logo

Windows LNK Exploits

State-backed and criminal actors have long abused Windows .lnk shortcut handling and UI‑misrepresentation flaws (e.g., ZDI-CAN-25373/CVE-2025-9491) to hide command-line arguments and deliver malware, prompting detection guidance and uneven vendor fixes.

List of posts related to this topic

Post TitleDate PublishedDescribes IncidentFeed
Microsoft: New Windows LNK spoofing issues aren't vulnerabilities2026-02-12TrueBleeping Computer
Not Subscribed
Microsoft quietly shuts down Windows shortcut flaw after years of espionage abuse2025-12-04TrueThe Register (Security)
Not Subscribed
Microsoft Patched Windows LNK Vulnerability Abused by Hackers to Hide Malicious Code2025-12-03TruecybersecurityNews.com
Not Subscribed
Windows Shortcut (LNK) Malware Strategies2025-07-02TruePalo Alto Networks Unit 42
Not Subscribed
Nation-state actors and cybercrime gangs abuse malicious .lnk files for espionage and data theft2025-03-18TrueSecurity Affairs
Not Subscribed
8-Year Old Windows Shortcut Zero-Day Exploited by 11 State-Sponsored Hacker Groups2025-03-18TruecybersecurityNews.com
Not Subscribed
New Windows zero-day exploited by 11 state hacking groups since 20172025-03-18TrueBleeping Computer
Not Subscribed
Microsoft isn't fixing 8-year-old shortcut exploit abused for spying2025-03-18TrueThe Register (Security)
Not Subscribed

1–8 of 8