Microsoft silently mitigates Windows LNK Zero-Day flaw exploited by state-backed hackers
Microsoft silently patched a high-severity Windows LNK vulnerability (CVE-2025-9491) that was actively exploited by at least 11 state-backed hacking groups and cybercrime organizations to hide malicious commands within .lNK files by padding them beyond the 260-character visibility limit. The flaw, which targeted European diplomatic entities and government departments, initially was not patched by Microsoft despite exploitation. The November 2025 fix is incomplete as it doesn't remove existing malicious code or warn users about suspicious files.
**Apply the November 2025 Windows updates immediately to partially mitigate a vulnerability, which allows hackers to hide malicious commands in .LNK shortcut files. Also, be EXTREMELY cautious opening any .LNK files from emails or downloads, especially from ZIP archives - even after updating, only open shortcuts from sources you can absolutely verify and trust.**
#cybersecurity #infosec #attack #activeexploit
https://beyondmachines.net/event_details/microsoft-silently-mitigates-windows-lnk-zero-day-flaw-exploited-by-state-backed-hackers-l-c-e-8-v/gD2P6Ple2L