Security Affairs newsletter Round 526 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-4428 | Authenticated Code Injection RCE in Ivanti Endpoint Manager Mobile (EPMM) API CVE-2025-4428 is a code injection flaw (CWE-94) in the API component of Ivanti Endpoint Manager Mobile (EPMM) that lets an authenticated, low-privileged remote attacker execute arbitrary code by sending crafted API requests. Successful exploitation yields code execution on the MDM server itself (CVSS 8.8, High), which typically holds device inventory and administrative control over an organization's enrolled mobile fleet. Any organization running EPMM 12.5.0.0 or earlier is in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-05-19, EPSS puts the 30-day exploitation probability at 86% (100th percentile), and public reporting ties limited attacks to the China-linked actor UNC5221, who reportedly began exploiting it alongside the companion API authentication bypass CVE-2025-4427 shortly after disclosure. CISA has also warned that threat actors exploiting these EPMM flaws deploy two malware strains; ransomware involvement has not been confirmed. Do: Upgrade every EPMM instance running 12.5.0.0 or earlier to the patched release per Ivanti's security advisory, prioritizing internet-facing servers, and note that federal agencies must satisfy the BOD 22-01 required action (patch, apply vendor mitigations, or discontinue use of the product). If patching is delayed, restrict internet exposure of the API and review EPMM logs and the advisory's indicators of compromise, since attackers have chained this flaw with the CVE-2025-4427 authentication bypass and deployed malware. Treat any unpatched, exposed EPMM instance as actively targeted until it is remediated. | 8.8 | 87% | KEV |
| largetens of thousands of enterprise deployments (order of 10k-100k EPMM servers; many are internet-exposed) | |
| CVE-2025-4598 | A vulnerability was found in systemd-coredump. A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type of permission, which allows the process to run with the file owner's permissions, regardless of the user executing the binary. This allows the process to access more restricted data than unprivileged users or processes would be able to. An attacker can leverage this flaw by forcing a SUID process to crash and force the Linux kernel to recycle the process PID before systemd-coredump can analyze the /proc/pid/auxv file. If the attacker wins the race condition, they gain access to the original's SUID process coredump file. They can read sensitive content loaded into memory by the original binary, affecting data confidentiality. NVD description · AI analysis pending | 4.7 | <1% | PoC ×2 |
| — | |
| CVE-2025-5054 | Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. Race condition in Canonical apport up to and including 2.32.0 allows a local attacker to leak sensitive information via PID-reuse by leveraging namespaces. When handling a crash, the function `_check_global_pid_and_forward`, which detects if the crashing process resided in a container, was being called before `consistency_checks`, which attempts to detect if the crashing process had been replaced. Because of this, if a process crashed and was quickly replaced with a containerized one, apport could be made to forward the core dump to the container, potentially leaking sensitive information. `consistency_checks` is now being called before `_check_global_pid_and_forward`. Additionally, given that the PID-reuse race condition cannot be reliably detected from userspace alone, crashes are only forwarded to containers if the kernel provided a pidfd, or if the crashing process was unprivileged (i.e., if dump mode == 1). NVD description · AI analysis pending | 4.7 | <1% | PoC |
| — |
Full article434 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
DragonForce actors target SimpleHelp vulnerabilities to attack MSP, customers
The Epic Rise and Fall of a Dark-Web Psychedelics Kingpin
Threat Spotlight: Hijacked Routers and Fake Searches Fueling Payroll Heist
Dark Partners cybercrime gang fuels large-scale crypto heists
ConnectWise Confirms ScreenConnect Cyberattack, Says Systems Now Secure: Exclusive
Steal, deal and repeat: How cybercriminals trade and exploit your data
Websites selling hacking tools to cybercriminals seized
Malware
60 Malicious npm Packages Leak Network and Host Data in Active Malware Campaign
Inside a VenomRAT Malware Campaign
Fake Google Meet Page Tricks Users into Running PowerShell Malware
PyBitmessage Backdoor Malware Installed with CoinMiner
PumaBot: Novel Botnet Targeting IoT Surveillance Devices
GreyNoise Discovers Stealthy Backdoor Campaign Affecting Thousands of ASUS Routers
Hacking
Sugar-Coated Poison: Benign Generation Unlocks LLM Jailbreaking
The Sharp Taste of Mimo’lette: Analyzing Mimo’s Latest Campaign targeting Craft CMS
From Infection to Access: A 24-Hour Timeline of a Modern Stealer Campaign
Intelligence and Information Warfare
Mysterious hacking group Careto was run by the Spanish government, sources say
Russian hacker group Killnet returns with new identity
New Russia-affiliated actor Void Blizzard targets critical sectors for espionage
Russia-Aligned TAG-110 Targets Tajikistan with Macro-Enabled Word Documents
AIVD and MIVD recognize new Russian cyber actor
Chinese spies blamed for attempted hack on Czech government network
Mark Your Calendar: APT41 Innovative Tactics
Earth Lamia Develops Custom Arsenal to Target Multiple Industries
Lazarus Group Targets Crypto-Wallets and Financial Data while employing new Tradecrafts
Cybersecurity
The App Store prevented more than $9 billion in fraudulent transactions over the last five years
Anthropic’s new AI model turns to blackmail when engineers try to take it offline
Victoria’s Secret Website Taken Offline After Cyberattack
Massive data breach exposes 184 million passwords for Google, Microsoft, Facebook, and more
Treasury Takes Action Against Major Cyber Scam Facilitator
Integrity Reports, First Quarter 2025
Meta’s Adversarial Threat Report, First Quarter 2025
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/178468/breaking-news/security-affairs-newsletter-round-526-by-pierluigi-paganini-international-edition.html