ZeroHour
Recorded Futurepublished ()ingested Levi Gundert1

Rate My Rizz: Elevating Cyber Resilience Beyond Compliance

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-42013
Path Traversal and RCE in Apache HTTP Server (follow-up to CVE-2021-41773)

Apache HTTP Server contains a path traversal flaw (CWE-22) that can lead to remote code execution; CVE-2021-42013 resolves an incomplete patch previously issued for CVE-2021-41773. The flaw is triggered when files outside directories mapped by Alias-like directives are not protected by the default 'require all denied' configuration, or when CGI scripts are enabled, allowing an attacker to traverse outside the intended directory roots. An attacker can read files outside the configured paths, and where CGI script execution is enabled, achieve remote code execution on the server. The affected product per CISA is Apache HTTP Server; the source data does not specify exact version ranges, so defenders should consult the vendor advisory for fixed releases. Exploitation is confirmed in the wild: the vulnerability was added to CISA KEV on 2021-11-03 with known ransomware use, EPSS estimates a 100% probability of exploitation within 30 days, and no public PoC is listed.

Do: Apply the Apache HTTP Server update per vendor instructions immediately, since this is a CISA KEV item with known ransomware use and near-certain near-term exploitation. Until patched, ensure directories targeted by Alias-like directives are covered by 'require all denied' defaults and disable CGI script execution where it is not required. Review access logs for path traversal probes and confirm no replaced version retains the incomplete earlier patch.

9.8100% KEV ransomware PoC ×6
  • Apache HTTP Server
massorder of 100,000+ internet-exposed Apache HTTP Server instances at disclosure time
CVE-2025-24200
Incorrect Authorization in Apple iOS/iPadOS Lets Attackers Disable USB Restricted Mode

CVE-2025-24200 is an incorrect authorization flaw (CWE-863) in Apple iOS and iPadOS, caused by an authorization issue in state management that Apple resolved with improved state handling. An attacker with brief physical access to a locked device can exploit the flaw to disable USB Restricted Mode, the feature that locks down a locked iPhone or iPad's USB data port against accessories after a set period. This allows USB accessories, including data-extraction and attack peripherals, to communicate with the device while it remains locked, with a high confidentiality and integrity impact (CVSS 6.1, physical attack vector). Any iPhone or iPad user running a version prior to the applicable fixed release is affected, with fixes shipped in iOS 15.8.4, iOS 16.7.11, iOS 18.3.1, iPadOS 15.8.4, iPadOS 16.7.11, iPadOS 17.7.5, and iPadOS 18.3.1. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-12.

Do: Update iPhones to iOS 15.8.4, iOS 16.7.11, or iOS 18.3.1 and iPads to iPadOS 15.8.4, 16.7.11, 17.7.5, or 18.3.1 as applicable to each device's branch, checking Settings > General > Software Update for unmanaged devices. Because exploitation requires physical access, prioritize high-risk users (executives, journalists, government personnel), confirm no fleet devices remain on unpatched builds, and avoid untrusted USB accessories and charging ports until updated. CISA's KEV listing requires federal agencies to apply the vendor patch per the required action or discontinue use of the product.

6.14% KEV
  • Apple iOS (iPhone) Versions prior to the fixed releases in each branch: iOS < 15.8.4, iOS < 16.7.11, and iOS < 18.3.1
  • Apple iPadOS (iPad) Versions prior to the fixed releases in each branch: iPadOS < 15.8.4, iPadOS < 16.7.11, iPadOS < 17.7.5, and iPadOS < 18.3.1
mass≈1 billion+ devices (Apple's active installed base; every iPhone/iPad running a pre-patch iOS/iPadOS release at the time of disclosure)
CVE-2025-26633
Local Security Feature Bypass in Microsoft Windows Management Console (MMC)

Microsoft Windows Management Console (MMC) contains an improper neutralization flaw (CWE-707) that allows an unauthorized attacker to bypass a security feature locally. It is triggered when MMC processes specially crafted input during local use, letting the attacker sidestep a built-in Windows security control. The attacker gains evasion of that security feature, which is most valuable as one stage of a broader attack chain rather than as a standalone compromise. Virtually any organization running affected Microsoft Windows releases is affected, since MMC ships with Windows by default. The flaw is already being exploited in the wild: CISA added it to the KEV catalog on 2025-03-11 with known ransomware use, and EPSS places its 30-day exploitation probability at 30.4% (98th percentile), though no public proof-of-concept is known.

Do: Apply Microsoft's security updates per vendor instructions as required under CISA KEV/BOD 22-01, prioritizing this patch given known ransomware use and the KEV deadline. Inventory Windows endpoints and servers for patch status and hunt for anomalous MMC execution until updates are applied; for cloud services, follow applicable BOD 22-01 guidance, and discontinue or mitigate use where patches are unavailable.

7.030% KEV ransomware PoC ×2
  • Microsoft Windows
mass1 billion+ Windows installations (MMC is a default Windows component)
CVE-2025-29824
Use-After-Free Privilege Escalation in Microsoft Windows CLFS Driver (Actively Exploited)

CVE-2025-29824 is a use-after-free flaw (CWE-416) in the Windows Common Log File System (CLFS) kernel driver, scored 7.8 (High) with a local attack vector, low privileges required, and no user interaction. An authorized local attacker can trigger it by interacting with CLFS-managed log files in a way that references freed kernel memory. Successful exploitation elevates the attacker's local privileges, typically to SYSTEM, providing full control of the host that can be chained into ransomware deployment or lateral movement. Any unpatched system running the listed Windows 10, Windows 11, or Windows Server versions is affected. The flaw was exploited as a zero-day — reportedly by Play ransomware — before Microsoft shipped fixes in the April 2025 Patch Tuesday release; it was added to CISA's KEV catalog on 2025-04-08 with known ransomware use, and EPSS estimates a 13.9% probability of continued exploitation over 30 days (96th percentile).

Do: Apply Microsoft's April 2025 Patch Tuesday security updates for your Windows version immediately — the vendor update is the only complete fix, and the flaw is on the KEV list with known ransomware use, so prioritize servers and endpoints used by privileged users. Until patched, limit untrusted local code execution and review hosts for post-exploitation privilege escalation; public detection and mitigation scripts (e.g., Vicarius) are available to help hunt for exploitation. Federal agencies must apply the vendor mitigations per BOD 22-01 deadlines or discontinue use of affected versions.

7.814% KEV ransomware PoC ×2
  • microsoft Windows 10 1507 1507
  • microsoft Windows 10 1607 1607
  • microsoft Windows 10 1809 1809
  • +9 more
massHundreds of millions of Windows devices worldwide
Full article872 words · extracted from recordedfuture.com · click to collapse

RSA is always a good opportunity to reconnect with industry friends—2025 was no exception. Beneath the marketing avalanche of “AI-enabled everything,” one theme stuck out in conversations with CISOs and defensive leaders: the mounting time and energy spent on cyber audits, reporting, and remediation.

These Enterprise Risk Management (ERM) and Governance, Risk, and Compliance (GRC) efforts are especially demanding in regulated industries. But with mandates like NIS2 and DORA taking effect in Europe—and domestic frameworks like SOX, SOC2, and CMMC still in play—security leaders are spending more time with audit committees than ever before.

Compliance Theater: Starring the Risk Register

In enterprises, defensive resource allocations are often adjudicated by committees and measured by audit progress and the almighty risk register. This means most of the attention (and budget) aligns with avoiding one specific risk: legal or compliance failure (LCF). It’s no surprise that CISOs are often left with a single 15-minute slot each year to brief the board on the other four cyber risk impacts. That’s a missed opportunity.

Board presentation produced by ChatGPT 4o.

Boards need to better understand cyber risk beyond compliance. The “state of rizz” (resilience) depends on more than audit checklists. Point-in-time audits work well for demonstrating regulatory due diligence. If something goes wrong, but the virtual paperwork shows that policies were followed and corrections made, enforcement actions can often be minimized or avoided.

That’s not true for the other risk impacts—operational disruption, financial fraud, brand impairment, and competitive disadvantage. Even after clean audits, the residual risk across these domains remains. Boards need to grasp this difference. And CISOs must continue translating technical risk into business language that supports resilience conversations.

Measuring Rizz: Easier Said Than Sustained

Communicating rizz is momentary. Measuring it is constant. Organizations spend heavily to prevent all five impacts, but security investments tied to non-compliance impacts often receive less scrutiny (ROSI). That’s where control validation comes in.

Sankey diagram depicting threat categories leading to multiple possible risk impacts. Code produced with ChatGPT o3 and Claude-3.7-sonnet.

Looking ahead (meaning, likely six months from now), AI agents will monitor and challenge other AI agents in continuous loops of control testing and remediation, especially as adversary TTPs evolve daily.

The Automation Angle: Purple Teams and Silver Bullets

Until then, automation in purple teaming, breach and attack simulation (BAS), and exposure validation is the best way to scale defenses without burning out staff.

A growing number of vendors (like Picus) offer automated testing platforms with user-friendly workflows. These platforms aren’t silver bullets, but they help CISOs tell a better executive story.

A silver bullet produced by ChatGPT 4o.

Consider Business Email Compromise (BEC). GRC will enforce controls like phishing simulations and financial separation of duties to satisfy LCF (Limit Control Frameworks) requirements. But if the CISO is also emulating attacks and testing the actual tech stack—email gateways, MFA, IAM policies—the story becomes richer. It shows intentional, tested resilience across financial fraud risk, not just paper compliance. It’s far more compelling than: “We have an EDR as prescribed in our compliance framework.”

Real Rizz Moves: How Live Threat Emulation Beats Paper Promises

To make this real, draw from live TTPs observed in the wild. For example, within the past 90 days (as of May 14, 2025), Recorded Future’s AI Insights flagged dozens of events that could be used as fuel for BAS automation.

  • GitHub user winsecurity published AMSI-Bypass-HWBP, a lightweight debugger tool in Rust designed to evade Windows Antimalware Scan Interface (AMSI) detection.
  • ANY.RUN detailed a new information stealer called Zhong Stealer that targets the cryptocurrency and fintech sectors through social engineering tactics involving chat support systems.
  • @siri_urz shared a sample of DieStealer, indicating its capabilities of credential access and spyware functions.
  • Reports from Hunt.io indicated an intrusion campaign targeting South Korean organizations using Cobalt Strike Cat modified for exploitative purposes.
  • Kalman reported on a privilege escalation technique in GCP using IAM Conditions linked to tagBindings.
  • Check Point Research detailed a spearphishing campaign by APT29 utilizing GRAPELOADER malware against European diplomatic entities.
  • Insikt Group noted the discovery of CVE-2021-42013 scanning activities with overlaps found from Alibaba Cloud ISPs.
  • Quarkslab reported CVE-2025-24200 as an authorization bypass vulnerability in iOS and iPadOS, allowing physical access to disable USB Restricted Mode before Apple patched it.
  • Trend Micro highlighted EncryptHub's reliance on MSC EvilTwin loader exploiting CVE-2025-26633 as part of their custom malware arsenal.
  • IBM X-Force detailed a fileless lateral movement technique exploiting COM objects in Windows systems.
  • @tangent65536 shared Mimikatz binaries signed with legitimate certificates online.
  • Cato Networks reported the Ballista IoT botnet targeting TP-Link routers.
  • Coral Jasmine presented the LethalVoid RAT using malicious exfiltration methods via Discord webhooks and FTP.
  • ThreatFabric identified Crocodilus Android banking trojan targeting financial institutions.
  • Microsoft’s Threat Intelligence Center documented Storm-2460 ransomware’s introduction of PipeMagic malware exploiting CVE-2025-29824.
  • Morphisec Labs exposed new delivery techniques for ValleyRAT through phishing tactics.

Risk Registers Win Audits. Rizz Wins Crises.

If the board only sees traffic light audit checkmarks, they’re missing the real color of cyber risk. That’s why rizz narratives must move beyond compliance and into control validation and business risk translation—before the next threat does it for you.

The rizz game show produced by ChaptGPT 4o.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/rate-my-rizz