AD

‎Microsoft Fixes 8-Year Windows Security Flaw

The long-standing Microsoft flaw, tracked as CVE-2025-9491, allowed cybercriminals to hide malicious commands from users inspecting files through Windows’ standard interface, but the tech giant never officially announced the fix.

‎The update claimed that the flaw had existed for eight years, and that Windows users had unknowingly lived with a security hole that nation-states exploited daily. However, State-sponsored hacking groups from Asian countries and the Middle East— China, Iran, North Korea, and Russia, respectively- have weaponised this Windows shortcut vulnerability since 2017.

‎That notwithstanding, Trend Micro’s Zero Day Initiative discovered that 11 different government-backed teams actively exploited the security hole, turning what should have been harmless shortcut files into dangerous attack vectors.

‎The vulnerability impacted the way Windows displays LNK (shortcut) files, allowing attackers to create harmful shortcuts that seemed entirely safe when users examined their properties. Security researchers discovered nearly 1,000 malicious shortcut files that exploited this vulnerability across offensive campaigns spanning eight years.

‎Microsoft’s reaction to this vulnerability highlights a troubling trend in the company’s approach to security priorities. When researchers initially reported the flaw, Microsoft stated that it “does not meet the bar for immediate servicing” and intended to address it in a future update rather than through urgent patches.

News: Imose Technologies Offer Freebies On New Tablet Devices

‎The flaw was deceptively straightforward: Windows displayed only the initial part of harmful commands, concealing the dangerous segments that followed. Security firm 0patch clarified that while LNK files can include very lengthy Target arguments, the Properties dialogue only reveals the first 260 characters, quietly obscuring everything else from users. Attackers could embed malicious PowerShell commands beyond that character limit, causing their shortcuts to seem legitimate during inspection.

‎Increasing evidence of widespread exploitation ultimately compelled Microsoft to act. The XDSpy cyber espionage group utilised the flaw to spread malware aimed at Eastern European government entities, while Chinese-affiliated threat actors weaponised it just last month to target European diplomatic offices with PlugX malware.

‎Just a month ago, attacks showcased this vulnerability’s alarming potential for espionage activities. The Chinese threat group UNC6384 executed a sophisticated campaign against European diplomatic entities throughout September and October, exploiting CVE-2025-9491 to deploy the infamous PlugX remote access trojan.

Oh hi there 👋
It’s nice to meet you.

Sign up to receive awesome content in your inbox.

We don’t spam! Read our privacy policy for more info.

More Top Stories

Osimhen Out of Hospital After Successful Surgery, Eyes Quick Return
Osimhen Backed for Man United Move as Butt Says He Can Elevate Sesko
Drama Erupts as Verydarkman Fires Back at Blessing CEO Over Cancer Claim
Kpai Them All!” — Sarian Martins Unleashes Fury, Links Blessing CEO’s Illness to ‘Spiritual Payback’
Nwaiwu Earns Super Eagles Call-Up as Bassey Withdraws Ahead of Iran, Jordan Friendlies
Super Eagles star Alex Iwobi Leads 7-Man Premier League Player of the Month Shortlist
Delta Queens Edge FC Robo In Five-Goal Thriller to Boost Super Six Push
‎Injury knocks out ‘Super’ Calvin Bassey as Eagles suffer Int’l Friendlies blow‎
Osimhen Set for Race Against Time as Galatasaray Target Quick Return
Super Eagles Open Camp in Turkey Ahead of Iran, Jordan Friendlies
Chukwueze Set for Permanent Fulham Move After Impressive Loan Spell
Rivers United Humiliated as Nasarawa United Run Riot in 4–1 Thriller
‎Chelle can win next AFCON, He deserves a new contract –Ibitoye‎
‎Rivers United blame CAF Champions League for slump‎
Morocco National Team Captain Rejects AFCON Title, Backs Senegal as True Champions
‎Title race heats up as Rivers, Rangers face defining fixtures‎‎
Oborevwori Denies Assaulting Kickboxing Coach in Reimbursement Row
‎NFF faces court notice over congress misconduct‎
FULL CIRCLE AT WEMBLEY: ARSENAL, MAN CITY AND A FINAL LOADED WITH HISTORY
Finidi George Under Pressure as Rivers United’s Title Grip Slips
Osimhen Injury Shifted Momentum as Liverpool Power Through-Slot
Rivers United Stumble Again as Niger Tornadoes Strike Late to Deepen Title Tension
‎Ademola Lookman Cruise into UCL Q’finals, Osimhen Crash out‎
CAF Strips Senegal of AFCON Title, Crowns Morocco Champions After Dramatic Final Controversy
Ikorodu City Dominate Rivers United to Seal Crucial Home Victory
Rivers United Confront Tough Ikorodu City Test as NPFL Title Race Reaches Boiling Point
Obi Mikel Demands NFF Leadership Resignation After Nigeria’s World Cup Failure
Super Eagles Calvin Bassey is a beast” –Bryan Mbeumo‎
Ibinabo Fiberesima Opens Auditions For Web Series In Port Harcourt
Tinubu, NFF Mourns Former Super Eagles Coach Adegboye Onigbinde
Lemina Header Sinks Liverpool as Galatasaray Claim Crucial First Leg Victory
D’Tigress Arrive Lyon Ahead Of 2026 FIBA Women’s World Cup Qualifying
NPFL: Rivers United Trash Bendel Insurance to Remain Top
Portable Storms Street Face-Off on Horseback Ahead of Clash with Carter Efe
Thank You, But Not Very Much
RIVCHPP Urges Residents to Promote Health Insurance Enrollment
33% of Candidates Pass WAEC 2026 Private Exam
National Police Day: CP Adepoju Reaffirms Commitment to Human Rights, Community Policing
Education Boost in Omuma as Rivers NYSC Member Upgrades School Infrastructure

Leave a Reply

Your email address will not be published. Required fields are marked *