
Microsoft and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) have issued warnings about a critical Windows vulnerability exploited in a targeted cyberattack on a major Turkish defence organisation.
Discovered by researchers at Check Point, the vulnerability — tracked as CVE-2025-33053 — affects the Web Distributed Authoring and Versioning (WebDAV) feature in Windows. WebDAV allows users to manage files remotely and exists in legacy systems like Internet Explorer and Edge.
The flaw was weaponised in March by attackers who lured victims with a disguised .url file, seemingly a PDF related to military equipment. Once opened, the file enabled the hackers to execute code remotely from their server, effectively bypassing security measures.
Microsoft released a patch for the zero-day this week as part of its June Patch Tuesday update. The flaw has been given a high severity rating of 8.8 out of 10 and has been added to CISA’s Known Exploited Vulnerabilities catalogue.
Check Point attributed the attack to Stealth Falcon, an advanced persistent threat (APT) group previously linked to cyber-espionage across the Middle East and Africa. The group, believed to have ties to the UAE, is known for spearphishing campaigns and the use of zero-day exploits.
In this operation, Stealth Falcon deployed custom tools — dubbed Horus Agent and Horus Loader — to establish surveillance, avoid detection, and maintain persistence within the targeted network.
Cybersecurity analysts note that the campaign highlights the growing sophistication of APT groups and the continued targeting of government and defence entities. Organisations are urged to apply Microsoft’s patch immediately and remain vigilant against phishing threats.
Stealth Falcon’s ongoing evolution, combining zero-day exploits with legitimate tools and layered malware, signals a sustained threat to sensitive sectors worldwide.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543