⚡ THN Weekly Recap: From $1.5B Crypto Heist to AI Misuse & Apple’s Data Dilemma
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-0171 | Unauthenticated RCE/DoS in Cisco IOS & IOS XE Smart Install CVE-2018-0171 is a critical (CVSS 9.8) buffer-overflow vulnerability in the Smart Install feature of Cisco IOS and Cisco IOS XE, caused by improper validation of packet data (CWE-20, CWE-787). An unauthenticated, remote attacker can trigger it by simply sending a crafted Smart Install message to TCP port 4786 on an affected device, with no credentials or user interaction required. A successful exploit can cause a device reload, an indefinite loop that triggers a watchdog crash, or arbitrary code execution, giving the attacker full control of the switch or router. Any IOS or IOS XE device running the Smart Install service is affected — a configuration commonly present on Catalyst switches — and devices exposed to the internet on TCP 4786 are at direct risk. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog, and both Russian (Static Tundra, FSB-linked) and Chinese (Salt Typhoon) state-sponsored actors have exploited it to compromise unpatched, often end-of-life, Cisco network devices at hundreds of organizations worldwide. Do: Upgrade IOS/IOS XE to a fixed release per Cisco's advisory (Bug ID CSCvg76186); for end-of-life hardware that cannot be patched, plan replacement given active nation-state targeting of unpatched devices. If Smart Install is not in use, disable it with 'no vstack'; otherwise restrict TCP port 4786 with ACLs to trusted management hosts. Audit internet-facing switches and routers for Smart Install enabled and TCP 4786 exposed, and prioritize those devices for remediation. | 9.8 | 99% | KEV |
| mass≈250,000+ internet-exposed devices with TCP/4786 open, on top of a multi-million-device IOS/IOS XE installed base | |
| CVE-2024-12284 | Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. NVD description · AI analysis pending | 8.8 | 13% |
| — | ||
| CVE-2024-12510 | If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup. NVD description · AI analysis pending | 6.7 | <1% | — | — | ||
| CVE-2024-12511 | With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. With address book access, SMB/FTP settings could be modified, redirecting scans and possibly capturing credentials. This requires enabled scan functions and printer access. NVD description · AI analysis pending | 7.6 | <1% | — | — | ||
| CVE-2024-50379 | TOCTOU Race Condition in Apache Tomcat JSP Compilation Enables RCE CVE-2024-50379 is a time-of-check time-of-use (TOCTOU) race condition (CWE-367) in Apache Tomcat's JSP compilation path that permits unauthenticated remote code execution when Tomcat runs on a case-insensitive file system and the default servlet is enabled for write, which is a non-default configuration. An attacker who can upload or modify files through the write-enabled default servlet can race the JSP compiler so that an altered file is compiled and executed in place of the version that was checked, yielding code execution in the context of the Tomcat process (CVSS 3.1 9.8, network vector with no privileges required). Affected versions are 11.0.0-M1 through 11.0.1, 10.1.0-M1 through 10.1.33, and 9.0.0.M1 through 9.0.97, plus EOL releases 8.5.0 through 8.5.100 and possibly older EOL versions; NetApp products that embed Apache Tomcat are also listed as affected. The flaw is fixed in Tomcat 11.0.2, 10.1.34, and 9.0.98. As of this analysis there is no CISA KEV entry and no public PoC or confirmed in-the-wild exploitation is known, but EPSS assigns a 44.3% probability of exploitation within 30 days (99th percentile), making this a high-priority patch. Do: Upgrade Tomcat to 11.0.2, 10.1.34, or 9.0.98 as applicable; EOL 8.5.x deployments should migrate to a supported branch since no further 8.5 fixes are listed. Check whether your deployment runs on a case-insensitive file system (e.g., Windows, macOS) and whether the default servlet is enabled for write; if it is read-only, the exposure under the current description is low. NetApp customers should review NetApp security advisories for their products that embed Tomcat. | 9.8 | 44% |
| mass≈500,000+ internet-exposed Tomcat instances per public scan counts, with several million total deployments including embedded use | ||
| CVE-2024-50608 +1 in the same advisory: …50609 | An issue was discovered in Fluent Bit 3.1.9. An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl_sds_len, which in turn tries to cast a NULL pointer into struct cfl_sds. This is related to process_payload_metrics_ng() at prom_rw_prot.c. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2024-52316 | Unchecked Error Condition vulnerability in Apache Tomcat. Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M26, from 10.1.0-M1 through 10.1.30, from 9.0.0-M1 through 9.0.95. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fix the issue. NVD description · AI analysis pending | 9.8 | 6% |
| — | ||
| CVE-2024-53900 | Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. Mongoose before 8.8.3 can improperly use $where in match, leading to search injection. NVD description · AI analysis pending | 9.1 | 4% |
| — | ||
| CVE-2024-54756 | A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a craf A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file. NVD description · AI analysis pending | 9.8 | 3% | — | — | ||
| CVE-2024-54961 | Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email Nagios XI 2024R1.2.2 has an Information Disclosure vulnerability, which allows unauthenticated users to access multiple pages displaying the usernames and email addresses of all current users. NVD description · AI analysis pending | 6.5 | 2% |
| — | ||
| CVE-2024-56337 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. The mitigation for CVE-2024-50379 was incomplete. Users running Tomcat on a case insensitive file system with the default servlet write enabled (readonly initialisation parameter set to the non-default value of false) may need additional configuration to fully mitigate CVE-2024-50379 depending on which version of Java they are using with Tomcat: - running on Java 8 or Java 11: the system property sun.io.useCanonCaches must be explicitly set to false (it defaults to true) - running on Java 17: the system property sun.io.useCanonCaches, if set, must be set to false (it defaults to false) - running on Java 21 onwards: no further configuration is required (the system property and the problematic cache have been removed) Tomcat 11.0.3, 10.1.35 and 9.0.99 onwards will include checks that sun.io.useCanonCaches is set appropriately before allowing the default servlet to be write enabled on a case insensitive file system. Tomcat will also set sun.io.useCanonCaches to false by default where it can. NVD description · AI analysis pending | 9.8 | 9% |
| — | ||
| CVE-2024-57045 | Authentication Bypass in D-Link DIR-859 Firmware Leaks Admin Credentials CVE-2024-57045 is an improper-authentication flaw (CWE-287) in D-Link DIR-859 routers running firmware A3 1.05 or earlier that lets an unauthenticated attacker bypass access controls. It is triggered by sending a forged POST request to the router's /getcfg.php page, which returns the device's username and password without any prior authentication or user interaction. An attacker who recovers these credentials gains access to the router's management interface and, from there, potentially to the network it controls. Any DIR-859 (A3 hardware revision) running affected firmware is exposed, with risk greatest for devices whose web interface is reachable from the internet or from untrusted LAN clients. No confirmed in-the-wild exploitation is recorded (not in CISA KEV), but a public proof-of-concept exists and EPSS estimates roughly a 32% probability of exploitation within 30 days, so defenders should treat it as likely to be exploited. Do: Inventory networks for DIR-859 (A3) routers on firmware A3 1.05 or earlier and check D-Link's support portal for updated firmware, as no fixed version is provided in the disclosure data. Until patched, restrict the web management interface to trusted LAN segments (disable remote/WAN-side management) and limit untrusted LAN clients, since any client that can reach /getcfg.php can retrieve the credentials. Rotate the administrator username and password after patching or mitigating, and consider replacing the device if it is end-of-life and no firmware fix is released. | 9.8 | 32% | PoC |
| largetens of thousands of internet-exposed DIR-859 routers (est.); total installed base likely higher | |
| CVE-2024-57049 | Rejected reason: DO NOT USE THIS CVE RECORD. Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. NVD description · AI analysis pending | — | — | — | — | ||
| CVE-2024-57050 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11714. Reason: This candidate is a reservation duplicate of CVE-2018-11714. Notes: All CVE users should reference CVE-2018-11714 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. NVD description · AI analysis pending | — | — | — | — | ||
| CVE-2024-57401 | SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password function. SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password function. NVD description · AI analysis pending | 9.8 | <1% | — | — | ||
| CVE-2025-0366 | The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_s The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution. In this specific case, an attacker can create a form that allows SVG uploads, upload an SVG file with malicious content and then include the SVG file in a post to achieve remote code execution. This means it is relatively easy to gain remote code execution as a contributor-level user and above by default. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2025-0868 | A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of JSON data using eval() an unauthorized attacker could send arbitrary Python code to be executed via /api/remote endpoint.. This issue affects DocsGPT: from 0.8.1 through 0.12.0. NVD description · AI analysis pending | 9.3 | 17% | — | — | ||
| CVE-2025-1023 | A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vul A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a time-based blind SQL Injection vulnerability in the EditEventTypes functionality. The newCountName parameter is directly concatenated into an SQL query without proper sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion. NVD description · AI analysis pending | 9.3 | 2% | PoC |
| — | |
| CVE-2025-1134 | A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploiting a boolean-based and time-based blind SQL Injection vulnerability in the DonatedItemEditor functionality. The CurrentFundraiser parameter is directly concatenated into an SQL query without sufficient sanitization, allowing an attacker to manipulate database queries and execute arbitrary commands, potentially leading to data exfiltration, modification, or deletion. Please note that this vulnerability requires Administrator privileges. NVD description · AI analysis pending | 9.3 | <1% | PoC |
| — | |
| CVE-2025-20059 | Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue affects PingAM Java Policy Agent: through 5.10.3, through 2023.11.1, through 2024.9. NVD description · AI analysis pending | 9.2 | <1% | — | — | ||
| CVE-2025-21589 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and take administrative control of the device. This issue affects Session Smart Router: * from 5.6.7 before 5.6.17, * from 6.0 before 6.0.8 (affected from 6.0.8), * from 6.1 before 6.1.12-lts, * from 6.2 before 6.2.8-lts, * from 6.3 before 6.3.3-r2; This issue affects Session Smart Conductor: * from 5.6.7 before 5.6.17, * from 6.0 before 6.0.8 (affected from 6.0.8), * from 6.1 before 6.1.12-lts, * from 6.2 before 6.2.8-lts, * from 6.3 before 6.3.3-r2; This issue affects WAN Assurance Managed Routers: * from 5.6.7 before 5.6.17, * from 6.0 before 6.0.8 (affected from 6.0.8), * from 6.1 before 6.1.12-lts, * from 6.2 before 6.2.8-lts, * from 6.3 before 6.3.3-r2. NVD description · AI analysis pending | 9.3 | 1% | — | — | ||
| CVE-2025-23061 | Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900. NVD description · AI analysis pending | 9.8 | 7% |
| — | ||
| CVE-2025-23115 | A Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect Cameras mana A Use After Free vulnerability on UniFi Protect Cameras could allow a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect Cameras management network. NVD description · AI analysis pending | 9.0 | <1% | — | — | ||
| CVE-2025-23116 | An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor with access to UniFi Pr An Authentication Bypass vulnerability on UniFi Protect Application with Auto-Adopt Bridge Devices enabled could allow a malicious actor with access to UniFi Protect Cameras adjacent network to take control of UniFi Protect Cameras. NVD description · AI analysis pending | 9.6 | <1% | — | — | ||
| CVE-2025-23209 | Code Injection via Database Backup Path in Craft CMS Enables RCE Craft CMS contains a code injection flaw (CWE-94) in which the path used for database backups is not properly validated, allowing attacker-controlled input to be executed as code. An attacker who can influence the database-backup path — typically through an authenticated admin session or the utility that triggers a backup — can achieve remote code execution on the server running Craft CMS. Per CISA, the affected product is Craft CMS with no specific version range provided, so all deployments should be checked against the vendor's advisory for affected and fixed releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-20, confirming exploitation in the wild; EPSS assigns a 21.8% probability of exploitation within 30 days (97th percentile), no public proof-of-concept is known, and ransomware use is unconfirmed. Do: Apply the vendor's patched release per Craft's security advisory, or follow CISA's required action to apply mitigations or discontinue use if mitigations are unavailable; verify your installed Craft CMS version against the vendor's affected-versions list. Until patched, restrict access to admin utilities that trigger database backups and review web/application logs for unusual backup-path activity or signs of compromise. | 8.1 | 22% | KEV |
| masson the order of hundreds of thousands of sites (~10^5; third-party web-technology trackers report Craft CMS on roughly 250,000+ live websites) | |
| CVE-2025-24989 | Access Control Bypass Enables Privilege Escalation in Microsoft Power Pages CVE-2025-24989 is a critical (CVSS 9.8) improper access control flaw (CWE-284) in Microsoft Power Pages, Microsoft's low-code cloud service for building external-facing websites. An unauthenticated attacker can trigger it over the network by interacting with an affected Power Pages site, bypassing the user registration control and elevating privileges without any prior credentials or user interaction. Successful exploitation grants elevated access with high impact on the confidentiality, integrity, and availability of the affected site. Only organizations using Power Pages are in scope, and Microsoft has already mitigated the vulnerability in the cloud service and directly notified affected customers - if you were not notified, this vulnerability does not affect you. The flaw was actively exploited before and during patching, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-21, and carries a 1.6% EPSS probability of exploitation in the next 30 days. Do: No customer patch is required because Microsoft applied the fix service-side; review Microsoft's notification and follow its instructions to inspect your Power Pages sites for signs of exploitation (e.g., unexpected or unauthorized users, unusual privilege changes) and perform the recommended cleanup. Federal agencies must apply the vendor mitigations per CISA BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable. If you were not notified by Microsoft, the vulnerability does not affect you, though reviewing your site's registration settings is a prudent verification step. | 9.8 | 2% | KEV |
| largeunknown exact count; plausibly tens of thousands of Power Pages sites/tenants (affected subset undisclosed) | |
| CVE-2025-26465 | A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high. NVD description · AI analysis pending | 6.8 | 8% |
| — | ||
| CVE-2025-26466 | Unauthenticated Memory-Exhaustion DoS in OpenSSH CVE-2025-26466 is a denial-of-service flaw in the OpenSSH server: for every ping packet the SSH server receives, it allocates a corresponding pong packet in a memory buffer and adds it to a queue, and that memory is only freed once the server/client key exchange completes. A remote, unauthenticated attacker can hold a connection open and keep flooding it with ping packets faster than the key exchange finishes, driving uncontrolled memory growth until the SSH server becomes unavailable. The impact is availability-only, with no code execution or data exposure (CVSS 3.1 score 5.9, network vector with high attack complexity). Any system running an affected OpenSSH build is exposed, notably as packaged in Ubuntu Linux and Debian Linux, with internet-facing SSH endpoints the most attractive targets. No public PoC or confirmed in-the-wild exploitation is known and it is not in CISA KEV, but EPSS of ~40% (99th percentile) signals an elevated probability of exploitation within 30 days; the related headlines describing critical OpenSSH flaws also cover companion issues (including a man-in-the-middle bug) from the same disclosure. Do: Install the OpenSSH security updates released by Canonical and Debian in February 2025 (upstream fix in OpenSSH 9.9p2) and verify the running version with 'ssh -V' or your package manager. Until patched, reduce exposure by restricting SSH to trusted sources via firewall allowlists and rate-limiting unauthenticated connections (e.g., MaxStartups or fail2ban), and monitor sshd memory usage for abnormal growth. | 5.9 | 40% |
| mass~10-20 million internet-exposed SSH endpoints, with potentially millions of unpatched Ubuntu/Debian servers among them | ||
| CVE-2025-26763 | Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Object Injection.This issue affects Responsive Sl Deserialization of Untrusted Data vulnerability in MetaSlider Responsive Slider by MetaSlider ml-slider allows Object Injection.This issue affects Responsive Slider by MetaSlider: from n/a through <= 3.94.0. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-26776 | Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Chaty Pro: from n/a through 3.3.3. NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2025-26794 | Critical Unauthenticated SQL Injection in Exim 4.98 Exim, the widely deployed open-source mail transfer agent, is vulnerable to remote SQL injection (CVE-2025-26794, CWE-89) in version 4.98 before 4.98.1. The flaw is reachable over the network when a server uses SQLite for its hints database together with ETRN serialization, and per the CVSS vector requires no privileges or user interaction, with high impact on confidentiality, integrity, and availability. A successful attacker could manipulate the SQLite-backed data Exim relies on and disrupt mail handling, consistent with the critical 9.8 score. Only sites running Exim 4.98.x on affected configurations are exposed; sites with certain non-default rate-limit configurations need version 4.99.1 for the SQL injection to be fully resolved. No public proof-of-concept or CISA KEV entry exists yet, but EPSS assigns a 77.2% probability of exploitation within 30 days (100th percentile), so patching should be treated as urgent. Do: Upgrade Exim to 4.98.1 or later; sites using certain non-default rate-limit configurations should move to 4.99.1, since the SQL injection is only fully resolved there. Administrators should check whether their configuration uses SQLite for the hints database and ETRN serialization, and until patching can mitigate by disabling SQLite hints/ETRN serialization or restricting network access to the SMTP service. Given the 77.2% EPSS score, treat this as a priority patch even though exploitation has not yet been confirmed. | 9.8 | 77% |
| largelikely on the order of tens of thousands of mail servers (a configured subset of Exim's 1M+ installed base) |
Full article2,783 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananFeb 24, 2025
Welcome to your weekly roundup of cyber news, where every headline gives you a peek into the world of online battles. This week, we look at a huge crypto theft, reveal some sneaky AI scam tricks, and discuss big changes in data protection.
Let these stories spark your interest and help you understand the changing threats in our digital world.
⚡ Threat of the Week
Lazarus Group Linked to Record-Setting $1.5 Billion Crypto Theft — The North Korean Lazarus Group has been linked to a "sophisticated" attack that led to the theft of over $1.5 billion worth of cryptocurrency from one of Bybit's cold wallets, making it the largest ever single crypto heist in history. Bybit said it detected unauthorized activity within one of our Ethereum (ETH) Cold Wallets during a planned routine transfer process on February 21, 2025, at around 12:30 p.m. UTC. The incident makes it the biggest-ever cryptocurrency heist reported to date, dwarfing that of Ronin Network ($624 million), Poly Network ($611 million), and BNB Bridge ($586 million).
🔔 Top News
- OpenAI Bans ChatGPT Accounts for Malicious Activities — OpenAI has revealed that it banned several clusters of accounts that used its ChatGPT tool for a wide range of malicious purposes. This included a network likely originating from China that used its artificial intelligence (AI) models to develop a suspected surveillance tool that's designed to ingest and analyze posts and comments from platforms such as X, Facebook, YouTube, Instagram, Telegram, and Reddit. Other instances of ChatGPT abuse consisted of creating social media content and long-form articles critical of the U.S., generating comments for propagating romance-baiting scams on social media, and assisting with malware development.
- Apple Drops iCloud's Advanced Data Protection in the U.K. — Apple has stopped offering its Advanced Data Protection (ADP) feature for iCloud in the United Kingdom with immediate effect, rather than complying with government demands for backdoor access to encrypted user data. "We are gravely disappointed that the protections provided by ADP will not be available to our customers in the UK given the continuing rise of data breaches and other threats to customer privacy," the company said. The development comes shortly after reports emerged that the U.K. government had ordered Apple to build a backdoor that grants blanket access to any Apple user's iCloud content.
- Salt Typhoon Leverages Years-Old Cisco Flaw for Initial Access — The China-linked hacking group called Salt Typhoon leveraged a now-patched security flaw impacting Cisco devices (CVE-2018-0171) and obtaining legitimate victim login credentials as part of a targeted campaign aimed at major U.S. telecommunications companies. Besides relying extensively on living-off-the-land (LOTL) techniques to evade detection, the attacks have led to the deployment of a bespoke utility called JumbledPath that allows them to execute a packet capture on a remote Cisco device through an actor-defined jump-host. Cisco described the threat actor as highly sophisticated and well-funded, consistent with state-sponsored hacking activity.
- Russian Hackers Exploit Signal's Linking Feature — Multiple Russia-aligned threat actors have been observed targeting individuals of interest via malicious QR codes that exploit the privacy-focused messaging app Signal's "linked devices" feature to gain unauthorized access to their accounts and eavesdrop on the messages. The attacks have been attributed to two clusters tracked as UNC5792 and UNC4221. The development comes as similar attacks have also been recorded against WhatsApp.
- Winnti Stages RevivalStone Campaign Targeting Japan — Winnti, a subgroup with the APT41 Chinese threat activity cluster, targeted Japanese companies in the manufacturing, materials, and energy sectors in March 2024 that delivered a wide range of malware, including a rootkit that's capable of intercepting TCP/IP Network Interface, as well as creating covert channels with infected endpoints within the intranet. The activity has been codenamed RevivalStone.
️🔥 Trending CVEs
Your go-to software could be hiding dangerous security flaws—don’t wait until it’s too late! Update now and stay ahead of the threats before they catch you off guard.
This week’s list includes — CVE-2025-24989 (Microsoft Power Pages), CVE-2025-23209 (Craft CMS), CVE-2024-12284 (Citrix NetScaler Console and NetScaler Agent), CVE-2025-26465, CVE-2025-26466 (OpenSSH), CVE-2025-21589 (Juniper Networks Session Smart Router), CVE-2024-12510, CVE-2024-12511 (Xerox VersaLink C7025 Multifunction printer), CVE-2025-0366 (Jupiter X Core plugin), CVE-2024-50379, CVE-2024-56337, CVE-2024-52316, CVE-2024-50379, CVE-2024-56337 (Atlassian), CVE-2024-53900, CVE-2025-23061 (Mongoose library), CVE-2025-26776 (NotFound Chaty Pro plugin), CVE-2025-26763 (MetaSlider Responsive Slider by MetaSlider plugin), CVE-2024-54756 (ZDoom Team GZDoom), CVE-2024-57401 (Uniclare Student Portal), CVE-2025-20059 (Ping Identity PingAM Java Policy Agent), CVE-2025-0868 (DocsGPT), CVE-2025-1023, CVE-2025-1132, CVE-2025-1133, CVE-2025-1134, CVE-2025-1135 (ChurchCRM), CVE-2024-57045 (D-Link DIR-859 router), CVE-2024-57050 (TP-Link WR840N v6 router), CVE-2024-57049 (TP-Link Archer c20 router), CVE-2025-26794 (Exim), CVE-2024-50608, CVE-2024-50609 (Fluent Bit), CVE-2024-54961 (Nagios XI), CVE-2025-23115, and CVE-2025-23116 (Ubiquiti UniFi Protect Camera).
📰 Around the Cyber World
- U.S. Army Soldier Pleads Guilty to AT&T and Verizon Hacks — Cameron John Wagenius (aka Kiberphant0m), a 20-year-old U.S. Army soldier, who was arrested early last month over AT&T and Verizon hacking, has pleaded guilty to two counts of unlawful transfer of confidential phone records information in 2024. He faces up to 10 years of prison for each count. Wagenius is also believed to have collaborated with Connor Riley Moucka (aka Judische) and John Binns, both of whom have been accused of stealing data from and extorting dozens of companies by breaking into their Snowflake instances.
- Two Estonian Nationals Plead Guilty in $577M Cryptocurrency Fraud Scheme — Two Estonian nationals, Sergei Potapenko and Ivan Turõgin, both 40, have pleaded guilty for the operation of a massive, multi-faceted cryptocurrency Ponzi scheme that claimed hundreds of thousands of people from across the world, including in the U.S. They have also agreed to forfeit assets valued over $400 million obtained during the operation of the illicit scheme. The defendants "sold contracts to customers entitling them to a share of cryptocurrency mined by the defendants' purported cryptocurrency mining service, HashFlare," the Justice Department said. "Between 2015 and 2019, Hashflare’s sales totaled more than $577 million, but HashFlare did not possess the requisite computing capacity to perform the vast majority of the mining the defendants told HashFlare customers it performed." Potapenko and Turõgin each pleaded guilty to one count of conspiracy to commit wire fraud. If convicted, they each face a maximum penalty of 20 years in prison. The disclosure comes as Indian law enforcement authorities seized nearly $190 million in cryptocurrency tied to the BitConnect scam. BitConnect is estimated to have defrauded over 4,000 investors across 95 countries, amassing $2.4 billion before its collapse in 2018. Its founder Satish Kumbhani was charged by the U.S. in 2022, but he remained a fugitive until his whereabouts were traced to Ahmedabad.
- Thailand Rescues 7,000 People from Myanmar Call Centers — Thailand Prime Minister Paetongtarn Shinawatra said some 7,000 people have been rescued from illegal call center operations in Myanmar, and are waiting to be transferred to the country. In recent years, Myanmar, Cambodia, and Laos have become hotspots for illicit romance baiting scams, with most of them run by organized cybercrime syndicates and staffed by people who were illegally trafficked into the region under the promise of high-paying jobs. They are then tortured and enslaved into running scams such as romance fraud and fake investment schemes online. "We are facing an epidemic in the growth of financial fraud, leading to individuals, often vulnerable people, and companies being defrauded on a massive and global scale," INTERPOL noted last year. The United Nations estimated that scams targeting victims across East and Southeast Asia caused financial losses between $18 billion and $37 billion in 2023.
- Sanctioned Entities Fueled $16 billion in Crypto Activity — Sanctioned entities and jurisdictions were responsible for nearly $115.8 billion in cryptocurrency activity last year, accounting for about 39% of all illicit crypto transactions. "In a departure from prior years, sanctioned jurisdictions accounted for a record share of total sanctions-related activity compared to individual entities, commanding nearly 60% of value by the end of 2024," Chainalysis said. This is driven by the continued emergence of no-KYC exchanges despite enforcement actions, as well as the resurgence of Tornado Cash, which has been the target of sanctions and arrests. "The increase in Tornado Cash usage in 2024 was largely driven by stolen funds, which reached a three-year high, accounting for 24.4% of total inflows," the blockchain intelligence firm said. Another notable factor is the increasing use of digital currencies by Iranian services for sanctions-related crypto activity. Cryptocurrency outflows from Iran reached $4.18 billion in 2024, up about 70% year-over-year.
- U.S. Releases Russian Cybercriminal in Prison Swap — Alexander Vinnik, who pleaded guilty last year to money laundering charges in connection with operating the now-dismantled BTC-e cryptocurrency exchange, has been handed over by the U.S. government to Russia in exchange for Marc Fogel, a school teacher sentenced to 14 years in prison for drug trafficking charges. He was originally arrested in Greece in 2017. His sentencing was scheduled to take place in June 2025.
- Black Hat SEO Campaign Targets Indian Sites — Threat actors have infiltrated Indian government, educational, and financial services websites, using malicious JavaScript code that leverage search engine optimization (SEO) poisoning techniques to redirect users to sketchy websites promoting online betting and other investment-focused games that claim to offer referral bonus. "Targets of interest include websites with .gov.in , .ac.in TLDs and the usage of keyword stuffing mentioning well known financial brands in India," CloudSEK said. "Over 150 government portals, most belonging to state governments, have been affected at scale." It's currently not known how these websites are being compromised. A similar campaign targeting Malaysian government websites has also been reported in the past.
- Sky ECC Distributors Arrested in Spain, Netherlands — Four distributors of the encrypted communications service Sky ECC, which was used extensively by criminals, have been arrested in Spain and the Netherlands. The two suspects arrested in Spain are said to be the leading global distributors of the service, generating over €13.5 million ($14 million) in profits. In March 2021, Europol announced that it was able to crack open Sky ECC's encryption, thereby allowing law enforcement to monitor the communications of 70,000 users and expose the criminal activity occurring on the platform.In late January, the Dutch Police announced the arrest of two men from Amsterdam and Arnhem for allegedly selling Sky ECC phones in the country.
- Italian Spyware Maker Linked to Malicious WhatsApp Clones — An Italian spyware company named SIO, which offers solutions for monitoring suspect activities, gathering intelligence, or conducting covert operations, has been attributed as behind malicious Android apps that impersonate WhatsApp and other popular apps and are designed to steal private data from a target's device. The findings, reported by TechCrunch, demonstrate the various methods used to deploy such invasive software against individuals of interest. The spyware, codenamed Spyrtacus, can steal text messages, instant messaging chats, contacts, call logs, ambient audio, and images, among others. It's currently not known who was targeted with the spyware. The oldest artifact, per Lookout, dates back to 2019 and the most recent sample was discovered in mid-October 2024. Interestingly, Kaspersky revealed in May 2024 that it observed Spyrtacus being used to target individuals in Italy, stating it shared similarities with another stalkerware malware named HelloSpy. "The threat actor first started distributing the malicious APK via Google Play in 2018, but switched to malicious web pages forged to imitate legitimate resources relating to the most common Italian internet service providers in 2019," the company said. The development comes as iVerify said it discovered 11 new cases of Pegasus spyware infection in December 2024 that go beyond politicians and activists. "The new confirmed detections, involving known variants of Pegasus from 2021-2023, include attacks against users across government, finance, logistics, and real estate industries," iVerify said, adding in about half the cases, the victims did not receive any Threat Notifications from Apple.
- CryptoBytes Unleashes UxCryptor Malware — The financially motivated Russian threat actor known as CryptoBytes has been linked to a new ransomware called UxCryptor that uses leaked builders to create and distribute their malware. The group is active since at least 2023. "UxCryptor is part of a broader trend of ransomware families that use leaked builders, making it accessible to less technically skilled malware operators," the SonicWall Capture Labs threat research team said. "It is often delivered alongside other malware types, such as Remote Access Trojans (RATs) or information stealers, to maximize the impact of an attack. The malware is designed to encrypt files on the victim's system, demanding payment in cryptocurrency for decryption."
- Threat Actors Take a Mere 48 Minutes to Go From Initial Access to Lateral Movement — Cybersecurity company ReliaQuest, which recently responded to a manufacturing sector breach involving phishing and data exfiltration, said the attack achieved a breakout time of just 48 minutes, indicating that adversaries are moving faster than defenders can respond. The attack involved the use of email bombing techniques reminiscent of Black Basta ransomware, followed by sending a Microsoft Teams message to trick victims into granting them remote access via Quick Assist. "One user granted the threat actor control of their machine for over 10 minutes, giving the threat actor ample time to progress their attack," ReliaQuest said.
- Russia Plans New Measures to Tackle Cybercrime — The Russian government is said to have approved a series of measures aimed at combating cyber fraud. This includes tougher punishments for attackers, longer prison terms, and strengthening international cooperation by allowing the extradition of criminals hiding abroad to Russia for trial and punishment.
🎥 Expert Webinar
- Webinar 1: Build Resilient Identity: Learn to Reduce Security Debt Before It Costs You — Join our exclusive webinar with Karl Henrik Smith and Adam Boucher as they reveal the Secure Identity Assessment—a clear roadmap to close identity gaps, cut security debt, and future-proof your defenses in 2025. Learn practical steps to streamline workflows, mitigate risks, and optimize resource allocation, ensuring your organization stays one step ahead of cyber threats. Secure your spot now and transform your identity security strategy.
- Webinar 2: Transform Your Code Security with One Smart Engine — Join our exclusive webinar with Palo Alto Networks' Amir Kaushansky to explore ASPM—the unified, smarter approach to application security. Learn how merging code insights with runtime data bridges gaps in traditional AppSec, prioritizes risks, and shifts your strategy from reactive patching to proactive prevention. Reserve your seat today.
P.S. Know someone who could use these? Share it.
🔧 Cybersecurity Tools
- Ghidra 11.3 — It makes your cybersecurity work easier and faster. With built-in Python3 support and new tools to connect source code to binaries, it helps you find problems in software quickly. Built by experts at the NSA, this update works on Windows, macOS, and Linux, giving you a smart and simple way to tackle even the toughest challenges in reverse engineering.
- RansomWhen — It is an easy-to-use open-source tool designed to help you protect your data in the cloud. It works by scanning your CloudTrail logs to spot unusual activity that might signal a ransomware attack using AWS KMS. By identifying which identities have risky permissions, RansomWhen alerts you before an attacker can lock your S3 buckets and hold your data for ransom. This tool gives you a simple, proactive way to defend against sophisticated cyber threats.
🔒 Tip of the Week
Easy Steps to Supercharge Your Password Manager — In today’s digital world, using an advanced password manager isn’t just about storing passwords—it's about creating a secure digital fortress. First, enable two-factor authentication (2FA) for your password manager to ensure that even if someone gets hold of your master password, they’ll need an extra code to gain access. Use the built-in password generator to create long, unique passwords for every account, mixing letters, numbers, and symbols to make them nearly impossible to guess. Regularly run security audits within your manager to spot weak or repeated passwords, and take advantage of breach monitoring features that alert you if any of your credentials show up in data breaches. When you need to share a password, use the manager's secure sharing option to keep the data encrypted. Finally, ensure your password database is backed up in an encrypted format so you can safely restore your data if needed. These simple yet advanced steps turn your password manager into a powerful tool for keeping your online life secure.
Conclusion
We’ve seen a lot of action in the cyber world this week, with criminals facing charges and new scams coming to light. These stories remind us that keeping informed is key to online safety. Thanks for joining us, and we look forward to keeping you updated next week.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/02/thn-weekly-recap-from-15b-crypto-heist.html