ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 537 by Pierluigi Paganini

criticalRansomware exploited in the wildimportance 60CVE-2025-25256

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-25256
Unauthenticated OS command injection in Fortinet FortiSIEM (CVE-2025-25256)

CVE-2025-25256 is a critical (CVSS 9.8) OS command injection flaw (CWE-78) in Fortinet's FortiSIEM SIEM platform. An unauthenticated attacker can trigger it by sending specially crafted CLI requests over the network, which the appliance fails to properly neutralize before execution. Successful exploitation allows the attacker to execute unauthorized code or commands on the affected system without credentials or user interaction, effectively giving control of the appliance. Essentially every currently supported and many older FortiSIEM releases are affected, spanning versions 4.7 through 7.3.1. Fortinet has confirmed exploit code is being used in the wild, and the flaw carries a high 60.3% EPSS probability of exploitation within 30 days, though it is not yet in CISA's KEV catalog.

Do: Upgrade FortiSIEM to a fixed release per Fortinet's security advisory, ensuring the deployed version falls outside all affected ranges listed above; given in-the-wild exploitation and a ~60% EPSS probability, prioritize externally reachable instances. Until patched, restrict network access to the appliance's CLI/management-facing services and review logs for unexpected commands or connections that may indicate compromise.

9.860%
  • Fortinet FortiSIEM 7.3.0-7.3.1, 7.2.0-7.2.5, 7.1.0-7.1.7, 7.0.0-7.0.3, 6.7.0-6.7.9; 6.6, 6.5, 6.4, 6.3, 6.2, 6.1, 5.4, 5.3, 5.2, 5.1, 5.0, 4.10, 4.9, 4.7 (all versions)
largetens of thousands of deployed FortiSIEM instances worldwide (order-of-magnitude estimate)
Full article461 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

Google says hackers stole its customers’ data by breaching its Salesforce database

ShinyHunters sent Google an extortion demand; Shiny comments on current activities  

Two Defendants Plead Guilty To Fraud Scheme Involving Data Stolen From Hospital Patients  

Unmasking Interlock Group’s Evolving Malware Arsenal

Rapid7 Access Brokers Report: New Research Reveals Depth of Compromise in Access Broker Deals, with 71% Offering Privileged Access  

When Hackers Call: Social Engineering, Abusing Brave Support, and EncryptHub’s Expanding Arsenal

Treasury Sanctions Cryptocurrency Exchange and Network Enabling Sanctions Evasion and Cyber Criminals  

Malware

‘Blue Locker’ Analysis: Ransomware Targeting Oil & Gas Sector in Pakistan 

Persistent Risk: XZ Utils Backdoor Still Lurking in Docker Images  

SCENE 1: SoupDealer – Technical Analysis of a Stealth Java Loader Used in Phishing Campaigns Targeting Türkiye

Crypto24 Ransomware Group Blends Legitimate Tools with Custom Malware for Stealth Attacks 

Threat Bulletin: Fire in the Woods – A New Variant of FireWood  

Hacking

BadCam: Now Weaponizing Linux Webcams  

Postman, engineer, cleaner: Are hackers sneaking into your office?  

You Snooze You Lose: RPC-Racer Winning RPC Endpoints Against Services  

Chrome Sandbox Escape Earns Researcher $250,000

Case: Citrix vulnerability (Update 11-08-2025)  

Fortinet Warns About FortiSIEM Vulnerability (CVE-2025-25256) With In-the-Wild Exploit Code

Uncovering memory corruption in NVIDIA Triton (as a new hire) 

Don’t Phish-let Me Down: FIDO Authentication Downgrade 

Attacking GenAI applications and LLMs – Sometimes all it takes is to ask nicely!

The Root(ing) Of All Evil: Security Holes That Could Compromise Your Mobile Device  

Intelligence and Information Warfare

ScarCruft’s New Language: Whispering in PubNub, Crafting Backdoor in Rust, Striking with Ransomware

From Drone Strike to File Recovery: Outsmarting a Nation State

New Ransomware Charon Uses Earth Baxia APT Techniques to Target Enterprises

Curly COMrades: A New Threat Actor Targeting Geopolitical Hotbeds     

Norway spy chief blames Russian hackers for dam sabotage in April 

House of Commons hit by cyberattack from ‘threat actor’: internal email  

Vulnerabilities exposed: Israeli company reveals how users can hack ChatGPT accounts remotely  

UAT-7237 targets Taiwanese web hosting infrastructure  

Cybersecurity

The August 2025 Security Update Review     

SAP Security Notes: August 2025 Patch Day  

AI agents are being drafted into the cyber defense forces of corporations 

Manpower Says Data Breach Stemming From Ransomware Attack Impacts 140,000  

How we’re using AI in new ways to fight invalid traffic  

Cisco Warns of CVSS 10.0 FMC RADIUS Flaw Allowing Remote Code Execution

The First Federal Cybersecurity Disaster of Trump 2.0 Has Arrived  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181226/breaking-news/security-affairs-newsletter-round-537-by-pierluigi-paganini-international-edition.html