Windows NTLM hash leak flaw exploited in phishing attacks on governments
Hackers are now actively leveraging a Windows vulnerability that exposes NTLM hashes using.library-ms files in phishing efforts aimed at both private and governmental organizations.
Microsoft patched the vulnerability known as CVE-2025-24054 on March 2025. At first, it was considered 'less likely' to be exploited and not indicated as such.
Only a few days after updates were made available, however, Check Point researchers report seeing active exploitation activity for CVE-2025-24054, which culminated between March 20 and 25, 2025.
There is insufficient information to make a firm attribution, even though one of the IP addresses responsible for these assaults was previously connected to the state-sponsored threat group APT28 read more about Windows NTLM hash leak flaw exploited in ...


