ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 531 by Pierluigi Paganini

criticalRansomware exploited in the wildimportance 60CVE-2025-6543CVE-2025-6554

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-6543
Memory Buffer Overflow in Citrix NetScaler ADC and Gateway Exploited in the Wild

Citrix NetScaler ADC and NetScaler Gateway appliances contain a memory buffer overflow (CWE-119) that can lead to unintended control flow and denial of service. The flaw is only reachable when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server, and it is network-exploitable without authentication or user interaction, though attack complexity is rated high. A successful attacker could achieve unintended control flow — with the CVSS 4.0 vector rating impact high across confidentiality, integrity, and availability — or crash the appliance, disrupting VPN access and application delivery. Any organization running NetScaler ADC or NetScaler Gateway in an affected Gateway/AAA configuration is exposed, a population that public scan data places in the tens of thousands of internet-exposed devices. The vulnerability was added to CISA's KEV catalog on 2025-06-30, confirming exploitation in the wild, with EPSS at 10.1% and no public proof-of-concept known.

Do: Apply the patched NetScaler release specified in Citrix's security bulletin for CVE-2025-6543 immediately, prioritizing appliances in Gateway or AAA configurations, per CISA KEV and BOD 22-01 requirements. Audit which virtual servers (VPN, ICA Proxy, CVPN, RDP Proxy, AAA) are in use and whether they are internet-exposed, and check appliances for signs of compromise before and after upgrading.

9.210% KEV
  • Citrix NetScaler ADC
  • Citrix NetScaler Gateway
large≈50,000+ internet-exposed NetScaler ADC/Gateway devices (only Gateway/AAA configurations vulnerable)
CVE-2025-6554
Type Confusion in Google Chrome V8 Allows Arbitrary Read/Write (Actively Exploited)

CVE-2025-6554 is a type confusion vulnerability (CWE-843) in the V8 JavaScript engine of Google Chrome, affecting versions prior to 138.0.7204.96. A remote attacker can trigger it by inducing a user to open a crafted HTML page, and the flaw permits arbitrary read and write within the browser renderer process. Successful exploitation yields high confidentiality and integrity impact, and V8 type confusion bugs are commonly used as the first stage toward a full browser compromise. Any user of an unpatched Chrome or Chromium-based browser is exposed, and the flaw is being actively exploited in the wild as a zero-day; CISA added it to the Known Exploited Vulnerabilities catalog on 2025-07-02. Ransomware usage is not confirmed (reported as unknown), and no public proof-of-concept is known.

Do: Update Chrome to 138.0.7204.96 or later (check chrome://settings/help) and restart the browser to load the patched V8; users of Chromium-derived browsers (Edge, Brave, Opera, etc.) should install their vendor's corresponding V8 patch. Organizations must apply vendor mitigations or follow BOD 22-01 guidance given the KEV listing, and should inventory managed browsers and force-update policies to confirm rollout.

8.113% KEV
  • Google Chrome all versions prior to 138.0.7204.96
  • Google Chromium V8 JavaScript engine V8 versions shipping in Chromium/Chrome prior to the 138.0.7204.96 fix
mass≈3+ billion Chrome users; effectively every desktop Chrome installation running a build older than 138.0.7204.96
Full article479 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

Crypto investment fraud ring dismantled in Spain after defrauding 5 000 victims worldwide

New INTERPOL report warns of sharp rise in cybercrime in Africa     

QANTAS CYBER INCIDENT 

Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology Theft  

PDFs: Portable documents, or perfect deliveries for phish? 

Hunters International Ransomware Shuts Down, Offers Free Decryptors to Victims 

Malware

10 Things I Hate About Attribution: RomCom vs. TransferLoader 

FoxyWallet: 40+ Malicious Firefox Extensions Exposed 

Addressing malware family concept drift with triplet autoencoder

RawMal-TF: Raw Malware Dataset Labeled by Type and Family

Hacking

ICC detects and contains new sophisticated cyber security incident

CVE-2025-6543: Zero Day Exploitation of NetScaler ADC and NetScaler Gateway    

Chrome Zero-Day CVE-2025-6554 Under Active Attack — Google Issues Security Update

FileFix (Part 2)  attack

Cisco warns that Unified CM has hardcoded root SSH credentials

Taking over 60k spyware user accounts with SQL injection

China breaks RSA encryption with a quantum computer, threatening global data security

Exposed JDWP Exploited in the Wild: What Happens When Debug Ports Are Left Open 

Intelligence and Information Warfare

Iranian Cyber Actors May Target Vulnerable US Networks and Entities of Interest 

macOS NimDoor | DPRK Threat Actors Target Web3 and Crypto Platforms with Nim-Based Malware

Analysis of the threat case of kimsuky group using ‘ClickFix’ tactic 

Warning Against Distribution of Malware Disguised as Research Papers (Kimsuky Group)

Dissecting Kimsuky’s Attacks on South Korea: In-Depth Analysis of GitHub-Based Malicious Infrastructure 

Houken seeking a path by living on the edge with zero-days 

Israel strikes Iran’s nuclear sites and kills top generals. Iran retaliates with missile barrages  

How Geopolitical Tensions Are Shaping Cyber Warfare 

Cybersecurity

Facebook is asking to use Meta AI on photos in your camera roll you haven’t yet shared

Ahold Delhaize Data Breach Impacts 2.2 Million People     

Denmark to tackle deepfakes by giving people copyright to their own features 

Berlin data protection commissioner reports AI app DeepSeek in Germany to Apple and Google as illegal content

263,000 Impacted by Esse Health Data Breach 

China breaks RSA encryption with a quantum computer, threatening global data security

Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones 

Google Ordered to Pay $314M for Misusing Android Users’ Cellular Data Without Permission

Vulnerability Advisory: Sudo Host Option Elevation of Privilege  

Top AI models will lie, cheat and steal to reach goals, Anthropic finds

Only One in 10 Organizations Globally Are Ready to Protect Against AI-Augmented Cyber Threats    

More than 25% of UK businesses hit by cyber-attack in last year, report finds

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/179651/breaking-news/security-affairs-newsletter-round-531-by-pierluigi-paganini-international-edition.html