Week in review: Probing activity on Palo Alto Networks GlobalProtect portals, Patch Tuesday forecast
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-20439 | Undocumented Static Admin Credential in Cisco Smart Licensing Utility Cisco Smart Licensing Utility (CSLU) contains an undocumented, hardcoded administrative credential that allows an unauthenticated, remote attacker to log in to the application. The flaw is triggered simply by authenticating over the network with the static credential, with no user interaction or special conditions required, consistent with its 9.8 (critical) CVSS network/low-complexity score. A successful attacker gains administrative rights over the CSLU application API, which organizations use to manage Cisco smart licensing from a local host. Any organization running CSLU is affected; because the utility is typically installed on internal management hosts rather than exposed directly to the internet, the reachable footprint is likely limited, though exact install counts are not published. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-31, its EPSS of 92.1% sits in the 100th percentile, and Cisco patched it in the same release as a second critical CSLU vulnerability. Do: Upgrade CSLU to the fixed release published in Cisco's security advisory, which addresses this static-credential flaw and a second critical CSLU vulnerability patched in the same update. Inventory your estate for CSLU installations — especially any with the application API reachable from untrusted networks — and restrict access to trusted management segments. Because exploitation relies on a known static credential, treat prior API access as potentially attacker-controlled and review the host for unauthorized logins or configuration changes. | 9.8 | 92% | KEV |
| moderatelikely on the order of tens of thousands of enterprise installations worldwide, with only a small (low-thousands) subset internet-exposed (estimate) | |
| CVE-2025-0282 | Unauthenticated RCE in Ivanti Connect Secure, Policy Secure, and ZTA Gateways CVE-2025-0282 is a stack-based buffer overflow (CWE-121) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways, reachable by unauthenticated network input. An attacker can trigger it remotely by sending crafted, unauthenticated traffic to a vulnerable gateway, overwriting stack memory and gaining code execution under the appliance's context. Successful exploitation yields unauthenticated remote code execution on the device, giving the attacker control of the VPN/secure-access gateway and a foothold into the protected network. Organizations running any of the affected Ivanti secure-access products are exposed; the source data specifies no version ranges, so defenders should consult Ivanti's advisory for exact affected and fixed releases. The flaw is being actively exploited: it was added to CISA KEV on 2025-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), despite no public PoC being known. Do: Apply the patched releases identified in Ivanti's advisory and follow CISA's required action: hunt for signs of compromise, remediate if indicators are found, and apply updates before returning any device to service. Because exploitation is active and ransomware use is known, treat any appliance that was internet-reachable before patching as potentially compromised (check integrity, rotate credentials). Exact fixed versions were not included in the source data, so verify the correct update path for your branch (including older Connect Secure/Policy Secure releases) against Ivanti's bulletin. | 9.0 | 100% | KEV ransomware PoC ×3 |
| largetens of thousands of internet-exposed appliances (likely 100,000+ total deployments including internal-only gateways) | |
| CVE-2025-22457 | Unauthenticated Stack Buffer Overflow RCE in Ivanti Connect Secure Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow (CWE-121) that can be triggered by a remote, unauthenticated attacker sending crafted input that overruns a fixed-size stack buffer on the affected gateway. Successful exploitation yields remote code execution on the appliance, giving an attacker control of an enterprise VPN or zero-trust access gateway and a foothold in the surrounding network. Any organization running the affected Ivanti gateway products is exposed, with impact concentrated among enterprises using these appliances for remote-access VPN and zero-trust network access. The vulnerability was added to CISA's KEV catalog on 2025-04-04 with known ransomware use, and its maximum EPSS score (100.0%, 100th percentile) signals near-certain exploitation pressure within 30 days. No public proof-of-concept is known, but confirmed in-the-wild exploitation makes this an actively abused, high-priority flaw. Do: Apply the mitigations required by CISA and update Connect Secure, Policy Secure, and ZTA Gateways to the patched releases designated in Ivanti's advisory, prioritizing internet-exposed VPN gateways. Given known ransomware use, review appliance and downstream logs for signs of compromise, and treat unpatched gateways as high risk given the 100th-percentile EPSS score. | 9.8 | 100% | KEV ransomware |
| largetens of thousands of deployed gateways, with on the order of 10k-100k internet-exposed appliances | |
| CVE-2025-2825 | Rejected reason: DO NOT USE THIS CVE RECORD. Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-31161. Reason: This Record is a reservation duplicate of CVE-2025-31161. Notes: All CVE users should reference CVE-2025-31161 instead of this Record. All references and descriptions in this Record have been removed to prevent accidental usage. NVD description · AI analysis pending | — | — | — | — |
Full article1,203 words · extracted from helpnetsecurity.com · click to collapse

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:
Attackers are probing Palo Alto Networks GlobalProtect portals
Cybersecurity company GreyNoise is warning about a significant increase of scanning activity targeting internet-facing Palo Alto Networks GlobalProtect portals in the last 30 days, and has urged organizations with exposed systems to secure them and look for signs of compromise.
April 2025 Patch Tuesday forecast: More AI security introduced by Microsoft
Microsoft is continuing to build on their AI cybersecurity strategy and this month announced the introduction of new agents in Microsoft Security Copilot. They are introducing agents for phishing triage, alert triage for data loss prevention and insider risk management, conditional access optimization, vulnerability remediation, and threat intelligence briefing.
Forward-thinking CISOs are shining a light on shadow IT
In this Help Net Security interview, Curtis Simpson, CISO and Chief Advocacy Officer at Armis, discusses how CISOs can balance security and innovation while managing the risks of shadow IT.
Ivanti VPN customers targeted via unrecognized RCE vulnerability (CVE-2025-22457)
A suspected Chinese APT group has exploited CVE-2025-22457 – a buffer overflow bug that was previously thought not to be exploitable – to compromise appliances running Ivanti Connect Secure (ICS) 22.7R2.5 or earlier or Pulse Connect Secure 9.1x.
Building a cybersecurity strategy that survives disruption
Cybersecurity used to focus primarily on prevention. But in today’s environment, that’s not enough. That’s where cyber resilience comes in.
Attackers are leveraging Cisco Smart Licensing Utility static admin credentials (CVE-2024-20439)
CVE-2024-20439, a static credential vulnerability in the Cisco Smart Licensing Utility, is being exploited by attackers in the wild, CISA has confirmed on Monday by adding the flaw to its Known Exploited Vulnerabilities catalog.
Review: Zero to Engineer
Zero to Engineer is a practical guide for anyone looking to launch a career in information technology without a traditional college degree.
Phishers are increasingly impersonating electronic toll collection companies
Steam was the most imitated brands by phishers in the first quarter of 2025, followed by Microsoft and Facebook/Meta, Guardio researchers have revealed.
Balancing data protection and clinical usability in healthcare
In this Help Net Security interview, Aaron Weismann, CISO at Main Line Health, discusses the growing ransomware threat in healthcare and why the sector remains a prime target.
Google is making sending end-to-end encrypted emails easy
Sending end-to-end encrypted (E2EE) emails from Gmail enterprise accounts is about to become much easier than it is now, Google has announced on Tuesday.
BlueToolkit: Open-source Bluetooth Classic vulnerability testing framework
BlueToolkit is an open-source tool that helps find security flaws in Bluetooth Classic devices. It runs known and custom exploits to test if a device is vulnerable.
North Korean IT workers set their sights on European organizations
North Korean IT workers are expanding their efforts beyond the US, and are seeking to fraudulently gain employment with organizations around the world, but most especially in Europe.
Why global tensions are a cybersecurity problem for every business
With global tensions climbing, cyber attacks linked to nation-states and their allies are becoming more common, sophisticated, and destructive.
Attackers are targeting CrushFTP vulnerability with public PoC (CVE-2025-2825)
Exploitation attempts targeting the CVE-2025-2825 vulnerability on internet-facing CrushFTP instances are happening, the Shadowserver Foundation has shared on Monday, and the attackers have been leveraging publicly available PoC exploit code.
Generative AI is reshaping financial fraud. Can security keep up?
In this Help Net Security interview, Yinglian Xie, CEO at DataVisor, explains how evolving fraud tactics require adaptive, AI-driven prevention strategies.
CISA reveals new malware variant used on compromised Ivanti Connect Secure devices
CISA has released indicators of compromise, detection signatures, and updated mitigation advice for rooting out a newly identified malware variant used by the attackers who breached Ivanti Connect Secure VPN appliances in December 2024 by exploiting the CVE-2025-0282 zero-day.
Exegol: Open-source hacking environment
Exegol is a community-driven hacking environment, which helps users deploy hacking setups quickly and securely.
Windows 11 quick machine recovery: Restoring devices with boot issues
Microsoft has rolled out quick machine recovery, a new Windows feature aimed at preventing prolonged widespread outages like the one caused by a faulty CrowdStrike update in July 2024.
7 ways to get C-suite buy-in on that new cybersecurity tool
Convincing leadership, especially those more attuned to balance sheets than breach reports, can feel like selling a Wi-Fi router to someone without any internet connection. Securing buy-in is not just a technical challenge. It’s a game of strategy, storytelling, and persuasion.
Inside the AI-driven threat landscape
In this Help Net Security video, Nick Barter, Chief Strategy Officer at Nothreat, discusses how AI is no longer just a tool for defenders, it’s now a powerful weapon in the hands of attackers
How to map and manage your cyber attack surface with EASM
Security specialists generally define the attack surface as the sum of all possible points in a system or network where attacks can be launched against. In other words, it can be described as the sum of all potential attack vectors
GenAI turning employees into unintentional insider threats
The amount of data being shared by businesses with GenAI apps has exploded, increasing 30x in one year, according to Netskope.
How to build an effective cybersecurity simulation
What should organizations actively do to make these simulations as real and valuable as possible?
Only 2-5% of application security alerts require immediate action
The large volume of security alerts, many created by automated tools, is overwhelming security and development teams, according to the 2025 Application Security Benchmark report by Ox Security.
Two things you need in place to successfully adopt AI
Organizations should not shy away from taking advantage of AI tools, but they need to find the right balance between maximizing efficiency and mitigating organizational risk.
Building a reasonable cyber defense program
In this article, we’ll identify and discuss several policy elements you can incorporate into your cybersecurity program that meet the standard of reasonableness.
Connected cars drive into a cybersecurity crisis
The very fact that someone can hack a vehicle and take control of it is terrifying, turning scenarios from movies into reality.
Your smart home may not be as secure as you think
In this article, we explore the security challenges of smart IoT devices in the home, potential threats like hacking and privacy breaches, and measures users can take to ensure the security of their connected devices.
The human side of insider threats: People, pressure, and payback
While cybercriminals are often in the spotlight, one of the most dangerous threats to your company might be hiding in plain sight, within your own team.
How to recognize and prevent deepfake scams
Deepfakes are a type of synthetic media created using AI and machine learning. In simple terms, they produce videos, images, audio, or text that look and sound real, even though the events depicted never actually happened.
Cybersecurity jobs available right now: April 1, 2025
We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now.
New infosec products of the week: April 4, 2025
Here’s a look at the most interesting products from the past week, featuring releases from 1touch.io, Bitsight, Bluefin, CyberQP, and Exabeam.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/04/06/week-in-review-probing-activity-on-palo-alto-networks-globalprotect-portals-patch-tuesday-forecast/