Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Microsoft Patched Windows LNK Vulnerability Abused by Hackers to Hide Malicious Code

Microsoft has addressed the Windows shortcut vulnerability identified as CVE-2025-9491 . This vulnerability, exploited by threat actors since 2017, was patched in the November 2025 Patch Tuesday updates but was not prominently listed among the officially…

Microsoft has addressed the Windows shortcut vulnerability identified as CVE-2025-9491 . This vulnerability, exploited by threat actors since 2017, was patched in the November 2025 Patch Tuesday updates but was not prominently listed among the officially patched vulnerabilities.

The issue was initially reported on March 18, 2025, when researchers from Trend Micro's Zero Day Initiative, Peter Girnus, and Aliakbar Zahravi, published their findings. They identified nearly 1,000 malicious Windows shortcut (.lnk) files exploiting this flaw across various offensive campaigns dating back to 2017.

The vulnerability allowed attackers to create shortcut files that concealed malicious commands by displaying only the first 260 characters of the Target field in the Properties dialog.

Microsoft initially declined to patch this issue after being notified in September 2024, citing that it did not meet their servicing threshold and that existing security warnings provided adequate protection through the Mark of the Web feature.

Microsoft has addressed the Windows shortcut vulnerability identified as CVE-2025-9491 .
Noah Redmond · Thehackingpost

In October 2025, research from Arctic Wolf highlighted active exploitation of this vulnerability by threat actor UNC6384, targeting Hungarian and Belgian diplomatic entities. The attackers used PlugX malware, leveraging the UI misrepresentation flaw to hide malicious PowerShell commands.

Despite in-the-wild exploitation, Microsoft issued Advisory ADV25258226, maintaining that due to user interaction and existing warnings about untrusted formats, this was not considered a vulnerability.

In November 2025, Microsoft updated how Windows displays LNK file properties. The Properties dialog now shows the entire Target command, although in a single-line field requiring text selection to view completely. This change was not acknowledged in the official patch documentation.

Advertisement

ACROS Security developed an alternative patch that truncates any LNK file Target field exceeding 260 characters and alerts users to suspicious activity. This solution aims to block the malicious shortcuts identified by Trend Micro while preserving functionality for legitimate shortcuts.

Security experts recommend enhancing endpoint detection capabilities and conducting security awareness training to identify suspicious shortcut files, especially those received via email or downloaded from untrusted sources.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories