Silent Escalation: CLFS Zero-Day Used in Targeted Attack

Red | Attack Report
Download PDF

A U.S. organization was hit by a stealthy cyberattack linked to the Play ransomware operation, who took advantage of a flaw in Windows tracked as CVE-2025-29824 to gain higher system access. Using a custom-built infostealer called Grixba and cleverly disguised tools, the attackers quietly collected sensitive data and moved through the network undetected, underscoring the rising risk of zero-day exploits and sophisticated hacking tactics.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox