Unpatched Microsoft zero-day has been exploited by DPRK, Iran, Russia, and China (trendmicro.com)
Trend Zero Day Initiativeā„¢ (ZDI) uncovered both state-sponsored and cybercriminal groups extensively exploiting ZDI-CAN-25373 (aka ZDI-25-148), a Windows .lnk file vulnerability that enables hidden command execution.