intelligence coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 4:12 AM
Latest Most Read Breaking
Sort
Backdoor · Backlinkmanipulation

ESET Uncovers GhostRedirector: Silent IIS Backdoor Drives SEO Fraud on 65+ Windows Servers

At least 65 internet-facing Windows servers have been quietly conscripted into an SEO fraud network, each one armed with a stealthy backdoor and a malicious IIS module that feeds manipulated content...

Advertisement
Android Runtime · Bod 22-01

CISA Warns: Patch Linux Kernel, Android, and Sitecore Now as Active Attacks Confirmed

{ "title": "CISA Warns: Patch Linux Kernel, Android, and Sitecore Now as Active Attacks Confirmed", "content": "CISA has added three actively exploited vulnerabilities to its Known Exploited...

SE Security Desk·45w ago
Backdoor · C2

ESET Exposes GhostRedirector: China-Aligned Hackers Deploy IIS SEO Fraud and Custom Backdoor on 65 Windows Servers

In June 2025, ESET researchers unearthed a previously unknown threat actor they call GhostRedirector, which had compromised at least 65 Windows servers around the globe. The attackers deployed two...

SE Security Desk·45w ago
Ai Benchmarks · Ai Pcs

Windows 10’s October 2025 End Sparks Heated Debate: Should Microsoft Open Legacy Drivers?

With the clock ticking down to October 14, 2025, millions of Windows 10 PCs are facing an unprecedented crossroads: upgrade to Windows 11, pay for a temporary safety net, or keep running an...

AI AI & Copilot Desk·45w ago
Acp · Asterisk

FreePBX Zero-Day Exploited in Wild: CISA Orders Emergency Patching for CVSS 10 RCE

CISA on August 29, 2025, added a critical vulnerability in Sangoma’s FreePBX telephony platform to its Known Exploited Vulnerabilities (KEV) Catalog, warning that attackers have been exploiting the...

SE Security Desk·46w ago
Authentication · Back To School

RDP Timing Attacks Explode to 30,000 Malicious IPs in Pre-Attack Reconnaissance on U.S. Schools

Last week, threat intelligence firm GreyNoise observed a coordinated scanning campaign targeting Microsoft Remote Desktop Protocol (RDP) services that rapidly escalated from an initial wave of nearly...

SE Security Desk·46w ago
Authentication · Cisa

CISA Flags Zero-Day in INVT VT-Designer and HMITool: Remote Code Execution via Malicious Files

A zero-day vulnerability in INVT's VT-Designer and HMITool engineering software lets attackers run arbitrary code on industrial control system (ICS) workstations simply by tricking a user into...

SE Security Desk·47w ago
Bod 22-01 · Cisa

CISA Flags Urgent Patches for Exploited Citrix Session Recording and Git Flaws

The Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on August 25, 2025, signaling active exploitation of flaws...

SE Security Desk·47w ago
Ad Fs · Autonomous Malware Classification

Proofpoint Link Wrappers Hijacked in Malvertising Campaign Targeting Microsoft 365 Credentials

A sophisticated malvertising campaign is abusing legitimate link-wrapping services from Proofpoint and Intermedia, combined with Microsoft’s own Active Directory Federation Services (ADFS) redirect...

SE Security Desk·47w ago