Play Ransomware Group Used Windows Zero-Day
ID: 837165e7-be1c-5d80-8c55-70ec526b1dd9
STIX ID: report--837165e7-be1c-5d80-8c55-70ec526b1dd9
Feed Name: Dark Reading
Multiple ransomware actors exploited a Windows Common Log File System privilege-escalation zero-day (CVE-2025-29824) in the wild prior to Microsoft's April 2025 patch: Microsoft linked active exploitation to Storm-2460 while Symantec found Balloonfly/Play using a different exploit variant to deploy a Grixba infostealer and other malicious tools, enabling system-level privileges, lateral movement and potential ransomware deployment; Microsoft urges organizations to prioritize applying the patch to mitigate ransomware risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
