ZeroHour
Security Affairspublished ()ingested @securityaffairs1

Security Affairs newsletter Round 539 by Pierluigi Paganini

highRansomware exploited in the wildimportance 60CVE-2025-9074CVE-2025-7775CVE-2025-53786

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-53786
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix.

On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by taking the steps documented with the April 18th announcement. Microsoft strongly recommends reading the information, installing the April 2025 (or later) Hot Fix and implementing the changes in your Exchange Server and hybrid environment.

NVD description · AI analysis pending
8.07%
  • microsoft exchange server
  • microsoft exchange server subscription edition
CVE-2025-7775
Actively Exploited Memory Overflow RCE/DoS in Citrix NetScaler ADC/Gateway

CVE-2025-7775 is a memory overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution and/or denial of service. It is triggered when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or AAA virtual server, or — on 13.1, 14.1, 13.1-FIPS, and NDcPP builds — when load-balancing virtual servers of type HTTP, SSL, or HTTP_QUIC are bound with IPv6 services or servicegroups with IPv6 servers (including DBS IPv6), or a CR virtual server of type HDX is in use. A remote, unauthenticated attacker (CVSS 4.0 network vector with no privileges required) who triggers the memory overflow can execute code with high impact on confidentiality and integrity or crash the device. Organizations running NetScaler in these exposed configurations, notably as remote-access gateways, are affected. Exploitation is confirmed in the wild: Citrix has confirmed active exploitation, the flaw was added to CISA's KEV catalog on 2025-08-26, and EPSS estimates a 19.6% probability of exploitation within 30 days (97th percentile).

Do: Upgrade all NetScaler ADC and Gateway appliances to the patched builds on the 13.1, 14.1, 13.1-FIPS, and NDcPP release trains identified in Citrix's security bulletin, prioritizing internet-facing devices. Audit configurations for Gateway (VPN/ICA Proxy/CVPN/RDP Proxy) or AAA virtual servers, HTTP/SSL/HTTP_QUIC LB virtual servers with IPv6 bindings, and CR virtual servers of type HDX to confirm exposure. The KEV listing makes applying vendor mitigations or the upgrade mandatory for US federal agencies under BOD 22-01.

9.220% KEV
  • Citrix NetScaler ADC 13.1, 14.1, 13.1-FIPS, and NDcPP branches; vulnerable when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; or with
  • Citrix NetScaler Gateway 13.1, 14.1, 13.1-FIPS, and NDcPP branches; vulnerable when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
large≈28,000+ internet-exposed NetScaler instances per public scans; total vulnerable deployments likely higher
CVE-2025-9074
A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at

A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Container Isolation (ECI) enabled, and with or without the "Expose daemon on tcp://localhost:2375 without TLS" option enabled. This can lead to execution of a wide range of privileged commands to the engine API, including controlling other containers, creating new ones, managing images etc. In some circumstances (e.g. Docker Desktop for Windows with WSL backend) it also allows mounting the host drive with the same privileges as the user running Docker Desktop.

NVD description · AI analysis pending
9.32%
Full article469 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

U.S. Government Seizes Online Marketplaces Selling Fraudulent Identity Documents Used in Cybercrime Schemes  

Auchan announces that it has been the victim of “an act of cybercrime”, with “hundreds of thousands” of its customers’ data hacked  

Widespread Data Theft Targets Salesforce Instances via Salesloft Drift  

Storm-0501’s evolving techniques lead to cloud-based ransomware

Hacker used a voice phishing attack to steal Cisco customers’ personal information  

DSLRoot, Proxies, and the Threat of ‘Legal Botnets’  

Cyberattack against several municipal and regional systems

Infostealers: The Silent Smash-and-Grab Driving Modern Cybercrime   

Colt Technology Services gets ransomware’d via SharePoint initial access— some learning points    

Germany charges man over cyberattack on Rosneft subsidiary  

Ransomware gang takedowns causing explosion of new, smaller groups 

Citrix forgot to tell you CVE-2025–6543 has been used as a zero day since May 2025 

Malware

The Resurgence of IoT Malware: Inside the Mirai-Based “Gayfemboy” Botnet Campaign

Your Connection, Their Cash: Threat Actors Misuse SDKs to Sell Your Bandwidth 

Android backdoor spies on employees of Russian business 

Tamperedchef – The Bad PDF Editor

AppSuite PDF Editor Backdoor: A Detailed Technical Analysis    

Malware devs abuse Anthropic’s Claude AI to build ransomware 

Hacking

Breaking Docker’s Isolation Using… Docker? (CVE-2025-9074)  

Vtenext 25.02: A three-way path to RCE 

Citrix Patches Three NetScaler Flaws, Confirms Active Exploitation of CVE-2025-7775

Widespread Data Theft Targets Salesforce Instances via Salesloft Drift  

Cache Me If You Can (Sitecore Experience Platform Cache Poisoning to RCE) 

Inside the Lab-Dookhtegan Hack: How Iranian Ships Lost Their Voice at Sea  

WhatsApp Issues Emergency Update for Zero-Click Exploit Targeting iOS and macOS Devices

Intelligence and Information Warfare

APT36: Targets Indian BOSS Linux Systems with Weaponized AutoStart Files  

Deception in Depth: PRC-Nexus Espionage Campaign Hijacks Web Traffic to Target Diplomats  

ZipLine Campaign: A Sophisticated Phishing Attack Targeting US Companies 

Citizen Lab director warns cyber industry about US authoritarian descent

Dutch providers targeted by Salt Typhoon  

TAOTH Campaign Exploits End-of-Support Software to Target Traditional Chinese Users and Dissidents  

Biased AI chatbots can sway people’s political views in minutes  

Amazon disrupts watering hole campaign by Russia’s APT29 

Cybersecurity

2025 State of the Internet: Digging into Residential Proxy Infrastructure

Electronics manufacturer Data I/O reports ransomware attack to SEC    

FTC Calls on Tech Firms to Resist Foreign Anti-Encryption Demands  

ENISA to operate the EU Cyber Reserve 

Over 28,000 Citrix devices vulnerable to new exploited RCE flaw

Microsoft Releases Guidance on High-Severity Vulnerability (CVE-2025-53786) in Hybrid Exchange Deployments      

TransUnion says hackers stole 4.4 million customers’ personal information  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181754/breaking-news/security-affairs-newsletter-round-539-by-pierluigi-paganini-international-edition.html