ZeroHour
Recorded Futurepublished ()ingested Levi Gundert

Smarter Cybersecurity with IPv6: How Drip Architecture Defeats Spray-and

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-34362
Unauthenticated SQL Injection in Progress MOVEit Transfer

CVE-2023-34362 is an unauthenticated SQL injection flaw (CWE-89) in Progress MOVEit Transfer that allows an attacker with no credentials to gain unauthorized access to the product's database. It is triggered remotely via crafted input submitted to the MOVEit Transfer web application, with the impact varying by the backend database engine in use (MySQL, Microsoft SQL Server, or Azure SQL). A successful attacker can infer the structure and contents of the database and, depending on the engine, execute SQL statements that alter or delete database elements, exposing data handled by the file-transfer service. Any organization running an internet-reachable MOVEit Transfer instance is affected; public internet-exposure scans around disclosure identified on the order of a few thousand servers, each typically serving enterprise or government user bases. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2023-06-02 with known ransomware use and an EPSS exploitation probability of 99.9% (100th percentile), while no public PoC is known.

Do: Apply the vendor's updates immediately, per Progress instructions and CISA's required action. Until patched, restrict internet exposure of MOVEit Transfer and check the backend database for unexpected structure or content changes and deletions. Because in-the-wild exploitation and ransomware use are confirmed, treat any unpatched, internet-facing instance as potentially compromised and review stored transfer data and access logs for anomalies.

9.8100% KEV ransomware PoC
  • Progress MOVEit Transfer
large≈2,000-3,000 internet-exposed MOVEit Transfer servers (public internet-exposure scans)
CVE-2023-4966
Info-Disclosure Buffer Overflow (CitrixBleed) in Citrix NetScaler ADC/Gateway

Citrix NetScaler ADC and NetScaler Gateway appliances contain a buffer overflow (CWE-119) that leaks sensitive information from device memory when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. A remote attacker who can reach such a configuration can trigger the overflow and read memory contents, harvesting sensitive data such as session tokens (a technique that enables session hijacking which can bypass multi-factor authentication). Any organization running an affected NetScaler ADC or Gateway appliance in these configurations is exposed, with appliances deployed as VPN or access gateways being the primary concern. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2023-10-18 with known ransomware use and a 100% EPSS exploitation probability, although no public proof-of-concept is known at this time. Because tokens stolen from memory can remain valid even after patching, responders must terminate all active and persistent sessions as part of remediation.

Do: Upgrade affected appliances to the patched builds cited in Citrix's advisory, then immediately kill all active and persistent ICA/AAA sessions per the vendor instructions, since patching alone does not invalidate session tokens attackers may have already stolen. If patching is not immediately possible, discontinue use of the affected Gateway/AAA configurations as CISA directs. Given known ransomware abuse, also hunt for signs of exploitation such as logins from unexpected sources, anomalous session reuse, or suspicious mailbox changes, and reset credentials for potentially exposed accounts.

7.5100% KEV ransomware
  • Citrix NetScaler ADC and NetScaler Gateway
masshundreds of thousands of internet-exposed NetScaler ADC/Gateway appliances (public internet scan counts), plus an unknown number of VPN-only or internal…
CVE-2024-3400
Unauthenticated Root Command Injection in Palo Alto Networks PAN-OS GlobalProtect

Palo Alto Networks PAN-OS contains a command injection flaw (CWE-77, with improper input validation per CWE-20) in its GlobalProtect feature, allowing an unauthenticated attacker to execute arbitrary operating-system commands with root privileges on the affected firewall. The flaw is triggered through the GlobalProtect interface, which in most deployments is reachable from untrusted networks, so no valid user credentials or prior access are required. Successful exploitation yields full root control of the firewall, the most powerful position in a network perimeter, enabling traffic interception, configuration tampering, and use as a foothold for further compromise. All PAN-OS firewalls running affected releases with the GlobalProtect feature are exposed; CISA added the issue to the KEV catalog on 2024-04-12 with ransomware use noted, and EPSS puts the 30-day exploitation probability at 100% (100th percentile). No public proof-of-concept is recorded in the source data, but confirmed in-the-wild exploitation makes patching urgent.

Do: Apply the PAN-OS patches released in Palo Alto Networks' bulletin according to its published patch schedule, prioritizing internet-facing firewalls. Until patched, enable the vendor's Threat Prevention signatures as required by CISA KEV, restrict exposure of the GlobalProtect interface to trusted sources where possible, and review logs and device configuration for signs of compromise given confirmed exploitation with known ransomware use.

10.0100% KEV ransomware PoC ×2
  • Palo Alto Networks PAN-OS
large≈10,000–100,000 internet-exposed PAN-OS firewalls with GlobalProtect enabled
CVE-2025-31324
Unauthenticated File Upload RCE in SAP NetWeaver Visual Composer

CVE-2025-31324 is a critical (CVSS 9.8) unrestricted file upload flaw (CWE-434) in the Visual Composer Metadata Uploader component of SAP NetWeaver, which lacks proper authorization. An unauthenticated attacker can send crafted upload requests over the network to the Metadata Uploader endpoint and plant malicious executable binaries, such as webshells, on the host. Executing the uploaded files yields remote code execution with full impact on confidentiality, integrity, and availability, enabling system compromise, lateral movement, and ransomware deployment. Any organization running the affected SAP NetWeaver component is at risk, with the greatest exposure for instances reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2025-04-29, a public PoC exists, and researchers and media report active attacks, including by Chinese-linked actors deploying Golang-based implants on Linux systems and known ransomware use, often chained with CVE-2025-42999.

Do: Apply SAP's patch for CVE-2025-31324 (released in the April 2025 security updates) and follow the vendor mitigation instructions per CISA KEV/BOD 22-01 requirements. As interim mitigation, restrict or disable the Visual Composer Metadata Uploader endpoint and ensure it is not reachable from the internet; also patch the related CVE-2025-42999 since the flaws are being chained. Check affected hosts for uploaded webshells, Golang-based implants, and signs of ransomware activity.

9.8100% KEV ransomware PoC
  • sap netweaver
largetens of thousands of enterprise deployments worldwide, with several thousand instances directly internet-exposed
Full article1,116 words · extracted from recordedfuture.com · click to collapse

AI Hackathons and the Future of Security Architecture

Last week, a few Futurists met up to work out the practical realities of AI-enabled Red Teaming (among other topics). In addition to two days of phenomenal vibe coding in Cursor, the final presentations were light on hyperbole and heavy on capabilities and remarkable outcomes, created in a day or less. Two years ago, when LLMs made their mainstream debut, I was dubious, but the hackathon confirmed recent observations (last three months) that AI is accelerating security workflows (like everything else) at warp speed. Change, soon driven primarily through various agentic flavors, is happening at a pace that is difficult to comprehend.

The flight home was spent considering how to get ahead of the adversarial/defensive agent wars that will soon play out across the internet. Given the vast amount of uncertainty in agentic implementations and scale, there are no perfect solutions, but there are architecture scenarios worth considering NOW. Principal among them is IPv6. Long a headache for architects and engineers (nibble boundaries anyone?), IPv6 may now represent real business value through security, in exchange for the considerable effort. AI is a natural forcing function here. Given the time required to implement IPv6 and resolve the inevitable challenges along the way, enterprises should begin the work, aided by AI, of course.

Why IPv6 Belongs in Your Five-Year Security Roadmap

What if eliminating opportunistic attacks required nothing more than updating your network architecture? The vast IPv6 address space transforms internet-wide scanning from trivial to computationally impossible, removing one critical leg from the attacker's operational stool.

Modern adversaries operate on economics: maximum victims, minimum effort. IPv6's 340 undecillion addresses create an insurmountable barrier for brute-force discovery and enumeration, forcing attackers to abandon cheap, scalable tactics. Organizations dismissing this advantage miss a critical opportunity to reduce their attack surface while security teams fight multi-front battles against AI-powered threats.

The Opportunistic Threat Reality

Recorded Future tracks thousands of automated exploitation campaigns daily, following a predictable pattern. Vulnerability disclosure triggers mass scanning within hours, leading to indiscriminate compromise of exposed systems.

Recent campaigns demonstrate the scale:

The volume metrics paint a sobering picture. IoT devices are attacked within 5 minutes of connecting to the internet. Internet “background noise” includes 4.2 billion simultaneous events (five years ago). 152 billion scan probes are sent across the IPv4 internet daily, including 36,000 automated scans per second.

Claude Sonnet 4 render of IPv6 vs. IPv4 scanning.

[Dynamic Visualization: Global Scanning Heat Map - AI render showing IPv4 saturation]

The Three-Legged Stool of Modern Remote Attacks

Threat actors balance operations on three critical foundations. Remove any leg, and its operational efficiency collapses.

Leg Alpha: Opportunistic Scanning Automated discovery exploits internet-exposed vulnerabilities at scale. IPv6 effectively saws off this leg by making comprehensive scanning computationally infeasible.

Leg Beta: Targeted Reconnaissance Domain enumeration, supply chain analysis, and social engineering remain unaffected. Adversaries leverage Certificate Transparency logs, passive DNS, and BGP announcements to build targeted hit lists.

Leg Charlie: Identity & Insider Access Compromised credentials and third party breaches bypass network controls entirely. Address space complexity offers zero defense against authenticated attacks (and social engineering, which is a fourth leg).

Reality Check: IPv6 Security Benefits

The security community debates IPv6's defensive value, but data supports nuanced conclusions. Brute-force scanning genuinely becomes harder—even the fastest academic scanners map only millions of hosts from 2^128 possibilities.

However, targeted discovery remains trivial. Adversaries enumerate targets through domain names, WHOIS records, and Certificate Transparency logs. Dual-stack deployments particularly undermine benefits, as attackers simply pivot from IPv4 reconnaissance.

Key defensive advantages include:

  • Address space enables thousands of deception nodes
  • Granular segmentation without NAT complexity
  • Protocol modernization enforces TLS 1.3 and QUIC
  • Moving-target defense becomes economically viable

Practical Implementation Architecture

Organizations should maximize IPv6's defensive advantages while acknowledging its limitations. The evidence-based approach spans three phases over 24 months.

Phase Alpha: Foundation (Months 0-6) Deploy dual-stack architecture with IPv6-preferred public services. Implement strict ICMPv6 filtering, unpredictable address allocation, and comprehensive connection monitoring. Every IPv6 probe becomes a high-value threat signal.

Phase Beta: Segmentation (Months 6-12) Allocate /64 subnets per application tier with host-based microsegmentation. Deploy source address validation at edge routers and create honeypot networks throughout unused address space.

Phase Gamma: Advanced Defense (Months 12-24) Enable rapid address rotation for moving-target defense. Deploy IPv6-only management interfaces behind Single Packet Authorization, integrate telemetry into threat-hunting platforms, and participate in collaborative intelligence sharing.

Claude Sonnet 4 generated IPv6 implementation timeline.

[Dynamic Visualization: IPv6 Defense Architecture - AI render]

Measuring Risk Reduction

IPv6 deployment will deliver a significant drop in scanning, and additional canary hosts/services will help create metrics that translate to increased operational efficiency. Security teams spend less time chasing automated noise, focusing instead on sophisticated threats that matter.

Future-Proofing Against AI-Powered Attacks

The next five years demand strategies that counter automated exploitation at machine speed. IPv6 enables several critical defensive patterns that become essential as AI agents weaponize vulnerabilities within minutes.

Autonomous Defense Pipelines: Integrate CVE feeds with LLM agents that generate patches faster than attackers can weaponize exploits. Deploy eBPF-based sidecars ingesting real-time signatures, pushing rules globally via service mesh.

Zero-Exposure Architecture: Hide services behind cryptographic authentication using Single Packet Authorization or modern ZTNA. Removes targets from the attack graph entirely—zero exposed surface equals zero remote exploitation (in theory).

Continuous Surface Mutation: Leverage abundant IPv6 space for constant re-addressing and port shuffling. Combined with binary diversification and container re-imaging, force adversaries to continuously rediscover targets.

Strategic Recommendations

Security leaders planning 2025-2030 roadmaps should consider adopting this blueprint:

  1. Deploy IPv6-only for public services where feasible
  2. Publish no AAAA DNS records for management interfaces
  3. Automate defensive kill-chains matching attacker speed
  4. Implement moving-target techniques using address abundance
  5. Shift to memory-safe languages, eliminating bug classes
  6. Treat every /64 scan as suspicious intelligence
  7. Share sanitized samples with collaborative defense communities

The Bottom Line

IPv6 won't stop nation-states or targeted ransomware groups, but it eliminates the background radiation consuming security resources. Opportunistic campaigns that compromise thousands of organizations simply cannot operate efficiently in IPv6's vast address space.

Smart organizations recognize that removing entire attack classes beats chasing perfect security. IPv6 takes mass scanning off the table, forcing adversaries to reveal themselves through targeted activity. In an era where defensive teams need every advantage, that's one less leg supporting the attacker's operational model—and one more reason IPv6 belongs in your security roadmap.

Claude Sonnet 4 generated IPv6 cube.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/ipv6-drip-drowns-spray-and-pray