ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1182
Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 a

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric GENESIS32 versions 9.7 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions 10.97.3 and prior, and Mitsubishi Electric Iconics Digital Solutions GENESIS32 versions 9.7 and prior allows a local attacker to execute a malicious code by storing a specially crafted DLL in a specific folder when GENESIS64, ICONICS Suite, Hyper Historian, GENESIS32, and MC Works64 are installed with the Pager agent in the alarm multi-agent notification feature.

NVD description · AI analysis pending
7.0<1%
CVE-2024-12297
Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism.

Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device.

NVD description · AI analysis pending
9.2<1%
CVE-2024-13871
+1 in the same advisory: …13872
A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490).

A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, potentially leading to full remote code execution (RCE).

NVD description · AI analysis pending
9.4<1%
  • bitdefender box firmware
CVE-2024-54085
Remote Authentication Bypass by Spoofing in AMI MegaRAC SP-X BMC

CVE-2024-54085 is an authentication bypass by spoofing (CWE-290) in the AMI MegaRac SP-X baseboard management controller (BMC), allowing a remote attacker to impersonate an authorized client through the Redfish Host Interface without valid credentials. The flaw is network-exploitable with low attack complexity, no required privileges, and no user interaction, which is why it carries a maximum CVSS 4.0 score of 10.0. A successful attacker gains full BMC-level control of the host, with high impact to confidentiality, integrity, and availability; published coverage describes remote server takeover, including the ability to run attacker code and even brick servers. Anyone running servers or appliances built on the MegaRAC SP-X BMC is affected, including NetApp FAS (H300S, H500S, H700S), HCI (H410S, H410C), and StorageGRID (SG6160, SGF6112, SG110, SG1100) appliances that embed this BMC. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-06-25, and EPSS assigns a 60.7% probability of exploitation within 30 days (99th percentile), although no public proof-of-concept is known.

Do: Apply the patched MegaRAC SP-X firmware distributed by your server OEM, or the updated BMC firmware referenced in NetApp's security advisory for the affected FAS, HCI, and StorageGRID appliance models (fixed version numbers were not included in this data set). Until patched, restrict access to BMC management interfaces (including Redfish/IPMI) by isolating them from the internet and untrusted network segments, and scan for externally exposed BMC ports. As the flaw is on CISA's KEV catalog (added 2025-06-25), federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use of the product if mitigations are unavailable.

10.061% KEV
  • AMI MegaRAC SP-X (BMC firmware)
  • NetApp H300S firmware (FAS appliance with embedded AMI MegaRAC BMC)
  • NetApp H500S firmware (FAS appliance with embedded AMI MegaRAC BMC)
  • +7 more
massHundreds of thousands to millions of server BMCs (AMI's MegaRAC SP-X is embedded in server lines from many OEMs, and public internet-wide scans have repeatedly…
CVE-2024-56336
A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0 or SZVSN and the FS number is 02).

A vulnerability has been identified in SINAMICS S200 (All versions with serial number beginning with SZVS8, SZVS9, SZVS0 or SZVSN and the FS number is 02). The affected device contains an unlocked bootloader. This security oversight enables attackers to inject malicious code, or install untrusted firmware. The intrinsic security features designed to protect against data manipulation and unauthorized access are compromised when the bootloader is not secured.

NVD description · AI analysis pending
9.5<1%
CVE-2024-57040
TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account

TP-Link TL-WR845N devices with firmware TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained by analyzing downloaded firmware or via a brute force attack through physical access to the router. NOTE: The supplier has stated that this issue was fixed in firmware versions 250401 or later.

NVD description · AI analysis pending
9.81%
  • tp-link tl-wr845n firmware
CVE-2024-7587
Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mi

Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric GENESIS32 versions 9.70.300.23 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS32 versions 9.70.300.23 and prior, and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to disclose or tamper with confidential information and data contained in the products, or cause a denial of service (DoS) condition on the products, by accessing a folder with incorrect permissions, when GenBroker32 is installed on the same PC as GENESIS64, ICONICS Suite, MC Works64, or GENESIS32.

NVD description · AI analysis pending
7.8<1%
  • iconics genesis64
  • iconics mc works64
CVE-2024-8299
+1 in the same advisory: …9852
Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 a

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric GENESIS32 all versions, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions 10.97.3 and prior, and Mitsubishi Electric Iconics Digital Solutions GENESIS32 all versions allows a local authenticated attacker to execute a malicious code by storing a specially crafted DLL in a specific folder. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or to cause a denial of service (DoS) condition on the products.

NVD description · AI analysis pending
7.8<1%
CVE-2024-8300
Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric Iconics Digital Solutions

Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric Iconics Digital Solutions GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, and Mitsubishi Electric Iconics Digital Solutions ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 allows a local authenticated attacker to execute a malicious code by tampering with a specially crafted DLL. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.

NVD description · AI analysis pending
7.0<1%
CVE-2025-20115
A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker t

A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to a memory corruption that occurs when a BGP update is created with an AS_CONFED_SEQUENCE attribute that has 255 autonomous system numbers (AS numbers). An attacker could exploit this vulnerability by sending a crafted BGP update message, or the network could be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more. A successful exploit could allow the attacker to cause memory corruption, which may cause the BGP process to restart, resulting in a DoS condition. To exploit this vulnerability, an attacker must control a BGP confederation speaker within the same autonomous system as the victim, or the network must be designed in such a manner that the AS_CONFED_SEQUENCE attribute grows to 255 AS numbers or more.

NVD description · AI analysis pending
8.6<1%
  • cisco ios xr
CVE-2025-21590
Kernel Code Injection Flaw in Juniper Junos OS Exploited in the Wild

Juniper Junos OS contains an improper isolation or compartmentalization flaw (CWE-653) in the kernel that allows a local attacker with high privileges to inject arbitrary code and compromise the integrity of the device. The issue cannot be triggered from the Junos CLI, so exploitation requires shell access, such as via a compromised or rogue high-privileged account or as part of a chained attack. Code running in the kernel gives the attacker deep control of the device, enabling persistent tampering such as backdoors or rootkits. All Junos OS releases before the listed fix versions across the 21.2 through 24.2 branches are affected, covering Juniper's routing, switching, and security product lines. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-13, confirming exploitation in the wild, amid headlines reporting China-linked APT UNC3886 breaching Juniper routers with custom backdoors and rootkits.

Do: Upgrade affected systems to 21.2R3-S9, 21.4R3-S10, 22.2R3-S6, 22.4R3-S6, 23.2R2-S3, 23.4R2-S4, or 24.2R1-S2/24.2R2 per branch; releases older than 21.2 have no listed fix and require migration to a supported fixed release. Restrict shell/root access to trusted administrators and, given reported UNC3886 backdoor and rootkit activity on Juniper routers, audit devices for unexpected processes, modified system files, or unusual persistence in the Junos shell. U.S. federal agencies must apply the required remediation per BOD 22-01 due to the KEV listing.

6.72% KEV
  • Juniper Networks Junos OS All versions before 21.2R3-S9
  • Juniper Networks Junos OS 21.4 All 21.4 versions before 21.4R3-S10
  • Juniper Networks Junos OS 22.2 All 22.2 versions before 22.2R3-S6
  • +4 more
masson the order of 1M+ devices running affected Junos OS releases (Junos spans Juniper's global installed base of routers, switches, and firewalls at service…
CVE-2025-24201
WebKit Out-of-Bounds Write Sandbox Escape in Apple iOS, Safari, and macOS

CVE-2025-24201 is an out-of-bounds write (CWE-787) in WebKit, the web rendering engine used across Apple's platforms, which Apple addressed with improved bounds checks. It is triggered by processing maliciously crafted web content, meaning a victim only has to load attacker-controlled web content in Safari or in any app that renders web content. A successful attacker can break out of the Web Content sandbox and perform unauthorized actions, an impact CISA scores at CVSS 10.0 (critical, scope-changing). Affected users include anyone running vulnerable versions of iOS, iPadOS, macOS Sequoia, Safari, visionOS, or watchOS; Debian Linux is also listed in the CPE data because Debian ships WebKit in its webkit packages. Apple reports the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 17.2 (this patch is a supplementary fix for that previously blocked attack, extended to older branches), and the CVE was added to CISA's KEV catalog on 2025-03-13.

Do: Apply the vendor fixes immediately: Safari 18.3.1; iOS/iPadOS 18.3.2 (or 17.7.6, 16.7.11, or 15.8.4 on devices that cannot run the newest release); macOS Sequoia 15.3.2; visionOS 2.3.2; watchOS 11.4; and updated Debian webkit packages per Debian advisories. Because the CVE is in CISA's KEV catalog (added 2025-03-13), US federal agencies must patch per BOD 22-01, and all defenders should prioritize fleets with high-risk or frequently targeted users. Given the 'extremely sophisticated' targeted exploitation against individuals on iOS before 17.2, check whether targeted or high-value users' devices show indicators of compromise and ensure they are not left on older branches.

10.04% KEV
  • Apple Safari Versions prior to 18.3.1; fixed in Safari 18.3.1
  • Apple iPhone OS (iOS) iOS 15.x, 16.x and 18.x prior to the fixes; fixed in iOS 15.8.4, iOS 16.7.11, and iOS 18.3.2 (the referenced in-the-wild attacks targeted iOS versions before 17
  • Apple iPadOS iPadOS 15.x, 16.x, 17.x and 18.x prior to the fixes; fixed in iPadOS 15.8.4, 16.7.11, 17.7.6, and 18.3.2
  • +4 more
mass≈2 billion+ active Apple devices (iPhone, iPad, Mac, Apple Watch and Vision Pro all ship the affected WebKit; Apple publicly reports an active installed base…
CVE-2025-24813
Path Equivalence Flaw in Apache Tomcat Partial PUT Enables RCE and Disclosure

Apache Tomcat is affected by a path equivalence flaw (CWE-44) in its handling of partial PUT requests, compounded by deserialization of untrusted data (CWE-502). A remote attacker triggers it by sending a crafted partial PUT (a PUT request with a Content-Range header) to a Tomcat instance that has write access enabled on its default servlet, causing uploaded content to be placed or reconstructed incorrectly and potentially leading to deserialization of attacker-controlled data. Successful exploitation can yield remote code execution, disclosure of sensitive information, or injection of malicious content, and CISA notes the flaw can be chained with CVE-2026-34486. Any organization running Apache Tomcat is potentially affected (version ranges were not specified in the provided data), with risk concentrated in deployments that permit PUT uploads and use file-based session persistence in default locations. Exploitation is confirmed in the wild: the CVE was added to CISA's Known Exploited Vulnerabilities catalog on 2025-04-01 and EPSS assigns a 99.9% probability of exploitation within 30 days, though no public proof-of-concept is known.

Do: Apply the vendor mitigation per CISA's required action: upgrade Tomcat to the fixed release identified in Apache's security advisory for this CVE, or, if patching is not immediately possible, disable write access (readonly) on the default servlet/restrict partial PUT and move file-based session storage away from default locations. Federal agencies must follow BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Audit Tomcat instances (including embedded deployments) for write-enabled PUT and file-based session persistence, and consider exposure to chaining with CVE-2026-34486.

9.8100% KEV PoC ×3
  • Apache Tomcat
mass≥100,000 directly internet-exposed Tomcat instances, out of millions of total deployments worldwide
CVE-2025-24985
Local Code Execution via Integer Overflow in Microsoft Windows Fast FAT Driver

CVE-2025-24985 is an integer overflow (CWE-190) in the Windows Fast FAT file system driver that can lead to a buffer overflow condition (CWE-122) when the driver processes crafted FAT file system structures. Because the Fast FAT driver handles FAT-formatted storage, the flaw is triggered locally, most plausibly by mounting or interacting with a specially crafted FAT-formatted disk image or removable medium, with user interaction required per the CVSS vector. A successful exploit allows an unauthorized local attacker to execute code on the affected machine, with high impact to confidentiality, integrity, and availability (CVSS 3.1 base score 7.8, High). All Windows client versions from Windows 10 1507 through Windows 11 24H2 and Windows Server 2008/2012/2016/2019 are in the affected scope, meaning essentially any unpatched Windows system on those version lines is exposed. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-11, Microsoft fixed it in the March 2025 Patch Tuesday release as one of six actively exploited zero-days, and EPSS currently estimates a 3.8% chance of exploitation in the next 30 days (89th percentile); ransomware use is listed as unknown.

Do: Install Microsoft's March 2025 Windows cumulative security updates on every affected Windows 10, Windows 11, and Windows Server host, and prioritize endpoints that mount untrusted removable media or disk images; federal agencies must apply the fix within the CISA BOD 22-01 deadline tied to the 2025-03-11 KEV listing. Until systems are patched, discourage or restrict use of untrusted FAT-formatted media and crafted disk images, and inventory your estate for the affected version branches (Windows 10 1507/1607/1809/21H2/22H2, Windows 11 22H2/23H2/24H2, Server 2008/2012/2016/2019). Because ransomware use is listed as unknown, treat this as a high-priority patch given active exploitation is confirmed.

7.8
group max
4% KEV PoC
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 22H2, 23H2, 24H2
  • microsoft Windows Server 2008
  • +3 more
masshundreds of millions of unpatched Windows client and server systems worldwide (unknown precisely)
CVE-2025-25292
+1 in the same advisory: …25291
Authentication Bypass (Signature Wrapping) in ruby-saml via XML Parser Differential

ruby-saml versions prior to 1.12.4 and 1.18.0 (CVE-2025-25292) are vulnerable to an authentication bypass caused by a parser differential: the ReXML and Nokogiri XML parsers used in the SAML validation path can produce entirely different document structures from the same XML input (CWE-347, CWE-436). An attacker who can submit a crafted SAML response, for example through an account on a connected identity provider, can craft a response whose signature validates under one parser while the assertion is interpreted differently under the other, executing a Signature Wrapping attack. Successful exploitation allows an unauthenticated attacker to sign in as any user of the service provider, bypassing SAML SSO and enabling account takeover. Any Ruby application authenticating via ruby-saml directly or through dependencies such as omniauth-saml is affected, along with products that bundle the library such as NetApp StorageGRID and SSO platforms like GitLab that depend on it. The flaw is not yet on the CISA KEV list, but public PoCs and detailed write-ups from GitHub and PortSwigger are available, and a high EPSS score (65.1%, 99th percentile) indicates an elevated likelihood of exploitation within 30 days.

Do: Upgrade ruby-saml to 1.12.4 if pinned to the 1.12.x line or, preferably, to 1.18.0, and rebuild/update dependent gems such as omniauth-saml; apply vendor updates for NetApp StorageGRID as they become available. Operators of SAML SSO endpoints should prioritize internet-facing identity flows, audit recent sign-ins for anomalies, and verify patched versions are actually loaded at runtime (e.g., via 'gem list' or the dependency lockfile).

9.365% PoC ×2
  • onelogin ruby-saml all versions prior to 1.12.4 (1.12.x line) and prior to 1.18.0; fixed in 1.12.4 and 1.18.0
  • omniauth-saml releases depending on a vulnerable ruby-saml (prior to 1.12.4 / 1.18.0); exact omniauth-saml version range not specified in the data
  • netapp StorageGRID
massplausibly hundreds of thousands to millions of application deployments (ruby-saml/omniauth-saml are foundational Ruby SSO libraries with very large cumulative…
CVE-2025-27017
Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components gene

Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those processors may see the credentials information. Upgrading to Apache NiFi 2.3.0 is the recommended mitigation, which removes the credentials from provenance event records.

NVD description · AI analysis pending
6.91%
  • apache nifi
CVE-2025-27363
Out-of-Bounds Write in FreeType Font Parsing Allows Arbitrary Code Execution

FreeType, the widely bundled open-source font rendering library, contains an out-of-bounds write (CWE-787) when parsing subglyph structures in TrueType GX and variable font files. The flaw is triggered when an application using FreeType renders a specially crafted font file, such as one embedded in a document, webpage, or downloaded file. A successful exploit may allow the attacker to execute arbitrary code with the privileges of the application that processed the font. Because FreeType ships by default with virtually all major Linux distributions, Android, and many applications and embedded products, the affected population is extremely broad, though specific affected version ranges are not enumerated in the available data. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2025-05-06, indicating confirmed in-the-wild exploitation, and carries a high EPSS probability of 27.8% (98th percentile); no public proof-of-concept code is known.

Do: Update FreeType to the latest available release/commit and apply vendor patches for any product that bundles or depends on it, since exact vulnerable version ranges are not stated in the available data. Inventory your environment for software, operating systems, and dependencies that ship FreeType, and prioritize internet-facing or user-facing systems that process untrusted font files. Federal agencies must follow the CISA KEV required action (apply vendor mitigations per BOD 22-01) or discontinue use if mitigations are unavailable.

8.128% KEV
  • FreeType
masshundreds of millions to billions of devices (FreeType is the default font-rendering library bundled in major Linux distributions and Android)
CVE-2025-27407
graphql-ruby is a Ruby implementation of GraphQL.

graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21, loading a malicious schema definition in `GraphQL::Schema.from_introspection` (or `GraphQL::Schema::Loader.load`) can result in remote code execution. Any system which loads a schema by JSON from an untrusted source is vulnerable, including those that use GraphQL::Client to load external schemas via GraphQL introspection. Versions 1.11.8, 1.12.25, 1.13.24, 2.0.32, 2.1.14, 2.2.17, and 2.3.21 contain a patch for the issue.

NVD description · AI analysis pending
9.03%
CVE-2025-27509
fleetdm/fleet is an open source device management, built on osquery.

fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could craft a specially-formed SAML response to forge authentication assertions, provision a new administrative user account if Just-In-Time (JIT) provisioning is enabled, or create new accounts tied to forged assertions if f MDM enrollment is enabled. This vulnerability is fixed in 4.64.2, 4.63.2, 4.62.4, and 4.58.1.

NVD description · AI analysis pending
9.3<1%
CVE-2025-27593
The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks, leading to code execution on target s

The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification checks, leading to code execution on target systems.

NVD description · AI analysis pending
9.3<1%
CVE-2025-27636
Header Filter Bypass in Apache Camel Allows Bean Method and Queue Manipulation

CVE-2025-27636 is a case-sensitivity flaw (CWE-178) in the default incoming header filter of Apache Camel, which only blocks headers starting with "Camel", "camel", or "org.apache.camel.", allowing mixed-case variants such as "cAmel..." to pass through as trusted Camel runtime headers. An attacker who can inject custom headers into a Camel application — for example by sending crafted HTTP headers to applications exposed via camel-servlet, camel-jetty, camel-undertow, camel-platform-http, or camel-netty-http — can alter component behavior, such as making camel-bean invoke a different method on a bean than the application coded, or redirecting camel-jms messages to another queue on the same broker; similar behavior changes were observed with camel-exec. Depending on the components and methods in use, this can lead to information disclosure, integrity, or availability impact, and public proof-of-concept exploits (including demonstrations of remote code execution) already exist. Applications running Apache Camel 3.10.0 through 3.22.3, 4.8.0 through 4.8.4, or 4.10.0 through 4.10.1 that use the default header filter with any of the roughly two dozen listed components are affected, but practical exploitability requires attacker-reachable header injection, such as internet-facing HTTP endpoints. The flaw is not yet in CISA's KEV catalog, but public PoCs are available and EPSS puts the 30-day exploitation probability at 81.1% (100th percentile), so exploitation is considered likely.

Do: Upgrade to Apache Camel 4.10.2 (4.10.x LTS), 4.8.5 (4.8.x LTS), or 3.22.4 (3.x). As an interim mitigation, add a removeHeaders EIP (globally or per route) to strip header names matching mixed-case variants of "camel" (e.g., "cAmel", "cAMEL") or anything not starting with "Camel", "camel", or "org.apache.camel.". Prioritize reviewing internet-facing routes that use camel-servlet, camel-jetty, camel-undertow, camel-platform-http, or camel-netty-http, especially those invoking camel-bean or routing camel-jms messages.

5.681% PoC ×3
  • Apache Camel 3.10.0 through 3.22.3, 4.8.0 through 4.8.4, and 4.10.0 through 4.10.1 (components using the default header filter, including camel-activemq, camel-activemq6, ca
large≈10,000–100,000 internet-facing Camel applications (estimate; no public install counts available)
CVE-2025-27816
A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deserialization of

A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploited due to the insecure deserialization of potentially untrusted messages. The vulnerability is present in the Windows Plugin_Host service, which runs on all the servers where InfoScale is installed. The service is used only when applications are configured for Disaster Recovery (DR) using the DR wizard. Disabling the Plugin_Host service manually will eliminate the vulnerability.

NVD description · AI analysis pending
9.8<1%

Indicators of compromiseAll →

TypeIndicatorContext
domainbooking.comClickFix strategy as part of a phishing campaign that uses Booking.com lures to direct users to credential-stealing malware. The c
Full article2,935 words · extracted from thehackernews.com · click to collapse

From sophisticated nation-state campaigns to stealthy malware lurking in unexpected places, this week’s cybersecurity landscape is a reminder that attackers are always evolving. Advanced threat groups are exploiting outdated hardware, abusing legitimate tools for financial fraud, and finding new ways to bypass security defenses. Meanwhile, supply chain threats are on the rise, with open-source repositories becoming a playground for credential theft and hidden backdoors.

But it’s not all bad news—law enforcement is tightening its grip on cybercriminal networks, with key ransomware figures facing extradition and the security community making strides in uncovering and dismantling active threats. Ethical hackers continue to expose critical flaws, and new decryptors offer a fighting chance against ransomware operators.

In this week’s recap, we dive into the latest attack techniques, emerging vulnerabilities, and defensive strategies to keep you ahead of the curve. Stay informed, stay secure.

⚡ Threat of the Week

UNC3886 Targets End-of-Life Juniper Networks MX Series Routers — UNC3886, a China-nexus hacking group previously known for breaching edge devices and virtualization technologies, targeted end-of-life MX Series routers from Juniper Networks as part of a campaign designed to deploy six distinct TinyShell-based backdoors. Less than 10 organizations have been targeted as part of the campaign. "The backdoors had varying custom capabilities, including active and passive backdoor functions, as well as an embedded script that disables logging mechanisms on the target device," Mandiant said. Further analysis by Juniper Networks has revealed that at least one security vulnerability (CVE-2025-21590) contributed to a successful attack that allowed the threat actors to bypass security protections and execute malicious code.

🔔 Top News

  • Storm-1865 Uses ClickFix for Financial Fraud and Theft — A threat actor known as Storm-1865 has been observed leveraging the increasingly popular ClickFix strategy as part of a phishing campaign that uses Booking.com lures to direct users to credential-stealing malware. The campaign, ongoing since December 2024, casts a wide geographical net, spanning North America, Oceania, South and Southeast Asia, and Northern, Southern, Eastern, and Western Europe.
  • North Korea Targets Korean and English-Speaking Users with KoSpy — The North Korea-linked ScarCruft actor uploaded bogus Android apps to the Google Play Store by passing them off as seemingly innocuous utility apps that, when installed, unleashed a malware called KoSpy. It harbors features to collect SMS messages, call logs, location, files, audio, and screenshots via dynamically loaded plugins. The apps have since been removed from the app marketplace. The exact scale of the campaign remains unclear, although the earliest versions of the malware have been found as far back as March 2022.
  • SideWinder Goes After Maritime and Logistics Companies — The advanced persistent threat (APT) group dubbed SideWinder has been linked to attacks targeting maritime and logistics companies in South and Southeast Asia, the Middle East, and Africa using a modular post-exploitation toolkit called StealerBot to capture a wide range of sensitive information from compromised hosts. The attacks spread across Bangladesh, Cambodia, Djibouti, Egypt, the United Arab Emirates, and Vietnam.
  • LockBit Developer Extradited to the U.S. to Face Charges — Rostislav Panev, a 51-year-old dual Russian and Israeli national, was extradited to the U.S. from Israel to face charges related to his alleged involvement as a developer of the LockBit ransomware group from 2019 to February 2024. He was arrested in August 2024, a few months after the operation's online infrastructure was seized in a law enforcement exercise. Panev is said to have earned approximately $230,000 between June 2022 and February 2024.
  • Malicious PyPI Packages Conduct Credential Theft — A collection of 20 packages uncovered on the Python Package Index (PyPI) repository masqueraded as time- and cloud-related utilities but contained hidden functionality to steal sensitive data such as cloud access tokens. The packages were collectively downloaded over 14,100 times before they were removed from the PyPI repository. Three of these packages, acloud-client, enumer-iam, and tcloud-python-test, has been listed as dependencies of a relatively popular GitHub project named accesskey_tools that has been forked 42 times and starred 519 times.

‎️‍🔥 Trending CVEs

Attackers love software vulnerabilities—they’re easy doors into your systems. Every week brings fresh flaws, and waiting too long to patch can turn a minor oversight into a major breach. Below are this week's critical vulnerabilities you need to know about. Take a look, update your software promptly, and keep attackers locked out.

This week’s list includes — CVE-2025-24983, CVE-2025-24984, CVE-2025-24985, CVE-2025-24991, CVE-2025-24993, CVE-2025-26633 (Microsoft Windows), CVE-2025-24201 (Apple iOS, iPadOS, macOS Sequoia, Safari, and VisionOS), CVE-2025-25291, CVE-2025-25292 (ruby-saml), CVE-2025-27363 (FreeType), CVE-2024-12297 (Moxa PT switches), CVE-2025-27816 (Arctera InfoScale product), CVE-2025-24813 (Apache Tomcat), CVE-2025-27636 (Apache Camel), CVE-2025-27017 (Apache NiFi), CVE-2024-56336 (Siemens SINAMICS S200), CVE-2024-13871, CVE-2024-13872 (Bitdefender BOX v1), CVE-2025-20115 (Cisco IOS XR), CVE-2025-27593 (SICK DL100-2xxxxxxx), CVE-2025-27407 (graphql), CVE-2024-54085 (AMI), CVE-2025-27509 (Fleet), and CVE-2024-57040 (TP-Link TL-WR845N router).

📰 Around the Cyber World

  • Google Pays $11.8 Million in 2024 Bug Bounty Program — Google paid almost $12 million in bug bounty rewards to 660 security researchers who reported security issues through the company's Vulnerability Reward Program (VRP) in 2024. It also said it awarded more than $3.3 million to researchers who uncovered critical vulnerabilities within Android and Google mobile applications. Last but not least, the company said it received 185 bug reports related to its Artificial intelligence (AI) products, netting researchers over $140,000 in rewards.
  • Security Flaws in ICONICS Suite Disclosed — Five high-severity security flaws have been disclosed in a Supervisory Control and Data Acquisition (SCADA) system named ICONICS Suite – CVE-2024-1182, CVE-2024-7587, CVE-2024-8299, CVE-2024-9852, and CVE-2024-8300 – that allows an authenticated attacker to execute arbitrary code, elevate privileges, and manipulate critical files. In a real world attack aimed at industrial systems, an adversary who has already gained access to the targeted organization’s systems could leverage the SCADA vulnerabilities to cause disruption and in some cases to take full control of a system. "In combination, these vulnerabilities pose a risk to the confidentiality, integrity and availability of a system," Palo Alto Networks Unit 42 said.
  • Threat Actors Intensify Abuse of Remote Access Tools — Threat actors like TA583, TA2725, and UAC-0050 are increasingly using legitimate remote monitoring and management (RMM) tools such as ScreenConnect, Fleetdeck, Atera, and Bluetrait as a first-stage payload in email campaigns. They can be used for data collection, financial theft, lateral movement, and to install follow-on malware including ransomware. The development coincides with a decrease in prominent loaders and botnets typically used by initial access brokers. "It's fairly easy for threat actors to create and distribute attacker-owned remote monitoring tools, and because they are often used as legitimate pieces of software, end users might be less suspicious of installing RMMs than other remote access trojans," Proofpoint said. "Additionally, such tooling may evade anti-virus or network detection because the installers are often signed, legitimate payloads distributed maliciously."
  • Decryptor for Linux Variant of Akira Ransomware Released — A decryptor has been released for the Linux/ESXI variant of Akira ransomware released in 2024 by utilizing GPU power to retrieve the decryption key and unlock files for free. It has been made available by researcher Yohanes Nugroho on GitHub.
  • Volt Typhoon Hackers Dwelled in a U.S. Electric Company for Over 300 Days — Chinese hackers linked to the Volt Typhoon (aka Voltzite) campaign spent nearly one year inside the systems of a major utility company in Littleton, Massachusetts. According to a case study published by Dragos, Littleton Electric Light and Water Departments (LELWD) discovered its systems were breached before Thanksgiving in 2023. A subsequent investigation found evidence of lateral movement by the hackers and data exfiltration, but ultimately revealed that the "compromised information did not include any customer-sensitive data, and the utility was able to change their network architecture to remove any advantages for the adversary." The attackers are said to have gained access via a buggy Fortinet 300D firewall associated with a managed service provider (MSP). Dragos added: "The significance of the discovery of this attack is that it highlights that the adversary not only aimed to maintain persistent access to the victim's environment for a long tenure, but also were aiming to exfiltrate specific data related to OT operating procedures and spatial layout data relating to energy grid operations." The existence of Volt Typhoon came to light in May 2023. While China has denied any involvement in the Volt Typhoon attacks, U.S. government agencies have said the threat actors are "seeking to pre-position themselves on IT networks for disruptive or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States."
  • Lazarus Group Drops LazarLoader Malware — The North Korea-linked Lazarus Group, which was most recently implicated in the record-breaking $1.5 billion cryptocurrency theft from Bybit, has been observed targeting South Korean web servers to install web shells and a downloader malware dubbed LazarLoader, which then is responsible for fetching an unspecified backdoor.
  • YouTube Becomes Conduit for DCRat — A new wave of cyber attacks utilizing the Dark Crystal RAT (DCRat) backdoor has been targeting users since early 2025 through YouTube distribution channels. The attacks involve cybercriminals creating or compromising YouTube accounts to upload videos advertising gaming cheats, cracks, and bots that appeal to gamers looking for such tools, tricking them into clicking on booby-trapped links embedded in the video descriptions. "Besides backdoor capability, the trojan can load extra modules to boost its functionality," Kaspersky said. "Throughout the backdoor's existence [since 2018], we have obtained and analyzed 34 different plugins, the most dangerous functions of which are keystroke logging, webcam access, file grabbing and password exfiltration." Telemetry data gathered by the Russian cybersecurity company shows that a majority of the DCRat samples were downloaded to the devices of users in Russia, and to a lesser extent among users from Belarus, Kazakhstan, and China.
  • New Social Engineering Campaigns Aimed at Microsoft 356 Account Takeover — Proofpoint is warning of two ongoing, highly targeted campaigns that combine OAuth redirection mechanisms with brand impersonation techniques, malware proliferation, and Microsoft 365-themed credential phishing to facilitate account takeover (ATO) attacks. It said it discovered three malicious OAuth apps, disguised as Adobe Drive, Adobe Acrobat, and Docusign, which are used to redirect users to web pages hosting phishing and malware delivery threats. "To avoid detection solutions, the observed apps were assigned limited scopes (such as profile, email, openid," it said.
  • Wi-Fi Jamming Technique Enables Precision DoS Attack — New research has demonstrated a sophisticated Wi-Fi jamming technique that's capable of disabling individual devices with millimeter-level precision by leveraging Reconfigurable Intelligent Surface (RIS) technology. "In particular, we propose a novel approach that allows for environment-adaptive spatial control of wireless jamming signals, granting a new degree of freedom to perform jamming attacks," a group of academics from Ruhr University Bochum and Max Planck Institute for Security and Privacy said. "Using RIS-based environment-adaptive wireless channel control, allowing to maximize and minimize wireless signals on specific locations [27], the attacker gains spatial control over their wireless jamming signals. This opens the door to precise jamming signal delivery towards a target device, disrupting any legitimate signal reception, while leaving other, non-target devices, untouched."
  • Hash DoS Flaw in QUIC Implementations — Multiple Quick UDP Internet Connections (QUIC) protocol implementations have been found susceptible to a hash denial-of-service (DoS) attack. "By exploiting this vulnerability, an attacker is able to significantly slow down vulnerable servers," NCC Group said. "This vulnerability allows attackers to stall the server by forcing it to spend the majority of its computing power inserting and looking up colliding connection IDs."
  • Exposed Jupyter Notebooks Become Cryptominer Targets — A new evasive campaign is targeting misconfigured Jupyter Notebooks installed on both Windows and Linus systems to deliver a cryptocurrency miner. The payloads take the form of MSI installers and ELF binaries that are designed to drop the miner that singles out Monero, Sumokoin, ArQma, Graft, Ravencoin, Wownero, Zephyr, Townforge, and YadaCoin. Cado Security, which detected the activity against its honeypot network, said it also observed a parallel campaign targeting servers running PHP to distribute the same miner. Furthermore, some of the intermediate artifacts used in the campaign have been observed in prior attacks targeting South Korean web servers as well as Ivanti Connect Secure (ICS) instances vulnerable to CVE-2023-46805 and CVE-2024-21887.
  • ESP32 Chip Backdoor Claims Disputed — Espressif, the manufacturer of ESP32, a low-cost, low-power microcontroller with integrated Wi-Fi and dual-mode Bluetooth capabilities, has pushed back against claims of a backdoor in its products. Researchers at Tarlogic initially said they had found a "backdoor" in ESP32 that could "allow hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks, or medical equipment by bypassing code audit controls." The research has since been updated to make it clear that it's more of a "hidden functionality that can be used as a backdoor." It also said that the commands could facilitate supply chain attacks or other stealthy compromises. In response to the disclosure, Espressif pointed out that the 29 undocumented commands in question are not accessible remotely, but noted it will provide a software fix to remove them from the code. "The functionality found are debug commands included for testing purposes," it added. "These debug commands are part of Espressif's implementation of the HCI (Host Controller Interface) protocol used in Bluetooth technology. This protocol is used internally in a product to communicate between Bluetooth layers." ESP32-C, ESP32-S and ESP32-H series chips are not impacted by the issue, which is now tracked as CVE-2025-27840 (CVSS score: 6.8).
  • Switzerland Makes it Mandatory to Disclose Critical Infra Attacks — The National Cyber Security Centre (NCSC) of Switzerland has announced that critical infrastructure organizations will be required to report cyberattacks to the NCSC within 24 hours of discovery starting April 1, 2025. "Examples of when a cyberattack must be reported include when it threatens the functioning of critical infrastructure, has resulted in the manipulation or leakage of information, or involves blackmail, threats or coercion," the NCSC said. "Critical infrastructure operators who fail to report a cyberattack may be fined."
  • Bugs in Microsoft's Time Travel Debugging (TTD) Framework — Google-owned Mandiant has detailed its security analysis of the Time Travel Debugging (TTD) framework, a record-and-replay debugging tool for Windows user-mode applications. Given that TTD leans on CPU instruction emulation to reproduce issues, "subtle inaccuracies" in the process could have serious consequences, potentially allowing critical security flaws to slip undetected. Even worse, it could be deliberately abused by attackers to bypass analysis. The four identified issues have been addressed in TTD version 1.11.410. "The observed discrepancies, while subtle, underscore a broader security concern: even minor deviations in emulation behavior can misrepresent the true execution of code, potentially masking vulnerabilities or misleading forensic investigations," Mandiant said.
  • NIST Chooses HQC as Fifth Post-Quantum Crypto Algorithm — The U.S. National Institute of Standards and Technology (NIST) has selected HQC (short for Hamming Quasi-Cyclic) as backup algorithm as a "second line of defense" against the threat posed by a future quantum computer. "The new algorithm, called HQC, will serve as a backup defense in case quantum computers are someday able to crack ML-KEM," NIST said. "Both these algorithms are designed to protect stored information as well as data that travels across public networks." According to Dustin Moody, who heads NIST's Post-Quantum Cryptography project, HQC is not intended to replace ML-KEM.
  • Going from BYOVD to BYOTB to BYOVE — Bring Your Own Vulnerable Driver (BYOVD) is a known attack technique that involves a threat actor using a legitimate but vulnerable driver -- that's either already pre-installed on the host or introduced to a target environment -- with the goal of gaining elevated privileges and perform malicious actions, such as disabling security software. This approach has been adopted by various threat actors such as BlackByte, Kasseika, RansomHub (Water Bakunawa), and Lazarus Group. But new research published in recent weeks has shown that the technique can be exploited in conjunction with symbolic links (aka symlinks) to exploit a broader set of drivers. "With the new attack method that combines the file writing functionality of drivers and Windows Symbolic Links, attackers are relieved from the restriction of needing to find vulnerable drivers that are not yet on the blocklist to exploit," Zero Salarium researcher Nicky Thompson said. "Instead, they only need to identify any driver that has file writing capabilities, such as logging, tracing, etc. Merging with the abuse of symbolic links, BYOVD technique will evolve to a new level." The approach can be further extended to what's called a Bring Your Own Trusted Binary (BYOTB), which involves using legitimate binaries (e.g., cloudflared) in an adversarial manner, and Bring Your Own Vulnerable Enclave (BYOVE), which makes use of vulnerable versions of legitimate enclaves to run malicious code without attracting attention -- a memory evasion technique codenamed Mirage. While enclave modules have to be signed with a Microsoft-issued certificate to load, a threat actor could rely on an operating system flaw (CVE-2024-49706) to load an unsigned module into an enclave, obtain access to a Trusted Signing entity and sign their own enclaves, or even abuse debuggable and vulnerable enclaves (e.g., CVE-2023-36880) to read and write arbitrary data inside the enclave. "This could be useful in many scenarios — by storing payloads out of the reach of EDRs, sealing encryption keys hidden away from analysts, or keeping sensitive malware configuration out of memory dumps," Akamai researcher Ori David said. Another technique to blind security solutions involves a new path masquerading approach that employs "whitespace" characters in Unicode to spoof the execution path of any program to resemble that of an antivirus.

🎥 Cybersecurity Webinars

  • Learn How to Eliminate Identity-Based Threats — Despite massive security investments, identity-based attacks like phishing and MFA bypass continue to thrive. Traditional methods accept breaches as inevitable—but what if you could eliminate these threats altogether? Join this webinar to discover secure-by-design access solutions featuring phishing resistance, device compliance, and adaptive authentication—shifting your strategy from breach response to proactive prevention.
  • Discover AI-Driven Threats and Zero Trust Defense Before It's Too Late — Artificial Intelligence (AI) is reshaping cybersecurity, amplifying threats, and outsmarting traditional defenses. Join Diana Shtil from Zscaler to learn practical, proactive strategies—including Zero Trust—to protect your organization against evolving AI-driven attacks.
  • Your AI is Outpacing Your Security: Here’s How to Keep Up — Hidden AI tools are quietly spreading across your environment, bypassing security controls until they become a real threat. Join Dvir Sasson, Director of Security Research at Reco, to uncover stealthy AI risks in your SaaS apps, real-world AI attack scenarios, and practical strategies to detect and respond effectively. Reserve your spot now to stay ahead of AI threats.

🔧 Cybersecurity Tools

  • CVE Prioritizer — An advanced vulnerability assessment tool designed to streamline your patch management by intelligently combining CVSS scores, EPSS predictive insights, CISA's Known Exploited Vulnerabilities (KEV), and VulnCheck’s enriched community data (NVD++, KEV). Traditional CVSS scores reflect vulnerability severity, but adding EPSS helps pinpoint those most likely to be actively exploited. By integrating CISA KEV, the tool emphasizes vulnerabilities currently leveraged in real-world attacks. This combined approach categorizes CVEs into clear priority levels, enabling security teams to efficiently allocate resources, effectively manage risk, and strategically remediate the vulnerabilities that truly matter most.
  • Fleet — An open-source security and IT platform helping teams at companies like Fastly and Gusto manage thousands of devices easily. It simplifies vulnerability tracking, device health monitoring, security policies, and license management across macOS, Windows, Linux, cloud platforms, and IoT. Fleet is modular, and lightweight, integrates smoothly with popular tools, and offers a free, flexible solution tailored to your needs.
  • ZeroProbe — A specialized enumeration and exploit-development toolkit for security researchers, penetration testers, and red teamers. It provides precise detection of kernel exploits, DLL hijacking, privilege escalation opportunities, weak file permissions, and suspicious memory regions. Leveraging direct syscall execution, memory analysis, and syscall hooking detection, ZeroProbe enables stealthy, forensic-friendly security assessments on Windows 10, 11, and Server 2019, compatible across PowerShell versions.

🔒 Tip of the Week

Detecting Threat Actors Early with Sysmon and Event ID 4688 — Attackers rely heavily on running unusual or malicious processes—such as encoded PowerShell commands, uncommon scripts, or tools like certutil.exe or rundll32.exe—to escalate privileges and evade detection. Deploying Microsoft Sysmon combined with built-in Windows Event ID 4688 (Process Creation) auditing helps capture these actions early, significantly reducing the risk of compromise. Sysmon provides detailed logs on process activities, file creation, and network connections, enabling defenders to spot anomalies quickly.

For practical implementation, install Sysmon with a trusted, community-driven configuration (like SwiftOnSecurity’s config), and enable Windows process auditing through group policies or the command line. Then, automate detection and alerting using free SIEM solutions like Elastic Stack (ELK) or Graylog, easily integrating Sysmon and Windows logs for real-time visibility and rapid threat response.

Conclusion

Cyber threats aren’t just evolving—they’re adapting to security controls, exploiting human behavior, and weaponizing legitimate technologies. This week’s developments highlight a critical reality: outdated infrastructure isn’t just a liability, it’s an invitation. Trusting signed software blindly? That’s a risk. Assuming major platforms are inherently secure? That’s an oversight.

Threat actors are shifting tactics faster than many defenses can keep up. They’re embedding malware in everyday tools, leveraging phishing beyond mere credential theft, and manipulating vulnerabilities that most organizations overlook. The lesson? Security isn't about reacting to the breach—it’s about anticipating the next move.

As defenders, our edge isn’t just in patching vulnerabilities but in understanding the mindset of attackers. Every breach, every exploit, and every overlooked detail is a signal: the threat landscape doesn’t wait, and neither should our response. Stay proactive, stay skeptical, and stay ahead.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/03/thn-weekly-recap-router-hacks-pypi.html