ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 550 by Pierluigi Paganini

criticalRansomware exploited in the wildimportance 60CVE-2025-12480

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-12480
Improper Access Control in Gladinet Triofox Exploited in the Wild

Gladinet Triofox versions prior to 16.7.10368.56560 contain an improper access control flaw (CWE-284) that leaves the product's initial setup pages reachable without authentication even after initial configuration is complete. Because the flaw requires no privileges, user interaction, or special conditions (CVSS:3.1 AV:N/AC:L/PR:N/UI:N), a remote attacker can reach these setup pages on an internet-reachable Triofox server. By re-entering the setup flow, an attacker can reconfigure the deployment, and public reporting indicates attackers abused this to run malicious payloads via the antivirus configuration feature and install remote access tools, producing high confidentiality and integrity impact (C:H/I:H/A:N). Any organization running an affected Triofox version, whether deployed on-premises or as a cloud service, is exposed. The flaw is being actively exploited: Google/Mandiant published a public technical writeup, CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-12, and EPSS puts the 30-day exploitation probability at 90.5% (100th percentile).

Do: Upgrade Triofox to version 16.7.10368.56560 or later per vendor instructions; where patching is not immediately possible, apply vendor mitigations, restrict access to the setup pages, and note that federal agencies must follow CISA BOD 22-01 guidance (including for cloud services) or discontinue use. Given confirmed in-the-wild exploitation, check for compromise: review the antivirus configuration for tampering, hunt for installed remote access tools or unexpected payloads, and audit accounts and configuration changes made after initial setup.

9.191% KEV PoC
  • Gladinet Triofox prior to 16.7.10368.56560
moderateorder of a few thousand internet-facing Triofox deployments (est.), plausibly serving tens of thousands of users

Indicators of compromiseAll →

TypeIndicatorContext
domainbooking.comtter Cybercrime Phishing Campaigns “I Paid Twice” Targeting Booking.com Hotels and Customers Roman Novak, a crypto fraudster, and h
Full article483 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 16, 2025

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

Phishing Campaigns “I Paid Twice” Targeting Booking.com Hotels and Customers

Roman Novak, a crypto fraudster, and his wife were killed in the UAE 

Yanluowang initial access broker pleaded guilty to ransomware attacks

Man and woman jailed for their roles in multibillion-pound fraudulent Bitcoin scheme   

Google sues cybercriminal group behind E-ZPass, USPS text phishing scams 

The Great Indonesian TEA Theft: Analyzing a NPM Spam Campaign  

End of the game for cybercrime infrastructure: 1025 servers taken down 

Thousands of Domains Target Hotel Guests in Massive Phishing Campaign

New Scam Center Strike Force Battles Southeast Asian Crypto Investment Fraud Targeting Americans  

Malware

9 Malicious NuGet Packages Deliver Time-Delayed Destructive Payloads

Q3 2025 Ransomware Report

Fantasy Hub: Another Russian Based RAT as M-a-a-S   

Unleashing the Kraken ransomware group 

Malicious Chrome Extension Exfiltrates Seed Phrases, Enabling Wallet Takeover  

Hacking

Whisper Leak: A novel side-channel attack on remote language models 

No Place Like Localhost: Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480  

Dangerous runC flaws could allow hackers to escape Docker containers

CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Attacks

Suspected Fortinet zero-day exploited in the wild

Critical Vulnerability in Fortinet FortiWeb Exploited in the Wild 

Critical: Remote Code Execution via Malicious Obfuscated Malware in Imunify360 AV (AI-bolit)  

Multiple Vulnerabilities in GoSign Desktop leads to Remote Code Execution  

Intelligence and Information Warfare

Samsung Spyware Attack — Critical Landfall 0-Day Exploited 

Australia Sanctions Hackers Supporting North Korea’s Weapons Program  

Top US Army General Says He’s Letting ChatGPT Make Military Decisions

State-Sponsored Remote Wipe Tactics Targeting Android Devices      

Why a lot of people are getting hacked with government spyware  

It’s time to reckon with the geopolitics of artificial intelligence  

Amazon discovers APT exploiting Cisco and Citrix zero-days

Disrupting the first reported AI-orchestrated cyber espionage campaign  

Iranian Hackers Launch ‘SpearSpecter’ Spy Operation on Defense & Government Targets

Contagious Interview Actors Now Utilize JSON Storage Services for Malware Delivery  

Justice Department Announces Nationwide Actions to Combat Illicit North Korean Government Revenue Generation

Cybersecurity

Fearing vulnerability to China, Europe has a new worry: Electric buses 

ENISA Sectorial Threat Landscape – Public Administration

Meta is earning a fortune on a deluge of fraudulent ads, documents show  

Drilling Down on Uncle Sam’s Proposed TP-Link Ban  

The November 2025 Security Update Review  

Firefox expands fingerprint protections: advancing towards a more private web 

Evasion Attacks on LLMs – Countermeasures in Practice

Elon Musk’s X botched its security key switchover, locking users out

CISA Updates Guidance on Patching Cisco Devices Targeted in China-Linked Attacks  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/184688/breaking-news/security-affairs-newsletter-round-550-by-pierluigi-paganini-international-edition.html