Hackers are now actively leveraging a Windows vulnerability that exposes NTLM hashes using.library-ms files in phishing efforts aimed at both private and governmental organizations.
Microsoft patched the vulnerability known as CVE-2025-24054 on March 2025. At first, it was considered ‘less likely’ to be exploited and not indicated as such.
Only a few days after updates were made available, however, Check Point researchers report seeing active exploitation activity for CVE-2025-24054, which culminated between March 20 and 25, 2025.
There is insufficient information to make a firm attribution, even though one of the IP addresses responsible for these assaults was previously connected to the state-sponsored threat group APT28 read more about Windows NTLM hash leak flaw exploited in phishing attacks on governments.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
