Untitled attachment
https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/542/751/761/150/441/original/ee626285e645564f.png
Previously there was a report of threat actors using .URL files pointed at a WebDAV server, which made for, air quotes, "remote code execution", and was tracked as CVE-2025-33053. Turns out, you can do the same thing with a regular Windows Shortcut. Video: https://youtu.be/1Ymnvd1uyzQ
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.