ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Half of Ransomware Access Due to Hijacked VPN Credentials

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-20333
Authenticated Buffer Overflow RCE in Cisco ASA/FTD VPN Web Server

CVE-2025-20333 is a buffer overflow (CWE-120) in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software, caused by improper validation of user-supplied input in HTTP(S) requests. An attacker who already holds valid VPN user credentials can trigger it by sending crafted HTTP(S) requests to the device's VPN web interface; the flaw is remotely exploitable over the network with low attack complexity and no user interaction. A successful exploit allows arbitrary code execution as root, possibly resulting in complete compromise of the firewall or VPN gateway. Any organization running Cisco ASA or FTD software with the VPN web server enabled is affected. Exploitation is confirmed in the wild: the CVE was added to CISA's KEV on 2025-09-25, EPSS assigns a 70.7% probability of exploitation within 30 days (99th percentile), and Cisco and the UK NCSC have warned of real-world attacks (including RayInitiator and LINE VIPER malware deployment) that chain this flaw with at least one companion Cisco vulnerability.

Do: Inventory all ASA/FTD devices with the VPN web server reachable by users (especially internet-exposed ones) and upgrade to the fixed releases listed in the Cisco PSIRT advisory; where patching is delayed, apply Cisco's recommended mitigations and hunt for indicators of the reported attack chain (RayInitiator/LINE VIPER). Because exploitation requires valid VPN credentials, treat VPN user credentials on affected gateways as potentially compromised and force resets. US federal agencies must follow the mitigation steps in CISA Emergency Directive 25-03 and BOD 22-01 timelines for this KEV entry.

9.971% KEV
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
mass≈100,000–300,000 internet-exposed ASA/FTD VPN web servers (order of magnitude), within a multi-million-device installed base serving large VPN user populations
CVE-2025-20363
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Ci

A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, remote attacker (Cisco ASA and FTD Software) or authenticated, remote attacker (Cisco IOS, IOS XE, and IOS XR Software) with low user privileges to execute arbitrary code on an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web service on an affected device after obtaining additional information about the system, overcoming exploit mitigations, or both. A successful exploit could allow the attacker to execute arbitrary code as root, which may lead to the complete compromise of the affected device. For more information about this vulnerability, see the Details ["#details"] section of this advisory.

NVD description · AI analysis pending
9.07%
  • cisco ios xr
  • cisco adaptive security appliance software
  • cisco ios
  • +1 more
CVE-2025-53770
Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises

CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation.

9.8100% KEV ransomware PoC ×3
  • Microsoft SharePoint Server (on-premises) Specific version ranges not enumerated in the source data; Microsoft SharePoint on-premises is affected. CISA notes SharePoint Server 2013 and earlier are EOL/E
mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users
CVE-2025-54309
Unauthenticated Admin Access Bypass in CrushFTP (CVE-2025-54309)

CVE-2025-54309 is a critical authentication flaw (CWE-420, an "unprotected alternate channel" issue) in CrushFTP in which AS2 validation is mishandled, allowing unauthenticated HTTPS requests to reach the server's administrative interface through an alternate channel. It is triggered on deployments that do not use the CrushFTP DMZ proxy (perimeter) feature, so any vulnerable instance whose HTTPS service is reachable is exposed; attackers gain full administrative access to the file transfer server and the data it holds. CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23 are affected, while deployments fronted by the DMZ proxy feature are not. The flaw has been exploited in the wild since at least July 18, 2025, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-22, and carries a 94.7% EPSS probability of exploitation within 30 days.

Do: Upgrade to CrushFTP 10.8.5 (v10 line) or 11.3.4_23 (v11 line) or later; if patching is delayed, enable the DMZ proxy feature or restrict HTTPS access to the server. Because attackers gain admin access, review administrative accounts and HTTPS logs for unexplained activity since at least July 18, 2025, and rotate exposed credentials. Federal agencies must apply vendor mitigations or follow BOD 22-01 guidance, including for cloud service use of the product.

9.895% KEV
  • CrushFTP 10 before 10.8.5; 11 before 11.3.4_23 (when the DMZ proxy feature is not used)
moderateseveral thousand internet-exposed CrushFTP servers (order of magnitude 10^3–10^4); total deployments likely higher
CVE-2025-7775
Actively Exploited Memory Overflow RCE/DoS in Citrix NetScaler ADC/Gateway

CVE-2025-7775 is a memory overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that can lead to remote code execution and/or denial of service. It is triggered when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or AAA virtual server, or — on 13.1, 14.1, 13.1-FIPS, and NDcPP builds — when load-balancing virtual servers of type HTTP, SSL, or HTTP_QUIC are bound with IPv6 services or servicegroups with IPv6 servers (including DBS IPv6), or a CR virtual server of type HDX is in use. A remote, unauthenticated attacker (CVSS 4.0 network vector with no privileges required) who triggers the memory overflow can execute code with high impact on confidentiality and integrity or crash the device. Organizations running NetScaler in these exposed configurations, notably as remote-access gateways, are affected. Exploitation is confirmed in the wild: Citrix has confirmed active exploitation, the flaw was added to CISA's KEV catalog on 2025-08-26, and EPSS estimates a 19.6% probability of exploitation within 30 days (97th percentile).

Do: Upgrade all NetScaler ADC and Gateway appliances to the patched builds on the 13.1, 14.1, 13.1-FIPS, and NDcPP release trains identified in Citrix's security bulletin, prioritizing internet-facing devices. Audit configurations for Gateway (VPN/ICA Proxy/CVPN/RDP Proxy) or AAA virtual servers, HTTP/SSL/HTTP_QUIC LB virtual servers with IPv6 bindings, and CR virtual servers of type HDX to confirm exposure. The KEV listing makes applying vendor mitigations or the upgrade mandatory for US federal agencies under BOD 22-01.

9.220% KEV
  • Citrix NetScaler ADC 13.1, 14.1, 13.1-FIPS, and NDcPP branches; vulnerable when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server; or with
  • Citrix NetScaler Gateway 13.1, 14.1, 13.1-FIPS, and NDcPP branches; vulnerable when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
large≈28,000+ internet-exposed NetScaler instances per public scans; total vulnerable deployments likely higher
Full article366 words · extracted from infosecurity-magazine.com · click to collapse

Ransomware surged in Q3 2025, with just three groups accounting for the majority of cases (65%), and initial access most commonly achieved via compromised VPN credentials, according to Beazley Security.

The Beazley Insurance subsidiary said Akira, Qilin and INC Ransomware were the most prolific groups in the third quarter, which saw 11% more leak posts than the previous three months.

As per Q2, the use of valid credentials to access VPNs was the most common method of initial access, accounting for half (48%) of breaches – up from 38% the prior quarter. External service exploits was the second most popular technique, comprising 23% of cases.

Credentials were also targeted in a prolonged campaign by the Akira group against SonicWall security appliances.

“In cases where attribution was established, the group consistently gained access by using valid credentials in credential stuffing attacks against SonicWall SSLVPN services, exploiting weak access controls such as absent MFA and insufficient lockout policies on the device,” the report noted.

Read more on VPN attacks: SonicWall SSL VPN Attacks Escalate, Bypassing MFA

The commoditization of stolen credentials demands organizations embrace comprehensive multi-factor authentication (MFA) and conditional access policies, Beazley said.

Infostealers are helping to fuel the supply of such credentials on the cybercrime underground. Even as Operation Endgame disrupted the Lumma Stealer ecosystem, the Rhadamanthys variant appeared to take over, the report claimed.

Zero-Day Exploits Surge

The threat to corporate systems comes not just from credential abuse. In Q3, Beazley tracked 11,775 new CVEs published by NIST. Although that figure was barely changed from the previous quarter, Beazley Security Labs issued 38% more advisories to customers regarding zero-day vulnerabilities in Q3.

These included:

“The trend stresses the need for vulnerability management to be practiced as a continuous discipline, with organizations understanding and addressing severe vulnerabilities as quickly as possible,” said Beazley.

“In some situations, that may mean implementing temporary mitigations or locking down network access until critical patches can be provided. Additionally, organizations should assume that critically vulnerable devices that are exposed to the internet may have already been compromised, and to investigate appropriately.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/half-ransomware-access-hijacked/