TrustedSec[verified]@TrustedSecPatch
The blog discusses the newly patched Windows shortcut vulnerability CVE-2026-25185, describing how a particular ExtraData block can silently bypass authentication—no PoC, exploit, or active exploitation is mentioned.
Mr.Rabbit[verified]@01ra66itPoC
The post announces the Windows .lnk vulnerability CVE‑2026‑25185, details how it leaks credentials via SMB/UNC paths, and confirms a published PoC named LnkMeMaybe along with technical specifics.
VulnTracker[verified]@vuln_trackerDisclosure
The tweet announces that CVE-2026-25185 enables zero‑click authentication coercion via Windows shortcuts using ExtraData blocks, highlighting a serious vulnerability but providing no PoC, exploit code, patch, or evidence of active exploitation.
Israel[verified]@f1tym1Patch
Micropatches addressing CVE-2026-25185 were released in March 2026 as part of Windows updates, fixing a shell link spoofing vulnerability.
freefirex@freefirex2Disclosure
The text announces the discoverer’s first CVE (CVE‑2026‑25185) and links to Microsoft’s update guide, but provides no exploit details, patches, or technical specifics.
0patch@0patchPatch
Micropatches have been released to mitigate the Windows Shell Link Processing Spoofing vulnerability CVE‑2026‑25185, as announced by 0patch.
Florian Hansemann@CyberWarshipGeneral
The post is a brief mention of a blog review on CVE‑2026‑25185, lacking specific evidence of PoC, exploit availability, active use, patches, or technical details.
ET Labs@ET_LabsGeneral
The update lists several new malware campaigns and one specific vulnerability (CVE‑2026‑25185) related to Windows Shell Link spoofing, but offers no PoC, exploit code, active use, or patch details.