CVE-2025-24054, NTLM Exploit in the Wild

Key Points CVE-2025-24054 is a vulnerability related to NTLM hash disclosure via spoofing, which can be exploited using a maliciously crafted .library-ms file. Active exploitation in the wild has been observed since March 19, 2025, potentially allowing attackers to leak NTLM hashes or user passwords and compromise systems. Although Microsoft released a patch on March…

Read More

Disney and Universal Sue AI Company Midjourney for Copyright Infringement

Disney and Universal have filed a lawsuit against Midjourney, alleging that the San Francisco–based AI image generation startup is a “bottomless pit of plagiarism” that generates “endless unauthorized copies” of the studios’ work. There are already dozens of copyright lawsuits against AI companies winding through the US court system—including a class action lawsuit visual artists…

Read More

21st April – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 21st April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Retail giant Ahold Delhaize has suffered a cyber-attack resulting in data theft of customer information from its US business systems. The attack, claimed by ransomware group INC Ransom, impacted Ahold Delhaize USA…

Read More