Inside Stealth Falcon’s Espionage Campaign Using a Microsoft Zero-Day

Inside Stealth Falcon’s Espionage Campaign Using a Microsoft Zero-Day Check Point Research (CPR) identified a previously unknown Windows vulnerability (CVE-2025-33053) being actively exploited in the wild. Following CPR’s responsible disclosure, Microsoft released a patch on its June 10th Patch Tuesday The zero-day was used in a targeted espionage operation likely conducted by Stealth Falcon, a threat group known to target entities in the Middle East and Africa. The attack chain begins with a deceptive internet shortcut (.url file) that silently triggers malware hosted on an attacker-controlled WebDAV server, abusing legitimate Windows tools in the process. The operation deployed a sophisticated […]

The post Inside Stealth Falcon’s Espionage Campaign Using a Microsoft Zero-Day appeared first on Check Point Blog.



from Check Point Blog https://ift.tt/I7CFwlh
via

No comments:

Post a Comment

World Password Day 2026: Why “Strong Passwords” Can’t Save You from AI, Infostealers, and the Telegram Underground

As we recognize World Password Day in 2026, the traditional advice to “use a complex password with numbers and symbols” feels hopelessly out...