Chinese-speaking hackers targeting US municipalities with Cityworks bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-0994 | Authenticated Deserialization RCE in Trimble Cityworks Trimble Cityworks, a GIS-based asset management platform used largely by local governments and utilities, contains a deserialization vulnerability (CWE-502). An authenticated user triggers the flaw by submitting maliciously crafted serialized input to the Cityworks web application. Successful exploitation yields remote code execution on the underlying Microsoft IIS web server hosting the product. Any organization running Cityworks on IIS is affected, especially where the server is internet-facing. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-07, confirming exploitation in the wild; no public PoC is known, CVSS scoring is pending, and EPSS assigns roughly a 31% probability of exploitation within 30 days. Do: Patch or apply Trimble's mitigations to all Cityworks/IIS servers per vendor instructions, as required by the CISA KEV listing, and discontinue use if mitigations are unavailable. Because exploitation requires authentication, review and rotate Cityworks accounts and credentials, and inspect IIS/application logs on exposed servers for signs of compromise (ransomware use is unconfirmed but possible). | 8.6 | 31% | KEV |
| nicheroughly hundreds to low thousands of deployments, concentrated at local governments, utilities and public agencies (estimate; no public install counts… |
Full article380 words · extracted from therecord.media · click to collapse
A vulnerability in a critical tool used by local governments across the U.S. is being exploited by Chinese-speaking hackers, according to incident responders. Since January, cybersecurity experts at Cisco Talos have seen Chinese hackers exploiting CVE-2025-0994 — a bug impacting Trimble Cityworks. The tool is used by local governments to manage critical infrastructure assets from one platform and organize inspections, work orders, permits, operations and more. Both Trimble and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned in February that CVE-2025-0994 was being exploited, but Cisco Talos has confirmed that the hackers “conducted reconnaissance and rapidly deployed a variety of web shells and custom-made malware to maintain long-term access.” “Upon gaining access, [the hackers] expressed a clear interest in pivoting to systems related to utilities management,” Cisco Talos explained in a blog on Thursday. The malware and other tools used during the attacks “contained messaging written in the Chinese language” and one of them was built “using a malware-builder called ‘MaLoader’ that is also written in Simplified Chinese.” While some of the tools can be configured to use limited English, most require some level of Chinese proficiency. Based on the tools used, the tactics and the victims, Cisco Talos said they assessed with “high confidence” that the people behind the attacks were Chinese-speaking threat actors. Once access to a government system was achieved, the hackers looked for directories and files of interest before preparing them for exfiltration. Federal agencies were ordered to patch CVE-2025-0994 by February 28. The asset management system is used by many local and federal government agencies to manage infrastructure assets for airports, utilities, municipalities and counties. In a letter to customers earlier this year, the company behind the software said notice of the vulnerability followed “investigations of reports of unauthorized attempts to gain access to specific customers' Cityworks deployments." CISA said Trimble reported the vulnerability to them and Symantec’s Threat Hunter team contributed to the advisory they released about the bug.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/chinese-speaking-hackers-target-municipalities-cityworks