⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-41334 | Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2 Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to not utilize certificate verification, allowing attackers to upload crafted APPE modules from non-official servers, leading to arbitrary code execution. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-41340 | An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9. An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload crafted APP Enforcement modules, leading to arbitrary code execution. NVD description · AI analysis pending | 8.4 | <1% |
| — | ||
| CVE-2024-48248 | Unauthenticated absolute path traversal file read in NAKIVO Backup & Replication NAKIVO Backup & Replication before version 11.0.0.88174 contains an absolute path traversal flaw (CWE-36) in the getImageByPath function exposed through the /c/router endpoint, which lets an attacker read arbitrary files from the server. Because the request requires no authentication and no user interaction (CVSS 3.1: 8.6, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N), any party that can reach the NAKIVO web interface can send crafted requests to retrieve files. The impact can extend beyond file disclosure: the PhysicalDiscovery function stores credentials in cleartext, so files harvested via the traversal can expose credentials that may enable remote code execution across the enterprise. All organizations running affected versions are at risk, particularly those with the NAKIVO web UI reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-19 amid reports of active exploitation, and EPSS puts its 30-day exploitation probability at roughly 94%. Do: Upgrade NAKIVO Backup & Replication to version 11.0.0.88174 or later; federal agencies must apply vendor mitigations or follow BOD 22-01 guidance (or discontinue use) within the required timeframe. Until patched, restrict internet exposure of the NAKIVO web interface and /c/router endpoint, review logs for suspicious getImageByPath requests, and rotate credentials configured for PhysicalDiscovery since cleartext credential harvesting may have enabled broader compromise. | 8.6 | 94% | KEV PoC |
| moderate≈ tens of thousands of deployments (vendor marketing cites ~30k+ customers; only the subset with the web UI exposed to the internet, likely thousands, are… | |
| CVE-2024-50302 | Kernel Memory Leak via Uninitialized HID Report Buffer in Linux Kernel CVE-2024-50302 is a use of uninitialized resource flaw (CWE-908) in the Linux kernel's HID (Human Interface Device) core, where the shared report buffer was not zero-initialized at allocation. An attacker can trigger it by getting the kernel to process a specially crafted HID report, causing uninitialized kernel memory to be exposed to the requesting driver. The impact is an information disclosure: a local attacker, or a malicious/malfunctioning HID device, could leak kernel memory contents, which could in turn aid further attacks. Because nearly all Linux-based systems compile in HID support, affected code is present in Linux distributions, Android, and Siemens industrial products (SIMATIC S7-1500 TM MFP firmware and SINEC OS). The vulnerability is being actively exploited: CISA added it to the KEV catalog on 2025-03-04, and it is among the actively exploited flaws addressed in Google's March 2025 Android security update. Do: Apply the fixes per vendor channels: install the March 2025 Android security update on Android devices (it is listed as actively exploited and is in CISA KEV, required under BOD 22-01 for federal agencies), and apply Debian kernel updates and Siemens (SIMATIC S7-1500 TM MFP firmware / SINEC OS) updates once issued. Operators should inventory systems running Linux kernels with the HID core (most systems) and prioritize patching, since a local attacker or malicious USB HID device can leak kernel memory; the fix zero-initializes the HID report buffer and is included in current stable kernel branches. | 5.5 | <1% | KEV |
| massBillions of devices ship affected Linux kernel HID code (Linux runs on ~3+ billion Android devices plus millions of servers, desktops, and industrial systems),… | |
| CVE-2024-51138 | Vigor165/166 4.2.7 and earlier; Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier; Vigor2133/2762/2832 3.9.9 and earlier; Vigor2135/2765/2766 4.4.5. and earlier; Vigor2865/2866/2927 4.4.5.3 and earlier; Vigor2962 4.3.2.8 and earlier; Vigor3912 4.3.6.1 and earlier; Vigor3910 4.4.3.1 and earlier a stack-based buffer overflow vulnerability has been identified in the URL parsing functionality of the TR069 STUN server. This flaw occurs due to insufficient bounds checking on the amount of URL parameters, allowing an attacker to exploit the overflow by sending a maliciously crafted request. Consequently, a remote attacker can execute arbitrary code with elevated privileges. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2024-51139 | Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/ Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 4.2.7 and earlier and Vigor2135/2765/2766 4.4.5.1 and earlier and Vigor2865/2866/2927 4.4.5.3 and earlier and Vigor2962/3910 4.3.2.8/4.4.3.1 and earlier and Vigor3912 4.3.6.1 and earlier allows a remote attacker to execute arbitrary code via the CGI parser's handling of the "Content-Length" header of HTTP POST requests. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-56325 | Authentication Bypass in Apache Pinot Controller API CVE-2024-56325 is a critical authentication bypass (CWE-288) in Apache Pinot: when the request URL path is altered so it no longer matches the pattern the authentication check expects (per the disclosure, a path that does not contain '/' and contains characters such as a trailing dot), the endpoint processes the request without credentials. As demonstrated, an unauthenticated attacker can send a crafted POST to the /users endpoint on the controller port (9000 in the example) and successfully create a new user with the ADMIN role. The attacker thereby gains full control of the Pinot deployment, because that newly created administrative account can be used for further authenticated actions against the cluster. Any organization running Apache Pinot with its built-in authentication enabled is affected; the source data does not specify affected version ranges, so administrators should verify their version against the Apache security advisory. The flaw is not yet in CISA's KEV and no public proof-of-concept is known, but EPSS assigns an unusually high 80.2% probability of exploitation within 30 days (100th percentile), making rapid patching strongly advised. Do: Upgrade Apache Pinot to the fixed release identified in the official Apache security advisory as soon as practical; as an interim mitigation, restrict network access to the Pinot controller/API port (e.g., 9000) to trusted clients or place it behind an authenticating reverse proxy. Additionally, review existing user accounts for unexpectedly created ADMIN users and inspect access logs for POST requests to /users with manipulated paths (e.g., trailing semicolons or dots) indicating bypass attempts. | 9.8 | 80% |
| moderateroughly 1,000–10,000 internet-exposed Apache Pinot instances (order-of-magnitude estimate) | ||
| CVE-2025-0364 | BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker can create an administrative user through the default exposed SaaS registration mechanism. Once an administrator, the attacker can upload and execute arbitrary PHP code using the "Cloud Storage Addin," leading to unauthenticated code execution. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2025-1080 | LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice a link in a browser using that scheme could be constructed with an embedded inner URL that when passed to LibreOffice could call internal macros with arbitrary arguments. This issue affects LibreOffice: from 24.8 before < 24.8.5, from 25.2 before < 25.2.1. NVD description · AI analysis pending | 7.2 | <1% |
| — | ||
| CVE-2025-1316 | Unauthenticated OS Command Injection RCE in Edimax IC-7100 IP Camera CVE-2025-1316 is an OS command injection flaw (CWE-78) in the Edimax IC-7100 IP camera that fails to properly neutralize requests it receives. Because the request handling is reachable over the network without authentication or user interaction (per the CVSS 4.0 vector), an unauthenticated attacker can send specially crafted requests to the device. Successful exploitation yields full remote code execution on the camera, with high impact on confidentiality, integrity, and availability of the device itself. Only deployments using the Edimax IC-7100 camera and its firmware are affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-19, and public reporting indicates Mirai-based botnets have been exploiting it since roughly a year before its disclosure, making it effectively a zero-day used to recruit cameras into botnets. Do: Per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of the IC-7100 if mitigations are unavailable; check whether Edimax has released updated firmware and install it. In the meantime, reduce exposure by removing any port-forwarding or direct internet access to affected cameras, restricting management interfaces to trusted networks, and monitoring for Mirai-like scanning or traffic. Treat exploitation as likely given the high EPSS (74.5% in 30 days) and in-the-wild botnet use. | 9.3 | 74% | KEV |
| moderateapproximately 1,000-10,000 internet-exposed devices (estimated) | |
| CVE-2025-1723 | Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug. NVD description · AI analysis pending | 8.1 | 1% |
| — | ||
| CVE-2025-20206 | A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the Secure Firewall Posture Engine, formerly HostScan, is installed on Cisco Secure Client. This vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to a specific Cisco Secure Client process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker must have valid user credentials on the Windows system. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-22224 | TOCTOU Out-of-Bounds Write in VMware ESXi and Workstation Enables Guest-to-Host Escape VMware ESXi and Workstation contain a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) that can lead to an out-of-bounds write in the virtual machine's VMX process. To trigger it, a malicious actor needs local administrative privileges inside a guest virtual machine, where the race condition between the host's check and use of a resource can be exploited. Successful exploitation executes code as the VMX process on the host - effectively a guest-to-host escape, since the VMX process runs with host-level privileges on ESXi - reflected in the CVSS 3.1 score of 8.2 with changed scope. Affected products per the available data are VMware ESXi and Workstation, plus VMware Cloud Foundation and VMware Telco Cloud Infrastructure/Platform, which bundle the affected components; specific affected or fixed version ranges are not stated in the provided data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-04, confirming active in-the-wild exploitation (ransomware use is listed as unknown), though no public proof-of-concept code is known. Do: Upgrade ESXi, Workstation, VMware Cloud Foundation, and Telco Cloud deployments to the patched releases identified in Broadcom's security advisory (fixed version numbers are not present in the provided data, so confirm them directly in the advisory); because the flaw is on CISA KEV, BOD 22-01-bound organizations must apply vendor mitigations or patches by the KEV deadline or discontinue use of the product. As an interim measure, restrict local administrative privileges inside guest VMs to trusted users only, since guest admin access is the prerequisite for exploitation. Prioritize hosts that are internet-reachable or multi-tenant, where untrusted users are more likely to hold guest admin rights. | 8.2 | 2% | KEV |
| masson the order of 100,000+ internet-exposed ESXi hosts, with the total ESXi/Workstation install base plausibly in the hundreds of thousands to millions | |
| CVE-2025-22225 | Sandbox Escape via Arbitrary Kernel Write in VMware ESXi (Actively Exploited) VMware ESXi contains an arbitrary write vulnerability (CWE-787/CWE-123) in which an actor with privileges inside the VMX process can trigger a write into the kernel, escaping the ESXi sandbox. The flaw is exploited locally (AV:L), requires high privileges within the VMX process (PR:H), and involves no user interaction, so it is typically reached by chaining another ESXi/VMX bug or after an attacker already has a foothold on the host. Successful exploitation yields a sandbox escape with high confidentiality, integrity, and availability impact, effectively giving the attacker broad control at the hypervisor level. Any organization running VMware ESXi — including the ESXi components within VMware Cloud Foundation and VMware Telco Cloud Infrastructure/Platform — is potentially affected. The flaw is being exploited in the wild and was added to CISA's KEV on 2025-03-04 with known ransomware use; media reports attribute exploitation to China-linked actors, and Broadcom has released urgent patches. Do: Apply the ESXi updates released by Broadcom/VMware for CVE-2025-22225 (covering ESXi components inside VMware Cloud Foundation and Telco Cloud deployments), prioritizing internet-facing hosts, and follow CISA KEV required actions — federal agencies must remediate per BOD 22-01 deadlines. Since exploitation is confirmed in the wild with known ransomware use, check ESXi hosts for signs of compromise and restrict/remove management interfaces from the internet until patched. No public PoC is known, so rely on vendor guidance for mitigations if immediate patching is not possible. | 8.2 | <1% | KEV ransomware |
| mass≈100,000–1,000,000 ESXi hosts deployed worldwide, with tens of thousands of ESXi instances directly exposed to the internet | |
| CVE-2025-22226 | Out-of-Bounds Read in VMware ESXi, Workstation, and Fusion Leaks Host Memory via HGFS CVE-2025-22226 is an information disclosure vulnerability in the HGFS (Host Guest File System) component of VMware ESXi, Workstation, and Fusion, caused by an out-of-bounds read (CWE-125) in the vmx process. It is triggered when a malicious actor who already holds administrative privileges inside a guest virtual machine interacts with HGFS, causing the vulnerable code to read beyond a buffer boundary. Successful exploitation allows the attacker to leak memory from the host-side vmx process, potentially exposing sensitive host or cross-VM data (confidentiality-only impact; CVSS 6.0 with scope change). Any organization running ESXi standalone or as part of VMware Cloud Foundation or the Telco Cloud products, as well as users of Workstation or Fusion desktop hypervisors, is potentially affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-03-04, confirming exploitation in the wild; no public PoC is known and ransomware use is listed as unknown (EPSS ~1.7%, 76th percentile). Do: Apply the patched releases published in Broadcom's VMware advisory (released alongside CISA's KEV entry on 2025-03-04) for ESXi, Workstation, Fusion, and any Cloud Foundation/Telco Cloud deployments; federal agencies must remediate per BOD 22-01 timelines. Where shared folders/HGFS are not required, disable them, and restrict administrative privileges inside guest VMs since guest admin access is the prerequisite for exploitation. Verify current build numbers against the advisory, as the source data does not specify fixed versions. | 6.0 | 2% | KEV |
| mass≈100,000+ internet-exposed ESXi/vSphere hosts, plus a very large Workstation and Fusion desktop install base (order of magnitude: mass) | |
| CVE-2025-24494 | Path traversal may allow remote code execution using privileged account (requires device admin account, cannot be performed by a regular user). Path traversal may allow remote code execution using privileged account (requires device admin account, cannot be performed by a regular user). In combination with the 'Upload' functionality this could be used to execute an arbitrary script or possibly an uploaded binary. Remediation in Version 6.7.0, release date: 20-Oct-24. NVD description · AI analysis pending | 8.6 | 1% | — | — | ||
| CVE-2025-25015 | Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP requests. In Kibana versions >= 8.15.0 and < 8.17.1, this is exploitable by users with the Viewer role. In Kibana versions 8.17.1 and 8.17.2 , this is only exploitable by users that have roles that contain all the following privileges: fleet-all, integrations-all, actions:execute-advanced-connectors NVD description · AI analysis pending | 9.9 | 1% |
| — | ||
| CVE-2025-27218 | Insecure Deserialization RCE in Sitecore Experience Manager (XM) and XP 10.4 Sitecore Experience Manager (XM) and Experience Platform (XP) version 10.4, prior to the KB1002844 hotfix, are vulnerable to remote code execution through insecure deserialization, classified under CWE-94 (improper control of code generation). The flaw is reachable over the network with no privileges or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N), and successful exploitation gives an attacker code execution on the affected instance; the published base score is 5.3 (medium). Any organization running XM/XP 10.4 without the KB1002844 fix is affected, and related coverage highlights elevated RCE risk in enterprise deployments as well as a related hard-coded 'b' password issue in Sitecore XP. No exploitation has been documented so far: the flaw is not in CISA KEV and no public proof-of-concept is known. However, EPSS assigns a 65% probability of exploitation within the next 30 days (99th percentile), so defenders should treat near-term exploitation attempts as likely. Do: Apply the Sitecore hotfix KB1002844 to all XM/XP 10.4 instances, or upgrade to a release that includes it, and inventory internet-facing Sitecore servers to confirm none remain unpatched. Until patched, restrict network exposure of Sitecore servers and monitor for exploitation attempts given the 65% EPSS. Also review related coverage of the hard-coded 'b' password issue in Sitecore XP and apply any associated vendor guidance. | 5.3 | 65% |
| largeon the order of tens of thousands of internet-exposed Sitecore systems (10.4 pre-hotfix subset) | ||
| CVE-2025-27423 | Shell Command Injection in Vim tar.vim Plugin via Crafted Tar Archives CVE-2025-27423 is a command injection flaw (CWE-77) in Vim's bundled tar.vim plugin, introduced in Vim 9.1.0858, where content taken literally from a tar archive is passed to the ':read' ex command without sanitization when the plugin appends below the cursor position. A user triggers it by opening or viewing a specially crafted (compressed or uncompressed) tar archive in an affected Vim build; whether crafted text is executed as shell commands depends on the configured 'shell' option ($SHELL). A successful attacker gains arbitrary shell command execution with the privileges of the user running Vim, yielding high confidentiality and integrity impact with no availability impact (CVSS 3.1: 7.1). Anyone running Vim 9.1.0858 or later before patch 9.1.1164 is affected, including Vim as shipped or consumed with NetApp HCI Compute Node per the listed product CPE. As of now there is no known public proof-of-concept and the issue is not in CISA KEV, but the elevated EPSS score of 22.5% (98th percentile) suggests a meaningful near-term exploitation likelihood, and a fix is available in Vim patch v9.1.1164. Do: Upgrade Vim to patch level 9.1.1164 or later, which fixes this issue. Until then, do not open untrusted or unfamiliar tar archives with the tar.vim plugin (e.g., via 'vim archive.tar'), and review the 'shell' option in Vim configurations since exploitation depends on which shell is used. NetApp HCI Compute Node customers should track and apply NetApp's published updates for this CVE. | 7.1 | 22% |
| masson the order of hundreds of thousands to millions of Vim installations plausibly affected (Vim ships by default on virtually all Linux/macOS/Unix systems and… | ||
| CVE-2025-27622 +1 in the same advisory: …27623 | Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowi Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read permission to view encrypted values of secrets. NVD description · AI analysis pending | 4.3 | <1% |
| — |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | crrsg.site | n in 2021. There are at least 2,727 registered operators on crrsg.site. "The infrastructure of this operation includes a centraliz |
Full article2,965 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMar 10, 2025Cybersecurity / Newsletter
Cyber threats today don't just evolve—they mutate rapidly, testing the resilience of everything from global financial systems to critical infrastructure. As cybersecurity confronts new battlegrounds—ranging from nation-state espionage and ransomware to manipulated AI chatbots—the landscape becomes increasingly complex, prompting vital questions: How secure are our cloud environments? Can our IoT devices be weaponized unnoticed? What happens when cybercriminals leverage traditional mail for digital ransom?
This week's events reveal a sobering reality: state-sponsored groups are infiltrating IT supply chains, new ransomware connections are emerging, and attackers are creatively targeting industries previously untouched. Moreover, global law enforcement actions highlight both progress and persistent challenges in countering cybercrime networks.
Dive into this edition to understand the deeper context behind these developments and stay informed about threats that continue reshaping the cybersecurity world.
⚡ Threat of the Week
U.S. Charges 12 Chinese Nationals for Nation-State Hacking — The U.S. Department of Justice (DoJ) announced charges against 12 Chinese nationals for their alleged participation in a wide-ranging scheme designed to steal data and suppress free speech and dissent across the world. The defendants include two officers of the People's Republic of China's (PRC) Ministry of Public Security (MPS), eight employees of the company i-Soon, and two members of APT27. "These malicious cyber actors, acting as freelancers or as employees of i-Soon, conducted computer intrusions at the direction of the PRC's MPS and Ministry of State Security (MSS) and on their own initiative," the DoJ said. "The MPS and MSS paid handsomely for stolen data."
🔔 Top News
- U.S. Secret Service Dismantles Garantex — A coalition of international law enforcement agencies has seized the online infrastructure associated with the cryptocurrency exchange Garantex for facilitating money laundering by transnational criminal organizations. The exchange is estimated to have processed at least $96 billion in cryptocurrency transactions, with crypto transactions worth more than $60 billion processed since it was sanctioned in 2022. In addition, two individuals Aleksej Besciokov and Aleksandr Mira Serda have been charged in connection with operating an unlicensed money-transmitting business.
- Silk Typhoon Goes After IT Supply Chains — In what appears to be a shift in tactics, Salt Typhoon, the China-linked threat actor behind the zero-day exploitation of security flaws in Microsoft Exchange servers in January 2021, has begun to target the information technology (IT) supply chain, specifically remote management tools and cloud applications, as a means to obtain initial access to corporate networks. Upon gaining successful access, the threat actors have been found using stolen keys and credentials to further burrow into the compromised network and exfiltrate data of interest.
- Dark Caracal Linked to Use of Poco RAT — The threat actor called Dark Caracal has been linked to a phishing campaign that distributed a remote access trojan called Poco RAT in attacks targeting Spanish-speaking targets in Latin America in 2024. An analysis of Poco RAT artifacts indicates the intrusions are mainly targeting enterprises in Venezuela, Chile, the Dominican Republic, Colombia, and Ecuador.
- Links Between Black Basta and CACTUS Ransomware Examined — Threat actors deploying the Black Basta and CACTUS ransomware families have been found to rely on the same BackConnect (BC) module for maintaining persistent control over compromised systems, a sign that affiliates previously associated with Black Basta may have transitioned to CACTUS. The BackConnect module has source code references to QakBot, indicating likely shared authorship. The component is distributed via sophisticated social engineering tactics to trick targets into installing the Quick Assist remote desktop software.
- U.A.E. Entities Targeted by UNK_CraftyCamel — A previously undocumented threat activity cluster dubbed UNK_CraftyCamel has targeted "fewer than five" aviation and satellite communications entities in the United Arab Emirates (U.A.E.) to deliver a previously undocumented Golang backdoor dubbed Sosano. The attacks stand out because they took advantage of a compromised email account belonging to the Indian electronics company INDIC Electronics to send phishing messages. It's suspected that the campaign is the work of an Iranian-aligned hacking group.
Trending CVEs
The software you rely on every day can have hidden risks that hackers actively target. Staying safe means keeping up-to-date with the latest security patches before vulnerabilities become costly breaches.
Here’s this week’s critical list of software vulnerabilities you should urgently patch or review to protect your systems — CVE-2025-25015 (Elastic Kibana), CVE-2025-22224, CVE-2025-22225, CVE-2025-22226 (VMware), CVE-2024-50302 (Google Android), CVE-2025-0364 (BigAntSoft BigAnt), CVE-2024-48248 (NAKIVO Backup & Replication), CVE-2025-1723 (Zoho ADSelfService Plus), CVE-2025-27423 (Vim), CVE-2025-24494 (Keysight Ixia Vision), CVE-2025-1080 (LibreOffice), CVE-2025-27218 (Sitecore), CVE-2025-20206 (Cisco Secure Client for Windows), CVE-2024-56325 (Apache Pinot), CVE-2025-1316 (Edimax IC-7100), CVE-2025-27622, CVE-2025-27623 (Jenkins), and CVE-2024-41334 through CVE-2024-41340, CVE-2024-51138, CVE-2024-51139 (Draytek routers).
📰 Around the Cyber World
- Apple Reportedly Pushes Back Against Backdoor Access — Apple appears to be pushing back against a secret order issued by the U.K. to give the government access to encrypted iCloud data. According to a report from the Financial Times, the company has filed an appeal with the Investigatory Powers Tribunal, an independent judicial body that examines complaints against the U.K. security services, in hopes of overturning the order. The tribunal is expected to probe whether "the U.K.'s notice to Apple was lawful and, if not, could order it to be quashed." Apple recently stopped offering Advanced Data Protection in the U.K. in response to the secret order.
- IoT Devices Targeted by New Eleven11bot Botnet — A new botnet malware dubbed Eleven11bot is estimated to have infected thousands of IoT devices, primarily security cameras and network video recorders (NVRs), to conduct volumetric DDoS attacks. A majority of the infections are in the United States, the United Kingdom, Mexico, Canada, and Australia, per The Shadowserver Foundation. Threat intelligence firm GreyNoise said it has observed 1,042 IP addresses tied to the botnet's operation in the past month, most of which are based in Iran. Eleven11bot is assessed to be a variant of the infamous Mirai malware, which had its source code leaked in 2016. That said, there have been conflicting reports on the number of devices comprising Eleven11bot. Nokia said the botnet is made of roughly 30,000 devices, the Shadowserver Foundation said the size is well over 86,000. However, GreyNoise estimated the true number was likely fewer than 5,000.
- U.S. Treasury Sanctions Iranian National for Running Nemesis Market — The U.S. Treasury Department on Tuesday announced sanctions against an Iranian national named Behrouz Parsarad for running an online darknet marketplace called Nemesis Market that was used for trading drugs and cybercrime services. The online bazaar was shut down in March 2024 as a result of a law enforcement operation conducted by Germany, the U.S., and Lithuania. "As the administrator of the Nemesis darknet marketplace, Parsarad sought to build — and continues to try to re-establish — a safe haven to facilitate the production, sale, and shipment of illegal narcotics like fentanyl and other synthetic opioids," the Treasury Department said.
- Moonstone Sleet Deploys Qilin Ransomware — Microsoft revealed that it observed the North Korean threat actor tracked as Moonstone Sleet deploying Qilin ransomware at a limited number of organizations in late February 2025. "Qilin is a ransomware as a service (RaaS) payload used by multiple threat actors, both state-sponsored and cybercriminal groups," it said. "Moonstone Sleet has previously exclusively deployed their own custom ransomware in their attacks, and this represents the first instance they are deploying ransomware developed by a RaaS operator."
- Kaspersky Flags Thousands of Malicious Installations of Banking Trojans — Russian cybersecurity company Kaspersky said it prevented a total of 33.3 million attacks involving malware, adware, or unwanted mobile software in 2024. Adware accounted for 35% of total detections, with 1.13 million malicious and potentially unwanted installation packages detected. Nearly 69,000 of those installations were associated with banking trojans. The company said it also discovered threat actors using novel social engineering tactics to distribute the Mamont banking trojan targeting Android devices in Russia. "The attackers lured users with a variety of discounted products," it said. "The victim had to send a message to place an order. Some time later, the user received a phishing link to download malware disguised as a shipment tracking app."
- PrintSteal Campaigns Engages in Large-Scale KYC Document Generation Fraud in India — Details have emerged about a large-scale, organized criminal operation that involves the mass production and distribution of fake Indian KYC (Know Your Customer) documents, an activity that has been codenamed PrintSteal by CloudSEK. One such platform, named crrsg.site, is estimated to have fueled the creation of more than 167,391 fake documents since its creation in 2021. There are at least 2,727 registered operators on crrsg.site. "The infrastructure of this operation includes a centralized web platform, access to illicit APIs that provide data like Aadhaar, PAN, and vehicle information, a streamlined payment system, and encrypted communication channels (such as Telegram)," CloudSEK researcher Abhishek Mathew said. "The operation relies heavily on a network of affiliates, primarily local businesses like mobile shops and internet cafes, which serve as points of contact for customers seeking fake documents." Further investigation has revealed that an individual named Manish Kumar is a key figure behind crrsg.site. To date, no less than 1,800 domains have been identified as part of this operation, with over 600 domains currently active.
- Malicious Use of Cobalt Strike Down 80% Since 2023 — In April 2023, Microsoft and Health Information Sharing and Analysis Center (Health-ISAC) teamed up with Fortra, the company behind Cobalt Strike, to combat the abuse of the post-exploitation toolkit by bad actors to facilitate malicious activities. Since then, the number of unauthorized copies of Cobalt Strike observed in the wild has decreased by 80%, Fortra said. The company said it also seized and sinkholed over 200 malicious domains, effectively severing the connections. "Additionally, the average dwell time — the period between initial detection and takedown — has been reduced to less than one week in the United States and less than two weeks worldwide," it added. In July 2024, a coordinated law enforcement operation codenamed MORPHEUS dismantled 593 servers that were used by cybercriminal groups and were part of an attack infrastructure associated with unlicensed versions of Cobalt Strike.
- CrowdStrike Reports $21 Million Loss from July 2024 Outage — Cybersecurity firm CrowdStrike reported another $21 million in costs related to the July 19, 2024, outage in the fourth quarter, bringing the annual total to $60 million. In a related development, security firm SEC Consult detailed a now-patched vulnerability in CrowdStrike Falcon that allowed attackers to pause the sensor. "The vulnerability allowed an attacker with 'NT AUTHORITY\SYSTEM' permissions to suspend the CS Falcon Sensor processes," the Austrian company said. "A subset of malicious applications that are blocked or deleted when the CS Falcon Sensor processes are active could be executed or retained on the disk after the CS Falcon Sensor processes were suspended. This leads to a partial bypass of the CS Falcon Sensor detection mechanisms."
- FBI Warns of Fake Ransomware Notes Sent via Snail Mail — The U.S. government is warning that scammers are masquerading as the BianLian (aka Bitter Scorpius) ransomware and data extortion group to target corporate executives by sending extortion letters that threaten to release sensitive information on the e-crime gang's data leak site unless payment ranging between $250,000 and $500,000 is received within 10 days from receipt of the letter. The letters are believed to be an attempt to scam organizations into paying a ransom. Cybersecurity firm Arctic Wolf said the letters were being sent to executives primarily within the U.S. healthcare industry, but noted that the physical ransom letters are drastically different in word usage and tone from those of the actual BianLian group. GuidePoint Security and Palo Alto Networks Unit 42 also pointed out that the activity is likely the work of an imposter.
- Moscow-Based News Network Poisons AI Chatbot Results — A Moscow-based disinformation network named Pravda is publishing false claims and pro-Kremlin propaganda to deliberately distort responses from artificial intelligence (AI) models that rely on up-to-date information. The network, which uses search engine optimization strategies to boost the visibility of its content, is said to have published 3.6 million misleading articles in 2024 alone. "By flooding search results and web crawlers with pro-Kremlin falsehoods, the network is distorting how large language models process and present news and information," NewsGuard said, adding "the leading AI chatbots repeated false narratives laundered by the Pravda network 33 percent of the time."
- DoJ Charges 2 Venezuelans for ATM Jackpotting Scheme — The U.S. Justice Department said two Venezuelan nationals David Jose Gomez Cegarra, 24, and Jesus Segundo Hernandez-Gil, 19, were arrested and charged recently over their role in an ATM jackpotting scheme in the U.S. states of New York, Massachusetts, and Illinois in October and November 2024. The charges carry a maximum penalty of ten years in prison. "ATM Jackpotting involves removing an ATM’s cover and infecting the ATMs hard drive with malware or removing the hard drive and replacing it with an infected hard drive, which allows the operator to assume control of the ATM and cause it to dispense currency," the agency said.
- Researchers Flag Flaw in China's Great Firewall — Cybersecurity researchers have detailed a now-fixed buffer over-read vulnerability dubbed Wallbleed in the DNS injection subsystem of the Great Firewall of China that could result in information disclosure, causing certain nation-wide censorship middleboxes to reveal up to 125 bytes of their memory when censoring a crafted DNS query. It was patched in March 2024. "Until March 2024, certain DNS injection devices had a parsing bug that would, under certain conditions, cause them to include up to 125 bytes of their own memory in the forged DNS responses they sent," a group of academics said. The GFW's DNS injection subsystem relies on what's called DNS spoofing and tampering to inject fake DNS responses containing random IP addresses when a request matches a banned keyword or a blocked domain.
- Nine Threat Groups Active in OT Operations in 2024 — Industrial cybersecurity company Dragos said nine out of the 23 threat groups it tracks as targeting industrial organizations were active in 2024. Two of them – Bauxite (aka Cyber Av3ngers) and Graphite (aka APT28) – have been identified as two new threat groups setting their sights on operational technology (OT) networks. "A striking trend in 2024 was the continued lowering of the barrier to entry for adversaries targeting OT/ICS," Dragos said. "Adversaries that would have once been unaware of or ignored OT/ICS entirely now view it as an effective attack vector to achieve disruption and attention." Furthermore, the number of ransomware attacks targeting OT systems increased by 87% in 2024, and the number of groups going after such targets spiked by 60%. The disclosure comes as CrowdStrike revealed that China-nexus activity increased by 150% across all sectors in 2024, with a "staggering 200-300% surge" in key targeted industries including financial services, media, manufacturing, and industrials/engineering. The security vendor, which is tracking 257 named adversaries and over 140 emerging activity clusters, said adversaries are increasingly targeting cloud-based SaaS applications for data theft, lateral movement, extortion, and third-party targeting. Some of the new notable clusters include Envoy Panda (aka BackdoorDiplomacy), Liminal Panda, Locksmith Panda, Operator Panda (aka Salt Typhoon), Vanguard Panda (aka Volt Typhoon), and Vault Panda (aka Earth Berberoka).
- Google Details AMD Zen Vulnerability — Google researchers have disclosed the details of a recently patched AMD processor vulnerability dubbed EntrySign (CVE-2024-56161, CVSS score: 7.2) that could potentially permit an attacker to load a malicious CPU microcode under specific conditions. In a nutshell, the vulnerability enables arbitrary microcode patches to be installed on all Zen 1 through Zen 4 CPUs. "Luckily, the security impact was limited by the fact that attackers must first obtain host ring 0 access in order to attempt to install a microcode patch and that these patches do not persist through a power cycle," Google said. "Confidential computing using SEV-SNP, DRTM using SKINIT, and supply chain modification are some of the situations where the threat model permits an attacker to subvert microcode patches."
🎥 Expert Webinar
Traditional AppSec is Broken—Watch This to See How ASPM Can Fix It
Traditional AppSec tools often struggle with today's complex software environments, creating security blind spots. Application Security Posture Management (ASPM) promises to bridge these gaps by combining code-level insights and runtime context. But is ASPM the future or a passing trend?
Join Amir Kaushansky from Palo Alto Networks to quickly grasp ASPM’s real-world benefits—such as proactive risk management and reduced patching workloads. Get actionable insights and evaluate whether adopting ASPM can strengthen your organization's security posture.
Secure your spot now to stay ahead of evolving threats.
P.S. Know someone who could use these? Share it.
🔧 Cybersecurity Tools
- Rayhunter — It is a free and open-source tool developed by EFF to identify devices used for cellular surveillance, commonly called IMSI catchers. Designed specifically for use with the Orbic RC400L mobile hotspot, Rayhunter helps users detect if their cellular communications are being monitored. While built mainly for research and testing purposes—rather than high-risk situations—the tool offers a user-friendly web interface, allowing easy monitoring, capture of cellular signals, and basic analysis of potential spying attempts. Although Rayhunter might function on similar Qualcomm-based Linux or Android devices, compatibility is currently only confirmed for this specific Orbic model.
- GCPGoat: A Damn Vulnerable GCP Infrastructure — GCPGoat is a purposely vulnerable Google Cloud environment designed to help users safely learn cloud security. It mirrors real-world mistakes in cloud setups, covering OWASP’s top web app risks and common misconfigurations. Users can practice penetration testing, audit infrastructure code, improve secure coding, and enhance threat detection directly in their own GCP accounts.
🔒 Tip of the Week
Get Defense Against Advanced 'Living off the Land' Threats — Hackers often misuse built-in tools like PowerShell (Windows) or common Linux utilities to quietly break into systems—this is called a "Living off the Land" (LotL) attack. A simple, effective defense is Binary Allowlisting via Checksums, which ensures only verified tools can run.
For Linux users, create a trusted baseline by running this one-time command on a clean system:
sudo find /usr/bin -type f -exec sha256sum {} \; > /root/trusted.sha256
Then, schedule hourly checks using cron (edit with sudo crontab -e) to verify these binaries:
0 * * * * sha256sum -c /root/trusted.sha256 2>&1 | grep -v ": OK$" && echo "Checksum mismatch detected!" | mail -s "Security Alert" [email protected]
For Windows users, install the free, user-friendly security tool Wazuh, and enable its File Integrity Monitoring feature. It automatically alerts you if critical binaries like those in C:\Windows\System32 are unexpectedly changed or replaced.
This quick, practical approach stops attackers from sneaking through unnoticed, greatly strengthening your overall security posture.
Conclusion
Cybersecurity isn't just about technology—it's about understanding patterns, staying alert, and connecting the dots. As you finish this newsletter, ask yourself: which dot might become tomorrow's headline, and are you ready for it? Stay informed, stay curious, and keep connecting.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/03/thn-weekly-recap-new-attacks-old-tricks.html