Windows Shortcut Exploit Abused as Zero-Day in Widespread APT Campaigns
A Windows .lnk file vulnerability, ZDI-CAN-25373, has been extensively exploited by state-sponsored and cybercriminal groups. The vulnerability allows hidden command execution through crafted shortcut files, exposing organizations to data theft and cyber espionage risks. Nearly 1,000 malicious .lnk files abusing this vulnerability have been identified, with APT groups from North Korea, Iran, Russia, and China involved in the attacks. Targeted sectors include government, finance, telecommunications, military, and energy across North America, Europe, Asia, South America, and Australia. The exploitation leverages hidden command line arguments within .lnk files, complicating detection. Organizations are urged to implement security measures and maintain vigilance against suspicious .lnk files.
Pulse ID: 67d9de9f2917454580d43f6a
Pulse Link: https://otx.alienvault.com/pulse/67d9de9f2917454580d43f6a
Pulse Author: AlienVault
Created: 2025-03-18 20:59:11
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
The hard-working folk of the Australian Signals Directorate, a department that rarely gets mentioned (and they like it that way) has completed a major coup ASD against the Russian group who snatched millions of records from Australia's Medibank health insurance provider a couple of years ago.
With the help of the UK and US, they identified the major players, located the servers, and wiped out 250 𝘵𝘦𝘳𝘢𝘣𝘺𝘵𝘦𝘴 of stolen data; the Australian info, and that of many more organisations.
All gone, bye-bye.
The people who ran the show went out for a drink (Russian style, so they got blotto), and while they were in no position to respond, the ASD snuck in to their system and did the deed. The show runners are now sanctioned and on catch-and-keep lists.
Well done, everybody!
Kadrey v. Meta: Unsealed emails reveal Meta allegedly torrented 81.7TB+ of data from multiple shadow libraries via Anna's Archive for AI training. #Meta #AItraining #DataTheft #AIethics #Privacy #TechNews #LegalBattle #ArtificialIntelligence #AnnaArchive
If you believe that Musk just has read-only access, I've got a bridge I'd like to sell you.
@jolla I won’t run anything that has access to my personal data anywhere else than on a device I control.
Centralised models like OpenAI are #datatheft honeypots.
I welcome this innovation, which seems to come with the tools I need to connect to that computer running in my home securely over my phone, transmitting nothing but my prompt and the inference.
With Elon the #oligarch getting full access to Treasury systems, his goons now have access to our SSN and bank details that we provide to IRS for tax refunds and payments, all without our consent. Musk is not a Senate-confirmed government official. Can we all get together and sue him for stealing our sensitive financial data? A class action law suit with 100+ million Americans.
Any #lawyers on here who can weigh on the feasibility?
"OpenAI furious DeepSeek might have stolen all the data OpenAI stole from us"
Hahahahahahahahahahahahahahahaha
https://www.404media.co/email/855bf870-82ce-4544-8776-2225627fa39d/