Microsoft spots zero-day use in spy campaign against Kurdish military in Iraq
ID: 3f460a90-6be4-5529-81cd-effc08b19f0f
STIX ID: report--3f460a90-6be4-5529-81cd-effc08b19f0f
Feed Name: The Record from Recorded Future News
Researchers report that the Turkish-aligned APT 'Marbled Dust' exploited a zero-day (CVE-2025-27920) in Output Messenger to upload malicious files to server startup directories and spy on Kurdish military operations in Iraq; Microsoft links the activity to groups tracked as Sea Turtle/UNC1326, notes possible credential-interception techniques (DNS hijacking/typosquatting), and says Srimax has issued patches including for a second non-exploited CVE (CVE-2025-27921).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
