Threat Intelligence
The latest Threat Intelligence coverage — news, analysis, and updates from the WindowsNews.AI desk.
ESET Uncovers GhostRedirector: Silent IIS Backdoor Drives SEO Fraud on 65+ Windows Servers
At least 65 internet-facing Windows servers have been quietly conscripted into an SEO fraud network, each one armed with a stealthy backdoor and a malicious IIS module that feeds manipulated content...
Google Rushes Chrome 140 Fix for CVE-2025-9864 V8 Memory Bug, Microsoft Edge Also Patched
Google has released a critical security update for its Chrome browser, patching a high-severity use-after-free vulnerability in the V8 JavaScript engine that could let attackers hijack systems...
GhostRedirector Sneaks Native Backdoors Into IIS to Hijack SEO Rankings
A stealthy campaign that has compromised at least 65 Internet-facing Windows IIS servers worldwide is using a pair of previously unseen native implants to convert legitimate websites into invisible...
Behind CVE-2025-55241: Why the MSRC Advisory Is Sparking a Hunt for Windows Exploit Defenses
Microsoft's Security Response Center published advisory CVE-2025-55241, and within hours, security practitioners weren't just scanning for patches—they were demanding deep-dive guidance on...
CISA Warns: Patch Linux Kernel, Android, and Sitecore Now as Active Attacks Confirmed
{ "title": "CISA Warns: Patch Linux Kernel, Android, and Sitecore Now as Active Attacks Confirmed", "content": "CISA has added three actively exploited vulnerabilities to its Known Exploited...
ESET Exposes GhostRedirector: China-Aligned Hackers Deploy IIS SEO Fraud and Custom Backdoor on 65 Windows Servers
In June 2025, ESET researchers unearthed a previously unknown threat actor they call GhostRedirector, which had compromised at least 65 Windows servers around the globe. The attackers deployed two...
Windows 10’s October 2025 End Sparks Heated Debate: Should Microsoft Open Legacy Drivers?
With the clock ticking down to October 14, 2025, millions of Windows 10 PCs are facing an unprecedented crossroads: upgrade to Windows 11, pay for a temporary safety net, or keep running an...
FreePBX Zero-Day Exploited in Wild: CISA Orders Emergency Patching for CVSS 10 RCE
CISA on August 29, 2025, added a critical vulnerability in Sangoma’s FreePBX telephony platform to its Known Exploited Vulnerabilities (KEV) Catalog, warning that attackers have been exploiting the...
RDP Timing Attacks Explode to 30,000 Malicious IPs in Pre-Attack Reconnaissance on U.S. Schools
Last week, threat intelligence firm GreyNoise observed a coordinated scanning campaign targeting Microsoft Remote Desktop Protocol (RDP) services that rapidly escalated from an initial wave of nearly...
CISA Flags Zero-Day in INVT VT-Designer and HMITool: Remote Code Execution via Malicious Files
A zero-day vulnerability in INVT's VT-Designer and HMITool engineering software lets attackers run arbitrary code on industrial control system (ICS) workstations simply by tricking a user into...
CISA Flags Urgent Patches for Exploited Citrix Session Recording and Git Flaws
The Cybersecurity and Infrastructure Security Agency (CISA) added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog on August 25, 2025, signaling active exploitation of flaws...
Proofpoint Link Wrappers Hijacked in Malvertising Campaign Targeting Microsoft 365 Credentials
A sophisticated malvertising campaign is abusing legitimate link-wrapping services from Proofpoint and Intermedia, combined with Microsoft’s own Active Directory Federation Services (ADFS) redirect...