Microsoft has patched a critical zero-day vulnerability, CVE-2025-30400, in the Windows DWM, allowing attackers to escalate privileges to SYSTEM level. Disclosed on May 13, 2025, the flaw involved a “use-after-free” memory issue and posed significant risks. Users are urged to update systems immediately to mitigate exploitation risks, which were already detected pre-patch.

North Korean hackers step up phishing attacks on Ukraine government
North Korean state-sponsored cyber actor, TA406, is carrying out phishing attacks and credential-stealing operations against Ukrainian government entities to gather intelligence on the Russian invasion,