ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-0130
Directory Traversal Arbitrary File Read in Ruby on Rails (actionpack)

CVE-2014-0130 is a directory traversal vulnerability (CWE-22) in the implicit-render implementation of Ruby on Rails, located in actionpack's abstract_controller/base.rb. A remote attacker sends a crafted request that manipulates the template/render path, causing the application to resolve and render files outside the intended directory. Successful exploitation grants arbitrary file reads on the web server, potentially exposing application source code and configuration files containing secrets. Any Ruby on Rails deployment that relies on implicit rendering is affected, per CISA's listing of Ruby on Rails. The flaw is known to be exploited in the wild (added to CISA KEV on 2022-03-25), carries a high EPSS of 53.7% (99th percentile), and has no known public proof-of-concept; ransomware use is unknown.

Do: Apply updated Rails releases per vendor instructions, as required by CISA's KEV listing for this vulnerability. Audit Rails controllers and code paths that depend on implicit rendering, and review access logs for crafted requests containing traversal sequences (../ or encoded equivalents). Where patching is delayed, render templates explicitly and restrict accepted formats and paths.

54% KEV
  • Rails Ruby on Rails
mass≈1,000,000+ Rails deployments (Rails is a top-tier server-side web framework; only apps relying on implicit rendering are exploitable)
CVE-2014-0780
Directory Traversal in InduSoft Web Studio NTWebServer Enables Password Theft and RCE

InduSoft Web Studio's bundled NTWebServer component contains a directory traversal flaw (CWE-22) that lets a remote attacker send crafted HTTP requests that escape the web root and read files outside it, including the product's application (APP) files. Because those APP files store administrative passwords, an attacker who harvests them can authenticate to the product and ultimately achieve remote code execution. Any deployment running InduSoft Web Studio with the NTWebServer web service enabled is affected, especially HMI/SCADA servers reachable from untrusted networks or the internet. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-04-15) and carries a high EPSS score of about 74% (99th percentile), indicating substantial exploitation likelihood, though public PoC code is not known. Ransomware association is not documented.

Do: Apply updates to InduSoft Web Studio per the vendor's instructions, as required by CISA's KEV listing. Until patched, restrict access to NTWebServer from untrusted networks and review web logs for directory traversal request patterns. If compromise is suspected, rotate administrative passwords stored in APP files, since their disclosure enables remote code execution.

74% KEV
  • InduSoft Web Studio
moderatelikely on the order of tens of thousands of installed copies worldwide, with only a subset (internet-exposed NTWebServer instances) directly reachable
CVE-2015-0666
Directory Traversal in Cisco Prime Data Center Network Manager (DCNM)

CVE-2015-0666 is a directory traversal flaw (CWE-22) in the fmserver servlet of Cisco Prime Data Center Network Manager (DCNM), a management platform for Cisco data-center networking equipment. A remote attacker can send crafted requests containing traversal sequences to the fmserver servlet, bypassing intended path restrictions. Successful exploitation lets the attacker read arbitrary files from the DCNM server, potentially exposing configuration data, credentials, or other sensitive material stored on the host. Organizations running affected Cisco Prime DCNM deployments are affected, particularly where the management interface or fmserver servlet is reachable from untrusted networks. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog (2022-03-25), indicating confirmed in-the-wild exploitation, with a high EPSS of 40.4% for exploitation in the next 30 days, though ransomware use has not been confirmed.

Do: Apply Cisco updates for Prime DCNM per the vendor's instructions, as required by CISA's KEV listing. Inventory your environment for DCNM installations and check whether the fmserver servlet is exposed to untrusted networks, restricting access to trusted management hosts if patching must be deferred. Because the flaw has been exploited in the wild, review DCNM server access logs for signs of path-traversal requests while remediation is underway.

40% KEV
  • Cisco Prime Data Center Network Manager (DCNM)
moderatelikely on the order of thousands of DCNM deployments worldwide (specialized enterprise data-center management tool)
CVE-2015-4068
Directory Traversal Vulnerability in Arcserve Unified Data Protection (UDP)

CVE-2015-4068 is a directory traversal flaw (CWE-22) in Arcserve Unified Data Protection (UDP), Arcserve's backup and disaster recovery platform. A remote attacker can trigger it by submitting crafted requests containing directory traversal sequences to the affected UDP component, causing the software to access files outside the intended directory. Successful exploitation can disclose sensitive information accessible to the server or crash the service, resulting in a denial of service. Any organization running an affected Arcserve UDP deployment is potentially exposed; the available data does not specify affected version ranges, so administrators should compare their installed version against Arcserve's advisory. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25, confirming in-the-wild exploitation (ransomware association unconfirmed), and EPSS assigns a 63.6% probability of exploitation within 30 days (99th percentile), though no public proof-of-concept is known.

Do: Apply the updates prescribed in Arcserve's advisory, as required by the CISA KEV listing's mandated action to patch per vendor instructions. Until patched, limit internet exposure of UDP management consoles and related services and review access logs for directory traversal patterns. Because the available data does not list affected versions, verify your installed UDP version against the Arcserve advisory before remediation.

64% KEV
  • Arcserve Unified Data Protection (UDP)
largelikely on the order of 10,000-100,000 installations worldwide; number of internet-exposed instances unknown
CVE-2016-4523
Remote Denial-of-Service in Trihedral VTScada WAP Interface

CVE-2016-4523 is a remotely exploitable denial-of-service vulnerability in the WAP interface of Trihedral VTScada (formerly VTS), classified under CWE-119 (improper memory-bounds handling). A remote attacker can crash the VTScada service by sending crafted requests to the WAP interface, disrupting the SCADA/HMI application until the process is restarted; there is no indication of code execution. Organizations running VTScada/VTS where the WAP interface is reachable from untrusted or internet-facing networks are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-04-15, confirming exploitation in the wild years after publication (ransomware use: unknown), and the high EPSS score (30.7% within 30 days, 98th percentile) suggests meaningful near-term exploitation risk even though no public PoC is known.

Do: Apply updates from Trihedral per vendor instructions, as required by the CISA KEV catalog entry. As an interim mitigation, restrict the WAP interface to trusted networks (firewall or ACL it away from internet-facing access) and check whether your deployment exposes WAP services externally. Monitor for repeated crashes of the VTScada service, which would indicate active exploitation attempts.

7.531% KEV
  • Trihedral VTScada (formerly VTS)
nicheunknown (no published install-base or internet-exposure counts)
CVE-2016-8530
A remote denial of service vulnerability in HPE iMC PLAT version v7.2 E0403P06 and earlier was found.

A remote denial of service vulnerability in HPE iMC PLAT version v7.2 E0403P06 and earlier was found. The problem was resolved in iMC PLAT 7.3 E0504 or subsequent version.

NVD description · AI analysis pending
7.548%
  • hp intelligent management center
CVE-2017-11512
The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the name parameter for the download-snapshot URL. An unauthenticated remote attacker can use this vulnerability to download arbitrary files.

NVD description · AI analysis pending
7.580%
  • manageengine servicedesk
CVE-2018-3948
An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server.

An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server. A specially crafted URL can cause the server to stop responding to requests, resulting in downtime for the management portal. An attacker can send either an unauthenticated or authenticated web request to trigger this vulnerability.

NVD description · AI analysis pending
7.523% PoC
  • tp-link tl-r600vpn firmware
CVE-2018-3949
An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN.

An exploitable information disclosure vulnerability exists in the HTTP server functionality of the TP-Link TL-R600VPN. A specially crafted URL can cause a directory traversal, resulting in the disclosure of sensitive system files. An attacker can send either an unauthenticated or an authenticated web request to trigger this vulnerability.

NVD description · AI analysis pending
7.553% PoC
  • tp-link tl-r600vpn firmware
CVE-2019-18952
SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload.

SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.

NVD description · AI analysis pending
9.845% PoC ×2
  • sibsoft xfilesharing
CVE-2020-5410
Directory Traversal in VMware Spring Cloud Config Server

Spring Cloud Config's spring-cloud-config-server module (VMware/Pivotal/Tanzu) contains a directory traversal flaw that allows the config server to serve arbitrary configuration files from the underlying filesystem. An unauthenticated attacker triggers it by sending a request with a specially crafted URL containing path-traversal sequences to a vulnerable config server. Because the server resolves files outside the intended directory, the attacker gains the ability to read arbitrary files, including application configuration data and any credentials or secrets it references, with no integrity or availability impact. Anyone running Spring Cloud Config 2.2.x prior to 2.2.3, 2.1.x prior to 2.1.9, or older unsupported versions — including VMware Tanzu Spring Cloud Config Server deployments — is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-03-25 and carries a very high EPSS score (95.6%, 100th percentile).

Do: Upgrade Spring Cloud Config to 2.2.3 or later (2.2.x line) or 2.1.9 or later (2.1.x line); older unsupported versions should move to a supported release, and VMware Tanzu Spring Cloud Services users should apply updates per vendor instructions. Until patched, restrict network reachability of config servers, require authentication on config endpoints where supported, and scan for internet-exposed instances, since exploitation requires no privileges or user interaction. Audit hosts running config servers for reads of sensitive local files, as the flaw allows unauthenticated arbitrary file disclosure.

7.596% KEV
  • VMware (Pivotal/Tanzu) Spring Cloud Config (spring-cloud-config-server) 2.2.x prior to 2.2.3, 2.1.x prior to 2.1.9, and older unsupported versions
  • VMware Tanzu Spring Cloud Configuration (Config) Server deployments running affected Spring Cloud Config versions (2.2.x prior to 2.2.3, 2.1.x prior to 2.1.9, and older)
largetens of thousands of config server deployments worldwide, with likely thousands internet-exposed (exact install counts unpublished)
CVE-2020-8260
Authenticated RCE in Ivanti Pulse Connect Secure admin web interface (pre-9.1R9)

Ivanti Pulse Connect Secure versions before 9.1R9 contain a vulnerability (mapped to CWE-434) in the administrative web interface in which compressed uploads are handled with uncontrolled gzip extraction. An authenticated attacker with high-privilege (admin-level) access to that interface can send a crafted gzip-compressed file, triggering arbitrary code execution on the appliance with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.2, AV:N/PR:H). Successful exploitation yields arbitrary code execution on the VPN appliance itself, effectively enabling full compromise of the gateway that terminates the organization's VPN sessions. Any organization running Pulse Connect Secure on a release prior to 9.1R9 is affected, making the typical target an enterprise or government SSL VPN appliance accessible to anyone holding admin credentials. Exploitation is in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 96.5% EPSS exploitation probability (100th percentile), and a public proof of concept is available.

Do: Upgrade Pulse Connect Secure to 9.1R9 or later per the vendor's instructions; given the related patch-bypass flaw CVE-2021-22937 and the 'new urgent update' headlines, ensure the most recent available 9.1R release is applied rather than relying solely on the original 9.1R9 fix. Restrict the admin web interface to trusted management networks and review administrative accounts. Because the flaw is on CISA's KEV list and CISA has published malware analysis reports for Pulse Secure-targeted samples, hunt patched and unpatched devices for signs of compromise (e.g., web shells or implants).

7.296% KEV PoC
  • ivanti connect secure all releases prior to 9.1R9 (< 9.1R9)
mass≈10^5 devices: a six-figure installed base of Pulse Connect Secure appliances, with tens of thousands internet-exposed in public scans at the time of the 2021…
CVE-2021-43936
The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's e

The software allows the attacker to upload or transfer files of dangerous types to the WebHMI portal, that may be automatically processed within the product's environment or lead to arbitrary code execution.

NVD description · AI analysis pending
9.836% PoC
  • webhmi webhmi firmware
CVE-2022-24086
Unauthenticated RCE via checkout input-validation flaw in Adobe Commerce/Magento

Adobe Commerce and Magento Open Source versions 2.4.3-p1 and earlier and 2.3.7-p2 and earlier contain an improper input validation flaw (CWE-20) in the checkout process. A remote attacker can trigger it with no privileges and no user interaction by submitting crafted input to a store's checkout flow, and successful exploitation results in arbitrary code execution on the server hosting the storefront. Any Adobe Commerce or Magento Open Source storefront running the affected versions is exposed, and because these are internet-facing e-commerce sites the practical exposure is broad. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15), its EPSS exploitation probability is 99.2% (100th percentile), and news reports describe ongoing attacks against Magento 2 stores, including recurring 'Xurum' attack campaigns and template-based attacks.

Do: Upgrade every store to an Adobe-patched release per the vendor's instructions - i.e., any release newer than 2.4.3-p1 on the 2.4.x line or newer than 2.3.7-p2 on the 2.3.x line - noting that headlines indicate companion Magento CVEs were fixed in the same patch release, so consult Adobe's advisory for the full list. Because exploitation is unauthenticated and confirmed in the wild, prioritize internet-facing shops; WAF rules may reduce risk, but reports indicate WAF bypasses in related Magento attacks, so patching is the only reliable fix. After patching, review web server and application logs for exploitation attempts against the checkout flow and check affected hosts for indicators of compromise.

9.899% KEV
  • Adobe Commerce 2.4.3-p1 and earlier; 2.3.7-p2 and earlier
  • Adobe Magento Open Source 2.4.3-p1 and earlier; 2.3.7-p2 and earlier
massroughly 100,000-300,000 online storefronts (Magento/Adobe Commerce is among the most widely deployed e-commerce platforms)
CVE-2023-28771
Unauthenticated OS Command Injection in Zyxel ATP, USG FLEX, VPN, and ZyWALL Firewalls

CVE-2023-28771 is an unauthenticated OS command injection flaw (CWE-78) in Zyxel firewall firmware, caused by improper error message handling in the IKE packet decoder. A remote attacker triggers it by sending crafted packets to an affected device, with no credentials or user interaction required (CVSS 3.1: 9.8, network vector, low complexity). Successful exploitation lets the attacker execute operating-system commands on the firewall, which typically means full device compromise of these perimeter/VPN gateway appliances. Organizations running Zyxel ZyWALL/USG, VPN, USG FLEX, or ATP series firewalls on the affected firmware ranges are exposed, especially where IKE/VPN traffic is reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-05-31, carries a 99.3% EPSS score (100th percentile), is reportedly used by DDoS botnets, and was reportedly exploited in the May 2023 coordinated attacks against nearly two dozen Danish energy companies.

Do: Apply Zyxel's patched firmware to all affected devices per the vendor advisory - releases newer than 4.73 for ZyWALL/USG and newer than 5.35 for ATP, USG FLEX, and VPN series - prioritizing internet-facing and VPN gateway appliances, as this is a KEV required-action vulnerability. Where immediate patching is not possible, restrict IKE traffic (UDP 500/4500) to trusted peers or disable unneeded IPsec VPN termination. After patching, review device logs and configurations for signs of command execution or unexpected changes, given confirmed botnet and targeted-attack use.

9.899% KEV PoC
  • Zyxel ZyWALL/USG series firewalls firmware 4.60 through 4.73
  • Zyxel VPN series firewalls firmware 4.60 through 5.35
  • Zyxel USG FLEX series firewalls (USG FLEX 50, 50W, 100, 100W, 200, 500) firmware 4.60 through 5.35
  • +1 more
largetens of thousands of internet-exposed Zyxel firewall/VPN gateways (order of 10,000-100,000 devices/sites); estimate
Full article1,162 words · extracted from helpnetsecurity.com · click to collapse

Check Point Software’s latest threat index reveals a significant rise in infostealers like Lumma Stealer, while mobile malware like Necro continues to pose a significant threat, highlighting the evolving tactics used by cybercriminals across the globe.

cybercriminals infostealers rise

Last month researchers discovered an infection chain where fake CAPTCHA pages are being utilized to distribute Lumma Stealer malware, which has climbed to 4th place in the monthly top malware rankings.

This campaign is notable for its global reach, affecting multiple countries through two primary infection vectors: one involving cracked game download URLs and the other through phishing emails targeting GitHub users as an innovative new means of attack vector. The infection process misleads victims into executing a malicious script that has been copied to their clipboard, showcasing the increasing prevalence of infostealers as an effective means for cyber criminals to exfiltrate credentials and sensitive data from compromised systems.

Necro has infected various popular applications, including game mods available on Google Play, with a cumulative audience of over 11 million Android devices.

The malware employs obfuscation techniques to evade detection and utilizes steganography, which is the practice of concealing information within another message or physical object to avoid detection, to conceal its payloads.Once activated, it can display ads in invisible windows, interact with them, and even subscribe victims to paid services, highlighting the evolving tactics used by attackers to monetize their operations.

The rise of sophisticated infostealers underscores a growing reality. Cybercriminals are evolving their methods and leveraging innovative attack vectors. Organizations must go beyond traditional defenses, adopting proactive and adaptive security measures that anticipate emerging threats to counter these persistent challenges effectively.

Top malware families

FakeUpdates is the most prevalent malware this month with an impact of 6% worldwide organizations, followed by Androxgh0st with a global impact of 5%, and AgentTesla with a global impact of 4%.

FakeUpdates – FakeUpdates (AKA SocGholish) is a downloader written in JavaScript. It writes the payloads to disk prior to launching them. FakeUpdates led to further compromise via many additional malware, including GootLoader, Dridex, NetSupport, DoppelPaymer, and AZORult.

Androxgh0st – Androxgh0st is a botnet that targets Windows, Mac, and Linux, exploiting vulnerabilities in PHPUnit, Laravel Framework, and Apache Web Server to steal sensitive data.

AgentTesla – AgentTesla is an advanced RAT functioning as a keylogger and information stealer, which is capable of monitoring and collecting the victim’s keyboard input, system keyboard, taking screenshots, and exfiltrating credentials to a variety of software installed on a victim’s machine (including Google Chrome, Mozilla Firefox and the Microsoft Outlook email client).

Lumma Stealer – Lumma Stealer, also referred to as LummaC2, is a Russian-linked information-stealing malware that has been operating as a Malware-as-a-Service (MaaS) platform since 2022. As a typical information-stealer, LummaC2 focuses on harvesting various data from infected systems, including browser credentials and cryptocurrency account information.

Formbook – Formbook is marketed as Malware-as-a-Service. It is designed to steal credentials, gather screenshots, and download and execute files based on commands from its command and control serve.

NJRat – NJRat is a remote accesses Trojan, targeting mainly government agencies and organizations in the Middle East. NJRat infects victims via phishing attacks and drive-by downloads, and propagates through infected USB keys or networked drives, with the support of Command & Control server software.

AsyncRat – Asyncrat is a Trojan that targets the Windows platform. This malware sends out system information about the targeted system to a remote server. It receives commands from the server to download and execute plugins, kill processes, uninstall/update itself, and capture screenshots of the infected system.

Remcos – Remcos is a RAT that first appeared in the wild in 2016. Remcos distributes itself through malicious Microsoft Office documents, which are attached to SPAM emails, and is designed to bypass Microsoft Windowss UAC security and execute malware with high-level privileges.

Glupteba – Known since 2011, Glupteba is a backdoor that gradually matured into a botnet. By 2019 it included a C&C address update mechanism through public BitCoin lists, an integral browser stealer capability and a router exploiter.

Vidar – Vidar is an infostealer malware operating as malware-as-a-service that was first discovered in the wild in late 2018. The malware runs on Windows and can collect a wide range of sensitive data from browsers and digital wallets.

Top exploited vulnerabilities

Web Servers Malicious URL Directory Traversal (CVE-2010-4598,CVE-2011-2474,CVE-2014-0130,CVE-2014-0780,CVE-2015-0666,CVE-2015-4068,CVE-2015-7254,CVE-2016-4523,CVE-2016-8530,CVE-2017-11512,CVE-2018-3948,CVE-2018-3949,CVE-2019-18952,CVE-2020-5410,CVE-2020-8260) – There exists a directory traversal vulnerability On different web servers. The vulnerability is due to an input validation error in a web server that does not properly sanitize the URI for the directory traversal patterns. Successful exploitation allows unauthenticated remote attackers to disclose or access arbitrary files on the vulnerable server.

Command Injection Over HTTP (CVE-2021-43936,CVE-2022-24086) – A command Injection over HTTP vulnerability has been reported. A remote attacker can exploit this issue by sending a specially crafted request to the victim. Successful exploitation would allow an attacker to execute arbitrary code on the target machine.

Zyxel ZyWALL Command Injection (CVE-2023-28771) – A command injection vulnerability exists in Zyxel ZyWALL. Successful exploitation of this vulnerability would allow remote attackers to execute arbitrary OS commands in the effected system.

Top mobile malwares

This month Joker in the 1st place in the most prevalent Mobile malware, followed by Necro and Anubis.

Joker – An android Spyware in Google Play, designed to steal SMS messages, contact lists and device information. Furthermore, the malware signs the victim silently for premium services in advertisement websites.

Necro – Necro is an Android Trojan Dropper. It is capable of downloading other malware, showing intrusive ads and stealing money by charging paid subscriptions.

Anubis – Anubis is a banking Trojan malware designed for Android mobile phones. Since it was initially detected, it has gained additional functions including Remote Access Trojan (RAT) functionality, keylogger, audio recording capabilities and various ransomware features. It has been detected on hundreds of different applications available in the Google Store.

Top ransomware groups

The data is based on insights from ransomware “shame sites” run by double-extortion ransomware groups which posted victim information. RansomHub is the most prevalent ransomware group this month, responsible for 17% of the published attacks, followed by Play with 10% and Meow with 5%.

RansomHubRansomHub, a rebranded version of Knight ransomware, is known for its sophisticated encryption techniques and aggressive campaigns targeting various platforms, including Windows, macOS, Linux, and particularly VMware ESXi environments.

PlayPlay Ransomware, which emerged in 2022, has targeted businesses and critical infrastructureacross North America, South America, and Europe, often exploiting vulnerabilities in systems like Fortinet SSL VPNs.

Meow – Meow Ransomware is a variant of Conti ransomware , known for encrypting a wide range of files on compromised systems and appending the “. MEOW” extension to them. It spreads through various vectors, including unprotected RDP configurations, email spam, and malicious downloads, and uses the ChaCha20 encryption algorithm to lock files, excluding “.exe” and text files.

Most targeted industries

This month education/research remained in the 1st place in the attacked industries globally, followed by government/military and communications.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/11/13/cybercriminals-infostealers-rise/