The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent advisory regarding an actively exploited vulnerability in Microsoft Windows Management Console (MMC), tracked as CVE-2025-26633. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. As attackers increasingly target foundational Windows components, the cybersecurity community must advocate for modernizing legacy systems and adopting zero-trust architectures to mitigate future risks. Organizations relying on MMC for Active Directory or Group Policy management should test patches in staging environments before deployment. Kaaviya is a Security Editor and fellow reporter with Cyber Security News. A sophisticated backdoor malware called "Squidoor" being deployed by suspected Chinese threat actors against organizations across South America and Southeast Asia. Successful exploitation grants unauthorized privileges, enabling lateral movement within networks, data exfiltration, or deployment of secondary payloads. For cloud services, CISA mandates compliance with BOD 22-01’s hardening guidelines, including network segmentation and least-privilege access controls. She is covering various cyber security incidents happening in the Cyber Space. Private organizations are strongly encouraged to prioritize this vulnerability in their patch management cycles.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 12 Mar 2025 09:05:16 +0000