Week in review: Exploited 7-Zip 0-day flaw, crypto-stealing malware found on App Store, Google Play
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-40891 | Post-Authentication OS Command Injection in Zyxel DSL CPE Devices Multiple Zyxel DSL CPE devices contain a post-authentication OS command injection flaw (CWE-78) in their management commands. An attacker with valid credentials who can reach the device's management interface over Telnet sends crafted input that is executed as operating-system commands on the device. Successful exploitation yields arbitrary command execution on the CPE, potentially letting an attacker tamper with the gateway or pivot into the subscriber's local network. Organizations and ISPs running affected Zyxel DSL CPEs are exposed if authenticated Telnet management is reachable, and many impacted models may be end-of-life or end-of-service with limited fix options. The flaw was added to CISA's KEV catalog on 2025-02-11, confirming exploitation in the wild, and EPSS gives it a 21.5% chance of exploitation in the next 30 days (97th percentile). Do: Inventory your fleet for the affected Zyxel DSL CPE models and check Zyxel's advisory for patched firmware, noting that many impacted models are EoL/EoS and may never receive fixes. Until patched, restrict or disable Telnet-based management — allow it only from trusted management networks — and review logs for unexpected authenticated Telnet sessions or configuration changes. Federal agencies must remediate per KEV timelines; if no mitigation is available on EoL/EoS hardware, discontinue use or plan replacement as CISA recommends. | 8.8 | 22% | KEV |
| mass≈1M+ deployed units worldwide, though the directly exploitable subset (Telnet-reachable with valid credentials) is unknown | |
| CVE-2024-57968 +1 in the same advisory: …25181 | Unrestricted File Upload in Advantive VeraCore upload.aspx Advantive VeraCore, a warehouse management and order fulfillment platform, contains an unrestricted file upload flaw (CWE-434) in its upload.aspx endpoint that fails to properly restrict what files can be uploaded and where they are stored. A remote attacker with no credentials can abuse the endpoint to write files into unintended, attacker-influenced folders on the server. By placing crafted files (for example, script files) into web-reachable directories, an attacker can typically escalate an arbitrary upload into webshell deployment and code execution on the hosting server. Any organization running VeraCore, especially instances with the upload endpoint reachable from the internet, is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-10, indicating active exploitation, and EPSS assigns a 32.3% probability of exploitation within 30 days (98th percentile). Do: Apply the mitigations required under CISA KEV/BOD 22-01, following Advantive's instructions, and contact the vendor for the fixed release since no patched version is specified in the available data. In the interim, restrict network access to upload.aspx (allow only trusted users or VPN/internal traffic), enforce file-type and destination validation at a WAF/reverse proxy where possible, and hunt for unexpected or recently modified files in VeraCore's web directories plus suspicious entries in web access logs to detect webshells or uploaded payloads. | 8.8 group max | 32% | KEV PoC ×2 |
| nicheroughly hundreds to low thousands of deployments (fulfillment/3PL and e-commerce operations running VeraCore) | |
| CVE-2025-0411 | Mark-of-the-Web Bypass in 7-Zip Enables Code Execution via Crafted Archives CVE-2025-0411 is a protection-mechanism bypass in 7-Zip's handling of archived files: when extracting a crafted archive that carries the Mark-of-the-Web, 7-Zip fails to propagate the MotW flag to the extracted files. Exploitation requires user interaction, as the target must visit a malicious page or open a malicious archive. Because the extracted files lose their MotW designation, Windows skips its usual security prompts on attacker-supplied executables or scripts, allowing arbitrary code execution in the context of the current user. Anyone running affected 7-Zip installations is exposed, including NetApp Active IQ Unified Manager deployments that incorporate 7-Zip. The flaw was exploited as a zero-day — Russian cybercrime groups and SmokeLoader campaigns, notably targeting Ukrainian organizations, abused it — and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-06. Do: Upgrade 7-Zip to the latest patched release per vendor guidance, and for NetApp Active IQ Unified Manager apply the update specified in NetApp's security advisory; the CISA KEV required action is to apply vendor mitigations or discontinue use. Until patched, treat archives from untrusted sources with caution and verify extracted executables manually, since MotW prompts will not fire on extracted files. Hunt for signs of SmokeLoader-style post-extraction execution in user workstations. | 7.0 | 67% | KEV |
| masstens of millions of users (7-Zip is among the most widely deployed Windows archive utilities, plus NetApp-bundled deployments) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | asp.net | ers. Attackers compromise IIS servers by leveraging exposed ASP.NET machine keys A ViewState code injection attack spotted by M |
Full article970 words · extracted from helpnetsecurity.com · click to collapse

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:
Russian cybercrooks exploiting 7-Zip zero-day vulnerability (CVE-2025-0411)
CVE-2025-0411, a Mark-of-the-Web bypass vulnerability in the open-source archiver tool 7-Zip that was fixed in November 2024, has been exploited in zero-day attacks to deliver malware to Ukrainian entities, Trend Micro researchers have revealed.
Crypto-stealing iOS, Android malware found on App Store, Google Play
A number of iOS and Android apps on Apple’s and Google’s official app stores contain a software development kit (SDK) that allows them to exfiltrate cryptowallets’ seed recovery phrases, Kaspersky researchers have found.
The overlooked risks of poor data hygiene in AI-driven organizations
In this Help Net Security interview, Oliver Friedrichs, CEO at Pangea, discusses why strong data hygiene is more important than ever as companies integrate AI into their operations.
DeepSeek’s popularity exploited to push malicious packages via PyPI
Two malicious packages leveraging the DeepSeek name have been published to the Python Package Index (PyPI) package repository, and in the 30 minutes or so they were up, they have been downloaded 36 times.
Ransomware payments plummet as more victims refuse to pay
Chainalysis’ latest report on how the ransomware landscape changed from 2023 to 2024 shows a promising trend: An increasing number of victims refuses to pay the ransom.
What you can do to prevent workforce fraud
In this Help Net Security interview, Benjamin Racenberg, Senior Intelligence Services Manager at Nisos, discusses the threat of workforce fraud, particularly DPRK-affiliated IT workers infiltrating remote roles.
Suspected NATO, UN, US Army hacker arrested in Spain
The Spanish National Police has arrested a hacker suspected of having breached national and international agencies (including the United Nation’s International Civil Aviation Organization and NATO), Spanish universities and companies, and released stolen data on the dark web.
The hidden dangers of a toxic cybersecurity workplace
In this Help Net Security interview, Rob Lee, Chief of Research and Head of Faculty at SANS Institute, discusses what a toxic environment looks like and how professionals can recognize red flags such as high turnover, burnout, and a pervasive fear of mistakes.
Cybercrime gang exploited VeraCore zero-day vulnerabilities for years (CVE-2025-25181, CVE-2024-57968)
XE Group, a cybercriminal outfit that has been active for over a decade, has been quietly exploiting zero-day vulnerabilities (CVE-2025-25181, CVE-2024-57968) in VeraCore software, a popular solution for warehouse management and order fulfillment.
BadDNS: Open-source tool checks for subdomain takeovers
BadDNS is an open-source Python DNS auditing tool designed to detect domain and subdomain takeovers of all types.
Swap EOL Zyxel routers, upgrade Netgear ones!
There will be no patches for EOL Zyxel routers under attack via CVE-2024-40891, the company has confirmed. Meanwhile, Netgear has issued patches for critical flaws affecting its routers and wireless access points.
OpenNHP: Cryptography-driven zero trust protocol
OpenNHP is the open-source implementation of NHP (Network-resource Hiding Protocol), a cryptography-based zero trust protocol for safeguarding servers and data.
Casio UK site compromised, equipped with web skimmer
Japanese electronics maker Casio has had its UK website injected with a web skimmer that collected buyers’ personal and payment card information, Jscrambler has discovered.
Self-sovereign identity could transform fraud prevention, but…
The way we manage digital identity is fundamentally broken. The root of the problem lies in traditional, centralized identity models, where a single organization holds and controls a user’s credentials, creating an attractive target for attackers.
Attackers compromise IIS servers by leveraging exposed ASP.NET machine keys
A ViewState code injection attack spotted by Microsoft threat researchers in December 2024 could be easily replicated by other attackers, the company warned.
The API security crisis and why businesses are at risk
In this Help Net Security video, Ivan Novikov, CEO of Wallarm, discusses the 2025 API ThreatStats Report, highlighting how APIs have become the primary attack surface over the past year, mainly driven by the rise of AI-related risks.
More destructive cyberattacks target financial institutions
Financial institutions will continue to be the ultimate targets for criminals and threat actors, as a successful attack offers a significant payoff, according to Contrast Security.
Aim for crypto-agility, prepare for the long haul
While organizations have long experimented with various facets of digital transformation, the journey toward crypto-agility is one of the most significant technological transitions of our time.
Only 3% of organizations have a dedicated budget for SaaS security
Mid-market organizations are grappling with managing the large volume of SaaS applications, both sanctioned and unsanctioned, with actual numbers often exceeding expectations, according to Cloud Security Alliance.
Man charged with stealing $65 million by exploting DeFI protocols vulnerabilities
A Canadian man has been indicted in federal court in New York for exploiting vulnerabilities in two decentralized finance (DeFi) protocols to fraudulently obtain about $65 million from the protocols’ investors.
8 steps to secure GenAI integration in financial services
GenAI offers financial services institutions enormous opportunities, particularly in unstructured dataset analysis and management, but may also increase security risks, according to FS-ISAC.
Cybersecurity jobs available right now: February 4, 2025
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.
How to customize Safari for private browsing on iOS
Apple’s Safari browser includes several features aimed at enhancing privacy while browsing the web.
How to use iCloud Private Relay for enhanced privacy
iCloud Private Relay, included with an iCloud+ subscription, enhances your privacy while browsing the web in Safari.
Why logs aren’t enough: Enhancing SIEM with AI-driven NDR
Join cybersecurity expert Jonathan Mayled from 5-hour Energy as he uncovers the limitations of log-based SIEMs and the transformative role of AI-driven Network Detection and Response (NDR).
New infosec products of the week: February 7, 2025
Here’s a look at the most interesting products from the past week, featuring releases from Dynatrace, Nymi, Qualys, SafeBreach, and Satori.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/02/09/week-in-review-exploited-7-zip-0-day-flaw-crypto-stealing-malware-found-on-app-store-google-play/