ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-11182
Unauthenticated Cross-Site Scripting (XSS) in MDaemon Email Server Webmail

MDaemon Email Server versions before 24.5.1c contain a cross-site scripting flaw (CWE-79) in its handling of HTML email: JavaScript embedded in an img tag is not properly sanitized. A remote, unauthenticated attacker can trigger it simply by sending a crafted HTML email that a webmail user then opens, requiring no privileges but relying on user interaction. Successful exploitation loads attacker-supplied JavaScript in the context of the webmail user's browser window, which could enable session or credential theft and further intrusions from that user's session. Any organization running an affected MDaemon version with users of its webmail client is affected; MDaemon is a commercial on-premises Windows mail server used mainly by small and mid-sized organizations. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-19, and public reporting ties MDaemon exploitation to Russia-linked APT28 (Fancy Bear) campaigns that targeted the email of high-level Ukrainians and their military suppliers.

Do: Upgrade to MDaemon Email Server 24.5.1c or later, prioritizing installations whose webmail is exposed to the internet, since the flaw is actively exploited and KEV-listed. Review webmail access and message-viewing logs for suspicious activity, especially in organizations that may be targeted by APT28 (Ukrainian government, military, or defense-supply interests). Federal agencies must follow CISA KEV required actions (apply vendor mitigations per instructions and applicable BOD 22-01 guidance, or discontinue use if mitigations are unavailable) by the required due date.

5.318% KEV
  • MDaemon Technologies MDaemon Email Server all versions before 24.5.1c
moderatetens of thousands of on-premises deployments; plausibly on the order of 10,000–100,000 webmail users
CVE-2025-22249
VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability.

VMware Aria automation contains a DOM based Cross-Site Scripting (XSS) vulnerability. A malicious actor may exploit this issue to steal the access token of a logged in user of VMware Aria automation appliance by tricking the user into clicking a malicious crafted payload URL.

NVD description · AI analysis pending
8.2<1%
  • vmware aria automation
  • vmware cloud foundation
  • vmware telco cloud platform
CVE-2025-23166
The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the

The C++ method SignTraits::DeriveBits() may incorrectly call ThrowException() based on user-supplied inputs when executing in a background thread, crashing the Node.js process. Such cryptographic operations are commonly applied to untrusted inputs. Thus, this mechanism potentially allows an adversary to remotely crash a Node.js runtime.

NVD description · AI analysis pending
7.5<1%
CVE-2025-27696
Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permission

Incorrect Authorization vulnerability in Apache Superset allows ownership takeover of dashboards, charts or datasets by authenticated users with read permissions. This issue affects Apache Superset: through 4.1.1. Users are recommended to upgrade to version 4.1.2 or above, which fixes the issue.

NVD description · AI analysis pending
5.31%
  • apache superset
CVE-2025-27920
Directory Traversal in Srimax Output Messenger Before 2.0.63

Output Messenger versions before 2.0.63 contain a directory traversal flaw (CWE-24) caused by improper handling of file paths in application parameters. An attacker who submits ../ sequences in these parameters can reach files outside the intended directory, potentially retrieving configuration files or other sensitive files from the server. The CVSS vector indicates network access with low privileges is required, so a low-privileged user account is sufficient to trigger the flaw. Any organization running Output Messenger below 2.0.63 is affected, and the flaw has been actively exploited: a Türkiye-aligned APT group reportedly used it as a zero-day against Kurdish military servers in Iraq, deploying Golang backdoors, an activity also observed by Microsoft. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on 2025-05-19, requiring federal agencies to apply vendor mitigations, follow BOD 22-01 guidance, or discontinue use of the product.

Do: Upgrade Srimax Output Messenger to version 2.0.63 or later per the vendor's instructions, as required by CISA's KEV entry (or follow BOD 22-01 guidance for federal cloud services). Organizations that cannot patch promptly should restrict network access to Output Messenger Server and review affected hosts for signs of compromise, including unexpected Golang backdoor binaries or processes and unauthorized access to or modification of configuration files.

8.82% KEV
  • Srimax Output Messenger all versions before 2.0.63
nicheunknown; likely no more than thousands of on-premises deployments (niche enterprise chat product)
CVE-2025-32706
+4 in the same advisory: …32709 …30400 …32701 …30397
Heap-Based Buffer Overflow in Windows CLFS Driver Enables Local Privilege Escalation

CVE-2025-32706 is a heap-based buffer overflow stemming from improper input validation (CWE-20) in the Microsoft Windows Common Log File System (CLFS) driver, triggered when a locally authenticated, low-privileged user gets the driver to process crafted log-related input. A successful exploit lets the attacker elevate from a limited local account to full system-level privileges, giving high impact to confidentiality, integrity, and availability on the host. All installations of the listed releases are affected — Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (22H2, 23H2, 24H2), and Windows Server 2008, 2012, 2016, and 2019 — because the CLFS driver ships with these products by default. The vulnerability is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-13, and it was one of the five actively exploited zero-days fixed in Microsoft's May 2025 Patch Tuesday. Ransomware use is currently unknown, and public detection and mitigation scripts are available for defenders.

Do: Apply the May 2025 Windows security updates to all affected Windows 10, Windows 11, and Windows Server systems, prioritizing internet-facing and shared servers given confirmed in-the-wild exploitation; federal agencies must follow BOD 22-01 required actions or discontinue use if mitigations are unavailable. Until patched, restrict local logon and code execution rights to trusted users and watch for local privilege-escalation activity, using the publicly available detection and mitigation scripts as a starting point.

7.8
group max
2% KEV PoC ×2
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019
masson the order of hundreds of millions of installations (CLFS driver present by default on all affected Windows 10, 11, and Server releases)
CVE-2025-31644
Authenticated Command Injection in F5 BIG-IP (Appliance Mode)

CVE-2025-31644 is a command injection flaw (CWE-77) in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command that is exposed when a BIG-IP system is running in Appliance mode. An authenticated attacker who already holds the Administrator role on the device can trigger the flaw by issuing a crafted command through the affected interface. A successful exploit lets the attacker execute arbitrary system commands on the underlying operating system, crossing the intended security boundary between the administrative control plane and the system. Affected organizations are those running any of the broad set of BIG-IP modules (e.g., LTM-adjacent services such as APM, ASM, AFM, AWAF, DNS, and others) in Appliance mode on software versions still within technical support; versions past End of Technical Support (EoTS) were not evaluated. As of now there is no known exploitation in the wild and no public proof-of-concept, but the EPSS score of 26.5% (98th percentile) indicates a relatively high probability of exploitation within the next 30 days.

Do: Inventory all BIG-IP systems and identify which run in Appliance mode, then upgrade to a fixed release listed in the F5 security advisory for CVE-2025-31644, noting that systems on EoTS software versions must move to a supported release to receive patches. Until patching is complete, restrict iControl REST and tmsh access to trusted administrators only, limit exposure of management interfaces to the internet, and review admin accounts for unnecessary Administrator-role assignments. Watch for updates to F5's advisory and KEV listings given the elevated EPSS score, and monitor management-plane logs for unexpected command activity.

8.527%
  • f5 BIG-IP Access Policy Manager
  • f5 BIG-IP Advanced Firewall Manager
  • f5 BIG-IP Advanced Web Application Firewall
  • +9 more
masson the order of hundreds of thousands of BIG-IP deployments (10^5), though the practically exploitable subset is smaller
CVE-2025-32756
Stack-based overflow RCE in Fortinet FortiMail, FortiVoice, FortiNDR, FortiFone

CVE-2025-32756 is a stack-based buffer overflow (CWE-124) in Fortinet's FortiMail, FortiVoice, FortiNDR and FortiFone products that is reachable over the network and requires no authentication. An attacker triggers the flaw by sending crafted HTTP requests to the affected device's web-facing service. Successful exploitation yields arbitrary code or command execution on the appliance, giving the attacker control of the device and any traffic or data it handles (such as email or voice services). Organizations running these Fortinet appliances or phones are affected, particularly where the devices are reachable from the internet. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-05-14, confirming exploitation in the wild; no public proof-of-concept is known, ransomware use is unconfirmed, and EPSS puts its 30-day exploitation probability at about 30% (98th percentile).

Do: Inventory your environment for FortiMail, FortiVoice, FortiNDR and FortiFone deployments and apply the patched releases specified in Fortinet's advisory for CVE-2025-32756. Until patched, restrict internet exposure of the affected devices' HTTP/HTTPS interfaces (limit admin and web access to trusted networks/VPN) per vendor mitigation guidance, and review device logs for signs of exploitation. Federal agencies must apply the required mitigations or discontinue use per BOD 22-01 deadlines.

9.830% KEV
  • Fortinet FortiMail
  • Fortinet FortiVoice
  • Fortinet FortiNDR
  • +1 more
largeLikely on the order of tens of thousands of deployed appliances/phones (estimate)
CVE-2025-3463
+1 in the same advisory: …3462
"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation vulnerability in ASUS Dri

"This issue is limited to motherboards and does not affect laptops, desktop computers, or other endpoints." An insufficient validation vulnerability in ASUS DriverHub may allow untrusted sources to affect system behavior via crafted HTTP requests. Refer to the 'Security Update for ASUS DriverHub' section on the ASUS Security Advisory for more information.

NVD description · AI analysis pending
9.4
group max
<1%
CVE-2025-42999
Insecure Deserialization in SAP NetWeaver Visual Composer Metadata Uploader

CVE-2025-42999 is an insecure deserialization flaw (CWE-502) in the Visual Composer Metadata Uploader component of SAP NetWeaver. It is triggered when a privileged user uploads untrusted or malicious content to the Metadata Uploader, which the application then deserializes; on its own the flaw requires high-privilege access, but attackers commonly chain it with the separately tracked unauthenticated upload flaw CVE-2025-31324 in the same component. Successful exploitation can yield remote code execution and full compromise of the host's confidentiality, integrity, and availability, with impact beyond the vulnerable component (CVSS scope changed, 9.1 critical). Any organization running SAP NetWeaver with the Visual Composer Metadata Uploader enabled, especially internet-facing application servers, is affected. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-15 with known ransomware use, and reporting links active attacks to ransomware groups (BianLian and RansomExx deploying the PipeMagic trojan) and to Chinese-linked APTs exploiting the sibling CVE-2025-31324.

Do: Apply SAP's security patches addressing CVE-2025-42999 together with the companion CVE-2025-31324 in the same Visual Composer Metadata Uploader, per vendor instructions, or restrict/disable access to the Metadata Uploader endpoint if patching is delayed. Given confirmed ransomware use (BianLian, RansomExx) and PipeMagic trojan deployments, review upload and authentication logs on NetWeaver servers and hunt for signs of compromise and post-exploitation activity. U.S. federal agencies must follow CISA BOD 22-01 guidance: apply mitigations by the KEV remediation due date or discontinue use of affected instances.

9.114% KEV ransomware PoC
  • SAP NetWeaver (Visual Composer Metadata Uploader component)
moderatelow thousands of internet-exposed SAP NetWeaver servers (≈1k–10k systems), with a substantially larger internal install base
CVE-2025-4317
The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem_get_logo_url() function in all versions

The TheGem theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the thegem_get_logo_url() function in all versions up to, and including, 5.10.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.

NVD description · AI analysis pending
8.81%
  • WordPress
CVE-2025-4428
+1 in the same advisory: …4427
Authenticated Code Injection RCE in Ivanti Endpoint Manager Mobile (EPMM) API

CVE-2025-4428 is a code injection flaw (CWE-94) in the API component of Ivanti Endpoint Manager Mobile (EPMM) that lets an authenticated, low-privileged remote attacker execute arbitrary code by sending crafted API requests. Successful exploitation yields code execution on the MDM server itself (CVSS 8.8, High), which typically holds device inventory and administrative control over an organization's enrolled mobile fleet. Any organization running EPMM 12.5.0.0 or earlier is in scope. Exploitation is confirmed in the wild: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-05-19, EPSS puts the 30-day exploitation probability at 86% (100th percentile), and public reporting ties limited attacks to the China-linked actor UNC5221, who reportedly began exploiting it alongside the companion API authentication bypass CVE-2025-4427 shortly after disclosure. CISA has also warned that threat actors exploiting these EPMM flaws deploy two malware strains; ransomware involvement has not been confirmed.

Do: Upgrade every EPMM instance running 12.5.0.0 or earlier to the patched release per Ivanti's security advisory, prioritizing internet-facing servers, and note that federal agencies must satisfy the BOD 22-01 required action (patch, apply vendor mitigations, or discontinue use of the product). If patching is delayed, restrict internet exposure of the API and review EPMM logs and the advisory's indicators of compromise, since attackers have chained this flaw with the CVE-2025-4427 authentication bypass and deployed malware. Treat any unpatched, exposed EPMM instance as actively targeted until it is remediated.

8.8
group max
86% KEV
  • Ivanti Endpoint Manager Mobile (EPMM) 12.5.0.0 and prior (API component; affected platforms unspecified in the source data)
largetens of thousands of enterprise deployments (order of 10k-100k EPMM servers; many are internet-exposed)
CVE-2025-4632
Actively Exploited Path Traversal File Write in Samsung MagicINFO 9 Server

Samsung MagicINFO 9 Server, the web-based management server used to run Samsung digital signage deployments, contains a path traversal flaw (CWE-22) that allows an attacker to write arbitrary files with system authority. An attacker triggers the flaw by sending crafted path input containing directory traversal sequences, causing files to be written outside the intended location; because the write occurs with system-level privileges, it can enable remote code execution, persistence, or full compromise of the host server. Any organization running MagicINFO 9 Server — typically operators of Samsung commercial signage networks — is potentially affected. CISA added the vulnerability to the Known Exploited Vulnerabilities catalog on May 22, 2025, confirming exploitation in the wild, and EPSS places it in the 98th percentile with a 24.3% probability of exploitation within 30 days; no public proof-of-concept is known. Specific affected version ranges are not stated in the available data.

Do: Immediately update MagicINFO 9 Server to the latest release per Samsung's security advisory, or if patching is not yet possible, restrict network and internet access to the server or discontinue use as required by the CISA KEV action (federal agencies must follow BOD 22-01 timelines). Hunt for signs of compromise — unexpected or newly written files, modified web content, or added web shells/accounts — since the flaw permits system-privileged file writes. Verify internet-exposed instances are remediated first.

9.824% KEV
  • Samsung MagicINFO 9 Server
moderate≈1,000–10,000 MagicINFO 9 Server deployments worldwide
CVE-2025-4664
Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

NVD description · AI analysis pending
4.36%
  • google chrome
CVE-2025-47539
Incorrect Privilege Assignment Allows Privilege Escalation in Eventin WordPress Plugin

Eventin, a WordPress events-management plugin developed by Arraytics (listed under the ThemeWinter vendor as plugin slug wp-event-solution), contains an incorrect privilege assignment flaw (CWE-266) that allows attackers to escalate privileges. Per the CVSS 3.1 vector, exploitation is possible over the network without authentication and without user interaction (AV:N/AC:L/PR:N/UI:N), though no public proof-of-concept documents the exact trigger point. A successful attacker gains elevated privileges on the affected WordPress site, such as the ability to create or modify privileged user accounts, with high impact on confidentiality, integrity, and availability. Any WordPress site running Eventin in any version up to and including 4.0.26 is affected. Exploitation has not been confirmed in the wild and there is no public PoC, but the EPSS score assigns a 27.9% probability of exploitation within 30 days (98th percentile), so defenders should treat this as likely to be targeted soon.

Do: Update Eventin to the newest release beyond 4.0.26 via the WordPress plugin directory as soon as the patched version is available. Until then, audit the site's user list for unexpected administrator-level accounts and remove unknown users, since privilege-assignment flaws are commonly abused to plant backdoor admin accounts. Given the elevated EPSS (27.9% within 30 days), prioritize this patch across all sites where the wp-event-solution plugin is active, and monitor Arraytics/Patchstack advisories for the fixed version.

9.828%
  • themewinter (Arraytics) Eventin (WordPress plugin wp-event-solution) All versions up to and including 4.0.26 (n/a through <= 4.0.26); no fixed version specified in the source data
large≈10,000+ sites (tens of thousands at most; WordPress.org lists 10,000+ active installs for the plugin)
CVE-2025-47729
Hidden cleartext message storage in TeleMessage TM SGNL archiving backend

TeleMessage's archiving backend (through 2025-05-05) silently retains cleartext copies of messages sent by users of the TM SGNL (Archive Signal) app, despite TeleMessage documentation advertising end-to-end encryption from the mobile phone through to the corporate archive. This stems from hidden backend functionality (CWE-912) rather than a remotely triggerable code flaw, and it was exploited in the wild in May 2025. Anyone who can reach those backend message stores, such as an attacker who compromises TeleMessage's infrastructure or the customer-facing archive, gains access to plaintext copies of users' messages, a high confidentiality impact reflected in the CVSS 4.9 score (high privileges required, no integrity or availability impact). Organizations and personnel who used TM SGNL through 2025-05-05 for compliance archiving are affected, including regulated enterprises and government users of the service. CISA added the issue to its Known Exploited Vulnerabilities catalog on 2025-05-12 with no public proof-of-concept known, and EPSS estimates a 0.4% chance of exploitation in the next 30 days.

Do: Apply mitigations per TeleMessage vendor instructions and follow applicable CISA BOD 22-01 guidance for cloud services, discontinuing use of TM SGNL if mitigations are unavailable. Treat messages archived through 2025-05-05 as potentially stored in cleartext and review backend/archive access controls and logs for signs of unauthorized access. Federal agencies must remediate per the KEV catalog deadline (added 2025-05-12).

4.9<1% KEV
  • TeleMessage TM SGNL (Archive Signal) app with TeleMessage archiving backend (text message archiver) archiving backend through 2025-05-05
nicheunknown; plausibly on the order of thousands to tens of thousands of users across TeleMessage's enterprise and government compliance-archiving customer base
CVE-2025-47884
In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment varia

In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a trusted job, potentially gaining unauthorized access to external services.

NVD description · AI analysis pending
9.1<1%
  • jenkins openid connect provider
CVE-2025-47889
In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated

In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.

NVD description · AI analysis pending
9.8<1%
  • jenkins wso2 oauth
CVE-2025-4802
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).

NVD description · AI analysis pending
7.8<1% PoC
  • gnu glibc

Indicators of compromiseAll →

TypeIndicatorContext
domainblackdb.cclead administrator of BlackDB.cc from 2018 to the present. "BlackDB.cc illegally offered for sale compromised account and server c
Full article2,976 words · extracted from thehackernews.com · click to collapse

Cybersecurity leaders aren’t just dealing with attacks—they’re also protecting trust, keeping systems running, and maintaining their organization’s reputation. This week’s developments highlight a bigger issue: as we rely more on digital tools, hidden weaknesses can quietly grow.

Just fixing problems isn’t enough anymore—resilience needs to be built into everything from the ground up. That means better systems, stronger teams, and clearer visibility across the entire organization. What’s showing up now isn’t just risk—it’s a clear signal that acting fast and making smart decisions matters more than being perfect.

Here’s what surfaced—and what security teams can’t afford to overlook.

⚡ Threat of the Week

Microsoft Fixes 5 Actively Exploited 0-Days — Microsoft addressed a total of 78 security flaws in its Patch Tuesday update for May 2025 last week, out of which five of them have come under active exploitation in the wild. The vulnerabilities include CVE-2025-30397, CVE-2025-30400, CVE-2025-32701, CVE-2025-32706, and CVE-2025-32709. It's currently not known in what context these defects have been exploited, who is behind them, and who was targeted in these attacks.

🔔 Top News

  • Marbled Dust Exploits Output Messenger 0-Day — Microsoft revealed that a Türkiye-affiliated threat actor codenamed Marbled Dust exploited as zero-day a security flaw in an Indian enterprise communication platform called Output Messenger as part of a cyber espionage attack campaign since April 2024. The attacks, the company said, are associated with the Kurdish military operating in Iraq. The attacks exploited CVE-2025-27920, a directory traversal vulnerability affecting version 2.0.62 that allows remote attackers to access or execute arbitrary files. It was addressed in December 2024.
  • Konni APT Focuses on Ukraine in New Phishing Campaign — The North Korea-linked threat actor known as Konni APT has been attributed to a phishing campaign targeting government entities in Ukraine, indicating the threat actor's targeting beyond Russia amidst the ongoing Russo-Ukrainian war. Proofpoint, which disclosed details of the activity, said the objective of the attacks is to collect intelligence on the "trajectory of the Russian invasion." The attack chains entail the use of phishing emails that impersonate a fictitious senior fellow at a non-existent think tank, tricking recipients into visiting credential harvesting pages or downloading malware that can conduct extensive reconnaissance of the compromised machines.
  • Coinbase Discloses Data Breach — Cryptocurrency giant Coinbase disclosed that unknown cyber actors broke into its systems and stole account data for a small subset of its customers. The activity bribed its customer support agents based in India to obtain a list of customers, who were then approached as part of a social engineering attack to transfer their digital assets to a wallet under the threat actor's control. The attackers also unsuccessfully attempted to extort the company for $20 million on May 11, 2025, by claiming to have information about certain customer accounts as well as internal documents. The compromised agents have since been terminated. While no passwords, private keys, or funds were exposed, the attackers made away with some amount of personal information, including names, addresses, phone numbers, email addresses, government ID images, and account balances. Coinbase did not disclose how many of its customers fell for the scam. Besides voluntarily reimbursing retail customers who were duped into sending cryptocurrency to scammers, Coinbase is offering a $20 million reward to anyone who can help identify and bring down the perpetrators of the cyber attack.
  • APT28 Behind Attacks Targeting Webmail Services — APT28, a hacking group linked to Russia's Main Intelligence Directorate (GRU), has been targeting webmail servers such as Roundcube, Horde, MDaemon, and Zimbra via cross-site scripting (XSS) vulnerabilities. The attacks, ongoing since at least 2023, targeted governmental entities and defense companies in Eastern Europe, although governments in Africa, Europe, and South America were also singled out. The victims in 2024 alone included officials from regional national governments in Ukraine, Greece, Cameroon and Serbia, military officials in Ukraine and Ecuador, and employees of defense contracting firms in Ukraine, Romania and Bulgaria. The group's spear-phishing campaign used fake headlines mimicking prominent Ukrainian news outlets like the Kyiv Post about the Russia-Ukraine war, seemingly in an attempt to entice targets into opening the messages using the affected webmail clients. Those who opened the email messages using the affected webmail clients were served, via the XSS flaws, a custom JavaScript payload capable of exfiltrating contacts and email data from their mailboxes. One of the payloads could steal passwords and two-factor authentication codes, allowing the attackers to bypass account protections. The malware is also designed to harvest the email credentials, either by tricking the browser or password manager into pasting those credentials into a hidden form or getting the user to log out, whereupon they were served a bogus login page.
  • Earth Ammit Breaches Drone Supply Chains to Target Taiwan and South Korea — The threat actor known as Earth Ammit targeted a broader range of organizations than just Taiwanese drone manufacturers, as initially supposed. While the set of attacks was believed to be confined to drone manufacturers in Taiwan, a subsequent analysis has uncovered that the campaign is more broader and sustained in scope than previously thought, hitting the heavy industry, media, technology, software services, healthcare, satellite, and military-adjacent supply chains, and payment service providers in both South Korea and Taiwan. The attacks targeted software vendors and service providers as a way to reach their desired victims, who were the vendors' downstream customers. "Earth Ammit's strategy centered around infiltrating the upstream segment of the drone supply chain. By compromising trusted vendors, the group positioned itself to target downstream customers – demonstrating how supply chain attacks can ripple out and cause broad, global consequences," Trend Micro noted. "Earth Ammit's long-term goal is to compromise trusted networks via supply chain attacks, allowing them to target high-value entities downstream and amplify their reach."

‎️‍🔥 Trending CVEs

Attackers love software vulnerabilities—they’re easy doors into your systems. Every week brings fresh flaws, and waiting too long to patch can turn a minor oversight into a major breach. Below are this week's critical vulnerabilities you need to know about. Take a look, update your software promptly, and keep attackers locked out.

This week’s list includes — CVE-2025-30397, CVE-2025-30400, CVE-2025-32701, CVE-2025-32706, CVE-2025-32709 (Microsoft Windows), CVE-2025-42999 (SAP NetWeaver), CVE-2024-11182 (MDaemon), CVE-2025-4664 (Google Chrome), CVE-2025-4632 (Samsung MagicINFO 9 Server), CVE-2025-32756 (Fortinet FortiVoice, FortiMail, FortiNDR, FortiRecorder, and FortiCamera), CVE-2025-4427, CVE-2025-4428 (Ivanti Endpoint Manager Mobile), CVE-2025-3462, CVE-2025-3463 (ASUS DriverHub), CVE-2025-47729 (TeleMessage TM SGNL), CVE-2025-31644 (F5 BIG-IP), CVE-2025-22249 (VMware Aria Automation), CVE-2025-27696 (Apache Superset), CVE-2025-4317 (TheGem WordPress theme), CVE-2025-23166 (Node.js), CVE-2025-47884 (Jenkins OpenID Connect Provider Plugin), CVE-2025-47889 (Jenkins WSO2 Oauth Plugin), CVE-2025-4802 (Linux glibc), and CVE-2025-47539 (Eventin plugin).

📰 Around the Cyber World

  • Attackers Leverage PyInstaller to Drop Infostealers on Macs — Attackers are using PyInstaller to deploy information stealers on macOS systems. These ad-hoc signed samples bundle Python code into Mach-O executables using PyInstaller, allowing them to be run without requiring Python to be installed or meet version compatibility requirements. "As infostealers continue to become more prevalent in the macOS threat landscape, threat actors will continue the search for new ways to distribute them," Jamf said. "While the use of PyInstaller to package malware is not uncommon, this marks the first time we've observed it being used to deploy an infostealer on macOS."
  • Kosovo National Extradited to the U.S. for Running BlackDB.cc — A 33-year-old Kosovo national named Liridon Masurica has been extradited to the United States to face charges of running an online cybercrime marketplace active since 2018. He has been charged with five counts of fraudulent use of unauthorized access devices and one count of conspiracy to commit access device fraud. If convicted on all counts, Masurica faces a maximum penalty of 55 years in federal prison. He was taken into custody by authorities in Kosovo on December 12, 2024. Masurica is alleged to be the lead administrator of BlackDB.cc from 2018 to the present. "BlackDB.cc illegally offered for sale compromised account and server credentials, credit card information, and other personally identifiable information of individuals primarily located in the United States," the Justice Department said. "Once purchased, cybercriminals used the items purchased on BlackDB.cc to facilitate a wide range of illegal activity, including tax fraud, credit card fraud, and identity theft."
  • Former BreachForums Admin to Pay $700k in Healthcare Breach — Conor Brian Fitzpatrick, aka Pompompurin, a former administrator of the BreachForums cybercrime forum, will forfeit roughly $700,000 in a civil lawsuit settlement related to Nonstop Health, a health insurance company whose customer data was posted for sale on the forum in 2023. Fitzpatrick was sentenced to time served last year, but he went on to violate the terms of his release. He is set to be resentenced next month.
  • Tor Announces Oniux for Kernel-Level Tor Isolation — The Tor project has announced a new command-line utility called oniux that provides Tor network isolation for third-party applications using Linux namespaces. This effectively creates a fully isolated network environment for each application, preventing data leaks even if the app is malicious or misconfigured. "Built on Arti, and onionmasq, oniux drop-ships any Linux program into its own network namespace to route it through Tor and strips away the potential for data leaks," the Tor project said. "If your work, activism, or research demands rock-solid traffic isolation, oniux delivers it."
  • DoJ Charges 12 More in RICO Conspiracy — The U.S. Department of Justice announced charges against 12 more people for their alleged involvement in a cyber-enabled racketeering conspiracy throughout the United States and abroad that netted them more than $263 million. Several of these individuals are said to have been arrested in the U.S., with two others living in Dubai. They face charges related to RICO conspiracy, conspiracy to commit wire fraud, money laundering, and obstruction of justice. The defendants are also accused of stealing over $230 million in cryptocurrency from a victim in Washington D.C. "The enterprise began no later than October 2023 and continued through March 2025," the Justice Department said. "It grew from friendships developed on online gaming platforms. Members of the enterprise held different responsibilities. The various roles included database hackers, organizers, target identifiers, callers, money launderers, and residential burglars targeting hardware virtual currency wallets." The attacks involved database hackers breaking into websites and servers to obtain cryptocurrency-related databases or acquiring databases on the dark web. The miscreants then determined the most valuable targets and cold-called them, using social engineering to convince them their accounts were the subject of cyber attacks and that they were helping them take steps to secure their accounts. The end goal of these attacks was to siphon the cryptocurrency assets, which were then laundered and converted into fiat U.S. currency in the form of bulk cash or wire transfers. The money was then used to fund a lavish lifestyle for the defendants. "Following his arrest in September 2024 and continuing while in pretrial detention, Lam is alleged to have continued working with members of the enterprise to pass and receive directions, collect stolen cryptocurrency, and have enterprise members buy luxury Hermes Birkin bags and hand-deliver them to his girlfriend in Miami, Florida," the agency said.
  • ENISA Launches EUVD Vulnerability Database — The European Union launched a new vulnerability database called the European Vulnerability Database (EUVD) to provide aggregated information regarding security issues affecting various products and services. "The database provides aggregated, reliable, and actionable information such as mitigation measures and exploitation status on cybersecurity vulnerabilities affecting Information and Communication Technology (ICT) products and services," the European Union Agency for Cybersecurity (ENISA) said. The development comes in the wake of uncertainty over MITRE's CVE program in the U.S., after which the U.S. Cybersecurity and Infrastructure Security Agency (CISA) stepped in at the last minute to extend their contract with MITRE for another 11 months to keep the initiative running.
  • 3 Information Stealers Detected in the Wild — Cybersecurity researchers have exposed the workings of three different information stealer malware families, codenamed DarkCloud Stealer, Chihuahua Stealer, and Pentagon Stealer, that are capable of extracting sensitive data from compromised hosts. While DarkCloud has been advertised in hacking forums as early as January 2023, attacks distributing the malware have primarily focused on government organizations since late January 2025. DarkCloud is distributed as AutoIt payloads via phishing emails using PDF purchase order lures that display a message claiming their Adobe Flash Player is out of date. Chihuahua Stealer, on the other hand, is a .NET-based malware that employs an obfuscated PowerShell script shared through a malicious Google Drive document. First discovered in March 2025, Pentagon Stealer makes use of Golang to realize its goals. However, a Python variant of the same stealer was detected at least a year prior when it was propagated via fake Python packages uploaded to the PyPI repository.
  • Kaspersky Outlines Malware Trends for Industrial Systems in Q1 2025 — Kaspersky revealed that the percentage of ICS computers on which malicious objects were blocked in Q1 2025 remained unchanged from Q4 2024 at 21.9%. "Regionally, the percentage of ICS computers on which malicious objects were blocked ranged from 10.7% in Northern Europe to 29.6% in Africa," the Russian security company said. "The biometrics sector led the ranking of the industries and OT infrastructures surveyed in this report in terms of the percentage of ICS computers on which malicious objects were blocked." The primary categories of detected malicious objects included malicious scripts and phishing pages, denylisted internet resources, and backdoors, and keyloggers.
  • Linux Flaws Surge by 967% in 2024 — The number of newly discovered Linux and macOS vulnerabilities increased dramatically in 2024, rising by 967% and 95% in 2024. The year was also marked by a 96% jump in exploited vulnerabilities from 101 in 2023 to 198 in 2024, and an unprecedented 37% rise in critical flaws across key enterprise applications. "The total number of software vulnerabilities grew by 61% YoY in 2024, with critical vulnerabilities rising by 37.1% – a significant expansion of the global attack surface and exposure of critical weaknesses across diverse software categories," Action1 said. "Exploits spiked 657% in browsers and 433% in Microsoft Office, with Chrome leading all products in known attacks." But in a bit of good news, there was a decrease in remote code execution vulnerabilities for Linux (-85% YoY) and macOS (-44% YoY).
  • Europol Announces Takedown of Fake Trading Platform — Law enforcement authorities have disrupted an organized crime group that's assessed to be responsible for defrauding more than 100 victims of over €3 million ($3.4 million) through a fake online investment platform. The effort, a joint exercise conducted by Germany, Albania, Cyprus, and Israel, has also led to the arrest of a suspect in Cyprus. "The criminal network lured victims with the promise of high returns on investments through a fraudulent online trading platform," Europol said. "After the victims made initial smaller deposits, they were pressured to invest larger amounts of money, manipulated by fake charts showing fabricated profits. Criminals posing as brokers used psychological tactics to convince the victims to transfer substantial funds, which were never invested but directly pocketed by the group." Two other suspects were previously arrested from Latvia in September 2022 as part of the multi-year probe into the criminal network.
  • New "defendnot" Tool Can Disable Windows Defender — A security researcher who goes by the online alias es3n1n has released a tool called "defendnot" that can disable Windows Defender by means of a little-known API. "There's a WSC (Windows Security Center) service in Windows which is used by antiviruses to let Windows know that there's some other antivirus in the hood and it should disable Windows Defender," the researcher explained. "This WSC API is undocumented and furthermore requires people to sign an NDA with Microsoft to get its documentation."
  • Rogue Communication Devices Found in Some Chinese Solar Power Inverters — Reuters reported that U.S. energy officials are reassessing the risk posed by Chinese-made solar power inverters after unexplained communication equipment was found inside some of them. The rogue components are designed to provide additional, undocumented communication channels that could allow firewalls to be circumvented remotely, according to two people familiar with the matter. This could then be used to switch off inverters remotely or change their settings, enabling bad actors to destabilize power grids, damage energy infrastructure, and trigger widespread blackouts. Undocumented communication devices, including cellular radios, have also been found in some batteries from multiple Chinese suppliers, the report added.
  • Israel Arrest Suspect Behind 2022 Nomad Bridge Crypto Hack — Israeli authorities have arrested and approved the extradition of a Russian-Israeli dual national Alexander Gurevich over his alleged involvement in the Nomad Bridge hack in August 2022 that allowed hackers to steal $190 million. Gurevich is said to have conspired with others to execute an exploit for the bridge's Replica smart contract and launder the resulting proceeds through a sophisticated, multi-layered operation involving privacy coins, mixers, and offshore financial entities. "Gurevich played a central role in laundering a portion of the stolen funds. Blockchain analysis shows that wallets linked to Gurevich received stolen assets within hours of the bridge breach and began fragmenting the funds across multiple blockchains," TRM Labs said. "He then employed a classic mixer stack: moving assets through Tornado Cash on Ethereum, then converting ETH to privacy coins such as Monero (XMR) and Dash."
  • Using V8 Browser Exploits to Bypass WDAC — Researchers have uncovered a sophisticated technique that leverages vulnerable versions of the V8 JavaScript engine to bypass Windows Defender Application Control (WDAC). "The attack scenario is a familiar one: bring along a vulnerable but trusted binary, and abuse the fact that it is trusted to gain a foothold on the system," IBM X-Force said. "In this case, we use a trusted Electron application with a vulnerable version of V8, replacing main.js with a V8 exploit that executes stage 2 as the payload, and voila, we have native shellcode execution. If the exploited application is whitelisted/signed by a trusted entity (such as Microsoft) and would normally be allowed to run under the employed WDAC policy, it can be used as a vessel for the malicious payload." The technique builds upon previous findings that make it possible to sidestep WDAC policies by backdooring trusted Electron applications. Last month, CerberSec detailed another method that employs WinDbg Preview to get around WDAC policies.

🎥 Cybersecurity Webinars

DevSecOps Is Broken — This Fix Connects Code to Cloud to SOC

Modern applications don’t live in one place—they span code, cloud, and runtime. Yet security is still siloed. This webinar shows why securing just the code isn’t enough. You’ll learn how unifying AppSec, cloud, and SOC teams can close critical gaps, reduce response times, and stop attacks before they spread. If you’re still treating dev, infra, and operations as separate problems, it’s time to rethink.

🔧 Cybersecurity Tools

  • Qtap It is a lightweight eBPF tool for Linux that shows what data is being sent and received—before or after encryption—without changing your apps or adding proxies. It runs with minimal overhead and captures full context like process, user, and container info. Useful for auditing, debugging, or analyzing app behavior when source code isn’t available.
  • Checkov It is a fast, open-source tool that scans infrastructure-as-code and container packages for misconfigurations, exposed secrets, and known vulnerabilities. It supports Terraform, Kubernetes, Docker, and more—using built-in security policies and Sigma-style rules to catch issues early in the development process.
  • TrailAlerts It is a lightweight, serverless AWS-native tool that gives you full control over CloudTrail detections using Sigma rules—without needing a SIEM. It’s ideal for teams who want to write, version, and manage their own alert logic as code, but find CloudWatch rules too limited or complex. Built entirely on AWS services like Lambda, S3, and DynamoDB, TrailAlerts lets you detect suspicious activity, correlate events, and send alerts through SNS or SES—without managing infrastructure or paying for unused capacity.

🔒 Tip of the Week

Catch Hidden Threats in Files Users Trust Too Much → Hackers are using a quiet but dangerous trick: hiding malicious code inside files that look safe — like desktop shortcuts, installer files, or web links. These aren’t classic malware files. Instead, they run trusted apps like PowerShell or curl in the background, using basic user actions (like opening a file) to silently infect systems. These attacks often go undetected because the files seem harmless, and no exploits are used — just misuse of normal features.

To detect this, focus on behavior. For example, .desktop files in Linux that run hidden shell commands, .lnk files in Windows launching PowerShell or remote scripts, or macOS .app files silently calling terminal tools. These aren’t rare anymore — attackers know defenders often ignore these paths. They’re especially dangerous because they don’t need admin rights and are easy to hide in shared folders or phishing links.

You can spot these threats using free tools and simple rules. On Windows, use Sysmon and Sigma rules to alert on .lnk files starting PowerShell or suspicious child processes from explorer.exe. On Linux or macOS, use grep or find to scan .desktop and .plist files for odd execution patterns. To test your defenses, simulate these attack paths using MITRE CALDERA — it’s free and lets you safely model real-world attacker behavior. Focusing on these overlooked execution paths can close a major gap attackers rely on every day.

Conclusion

The headlines may be over, but the work isn’t. Whether it’s rechecking assumptions, prioritizing patches, or updating your response playbooks, the right next step is rarely dramatic—but always decisive. Choose one, and move with intent.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/05/weekly-recap-zero-day-exploits-insider.html