Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploits
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-10294 | The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to log in as other users, including administrators, on instances where the plugin has not been fully configured yet. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-11499 | The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing fi The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the set_featured_image_from_external_url() function in all versions up to, and including, 1.1.32. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible in configurations where unauthenticated users have been provided with a method for adding featured images, and the workflow trigger is created. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2025-11833 | Unauthenticated Email-Log Access in Post SMTP WordPress Plugin (<= 3.6.0) CVE-2025-11833 is a missing-authorization flaw (CWE-862) in the Post SMTP WordPress plugin: in all versions up to and including 3.6.0, the email-log handling set up in the plugin's __construct function is registered without a capability check, so the log-viewing functionality effectively accepts requests from anyone. Any unauthenticated visitor who can reach the site can therefore read arbitrary emails logged by Post SMTP, including WordPress password-reset emails containing password reset links. By harvesting a reset link addressed to an administrator, an attacker can complete the password reset and take over the account, a full site-admin compromise reflected in the critical 9.8 CVSS score. Any WordPress site running Post SMTP 3.6.0 or earlier is affected, on the order of hundreds of thousands of installations. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is documented yet, but the EPSS of 51% (99th percentile) signals a high probability of exploitation within the next 30 days. Do: Update the Post SMTP plugin to the latest release, since every version through 3.6.0 is vulnerable. Until patched, purge stored email logs, consider temporarily disabling the plugin or blocking its log endpoints with WAF rules, and review the log for password-reset emails sent to administrators; treat any admin account whose reset emails appear in the log as potentially compromised, rotate those credentials, and enable two-factor authentication. | 9.8 | 51% |
| mass≈300,000+ sites (Post SMTP has roughly 300k active installs on WordPress.org) | ||
| CVE-2025-12596 +1 in the same advisory: …12595 | A security vulnerability has been detected in Tenda AC23 16.03.07.52. A security vulnerability has been detected in Tenda AC23 16.03.07.52. Affected is the function saveParentControlInfo of the file /goform/saveParentControlInfo. Such manipulation of the argument Time leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. NVD description · AI analysis pending | 7.4 | 1% | PoC |
| — | |
| CVE-2025-54106 | Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 1% |
| — | ||
| CVE-2025-54897 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 19% |
| — | ||
| CVE-2025-55234 | SMB Relay Elevation of Privilege in Microsoft Windows SMB Server CVE-2025-55234 is an improper authentication flaw (CWE-287) in the Microsoft SMB Server that leaves systems susceptible to credential relay attacks when SMB signing and Extended Protection for Authentication (EPA) are not enforced. It is configuration-dependent: an attacker who can induce an authenticated SMB connection, for example by tricking a user or machine into connecting to attacker-controlled resources, can relay the credentials to another host and authenticate as that user. Successful relaying grants the attacker the privileges of the relayed user, up to elevation of privilege on target systems, with high impact on confidentiality, integrity and availability. Affected systems span Windows 10 (1507 through 22H2), Windows 11 (22H2 through 24H2), and Windows Server 2008, 2012, 2016 and 2019, although only environments without SMB signing/EPA hardening are practically exploitable. As of the September 2025 Patch Tuesday release there is no known in-the-wild exploitation or public proof of concept, but EPSS assigns a 20.1% probability of exploitation within the next 30 days (97th percentile). Do: Install the September 2025 (or later) Microsoft security updates, which add SMB Server Hardening audit capabilities, and use the new audit events to identify clients, servers or legacy software that would break if SMB signing and EPA are enforced. After remediating incompatibilities, enable SMB Server signing and Extended Protection for Authentication on SMB servers to close the relay exposure, prioritizing domain controllers and file servers. Note that systems already enforcing both signing and EPA are not practically exposed. | 9.8 | 20% |
| masshundreds of millions of Windows 10/11 devices plus millions of Windows Server instances are potentially exposed, though only those lacking SMB signing/EPA… | ||
| CVE-2025-59230 | Local Privilege Escalation in Windows Remote Access Connection Manager (RasMan) CVE-2025-59230 is an improper access control flaw (CWE-284) in the Windows Remote Access Connection Manager service that allows an attacker who already has low-privileged access on a machine to gain elevated privileges locally. It is triggered by a local, authenticated user abusing the flawed access checks in the service; no remote or unauthenticated attack path is indicated by the CVSS vector (AV:L/PR:L). A successful exploit yields high impact to confidentiality, integrity and availability on the host, effectively giving the attacker full local control that can support persistence and lateral movement. All listed Windows 10 and Windows 11 releases and Windows Server 2008, 2012 and 2016 are affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-14, coinciding with Microsoft's October 2025 Patch Tuesday (one of six actively exploited zero-days patched that day), though no public PoC is known and ransomware use is unknown. Do: Apply Microsoft's October 2025 security updates for the affected Windows 10/11 and Windows Server releases immediately, prioritizing the per-version updates listed in Microsoft's advisory; as a CISA KEV entry (added 2025-10-14), BOD 22-01 remediation timelines apply for federal agencies. Because exploitation requires local code execution, prioritize hosts where low-privileged users can run code (RDS/VDI servers, kiosks, shared workstations) and verify that clients and servers have pulled the latest cumulative updates rather than relying on HEU state. There is no public PoC or documented mitigation, so patching is the primary defense. | 7.8 | 3% | KEV |
| masshundreds of millions of Windows endpoints and millions of Windows Servers (the listed versions cover essentially the entire supported Windows desktop and… | |
| CVE-2025-59295 | Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. Heap-based buffer overflow in Internet Explorer allows an unauthorized attacker to execute code over a network. NVD description · AI analysis pending | 8.8 | 2% |
| — |
Full article496 words · extracted from helpnetsecurity.com · click to collapse
Malware peddlers are targeting infosec enthusiasts, budding security professionals, and aspiring hackers with the Webrat malware, masquerading the threat as proof-of-concept (PoC) exploits for known vulnerabilities.
Delivering the malware
The recently uncovered Webrat can steal data from Telegram, Discord and Steam accounts and cryptocurrency wallets. It’s also capable of logging keystrokes, recording the computer screen, taking over the machine’s webcam and microphone, and acting as a backdoor through which the attackers can control the system.
The malware is packaged into a password-protected archive that’s offered for download on GitHub, via repositories that ostensibly host PoC exploits for vulnerabilities with high CVSSv3 scores.
The text in the malicious GitHub repositories was likely machine-generated, and the Download Exploit ZIP link in the Download & Install section leads to a password-protected archive hosted in the same repository.
The AI-generated content of the repositories (Source: Kaspersky)
Among the files in the archive file is an executable that escalates its privileges to the administrator level, disables Windows Defender, and fetches Webrat from from a hardcoded URL.
PoC exploits as lures
In this Webrat delivery campaign, which began in September 2025 and was discovered by Kaspersky researchers a month later, the attackers have leveraged vulnerabilities frequently mentioned in security advisories and industry news:
- CVE-2025-10294 (a vulnerability in the OwnID Passwordless Login plugin for WordPress)
- CVE-2025-59295 (a heap-based buffer overflow in Internet Explorer)
- CVE-2025-59230 (an elevation of privilege vulnerability in Windows RasMan)
- CVE-2025-12595 and CVE-2025-12596 (vulnerabilities in the Tenda AC23 wireless router)
- CVE-2025-54897 (a Microsoft SharePoint remote code execution vulnerability)
- CVE-2025-54106 (a vulnerability in Windows Routing and Remote Access Service (RRAS)
- CVE-2025-55234 (an EoP flaw in Windows SMB server)
- CVE-2025-11499 (an unauthenticated arbitrary file upload vulnerability affecting the Tablesome Table WordPress plugin)
- CVE-2025-11833 (a flaw in the Post SMTP WordPress plugin)
“This is not the first time threat actors have tried to lure security researchers with exploits. Last year, they similarly took advantage of the high-profile RegreSSHion vulnerability, which lacked a working PoC at the time,” Kaspersky researchers noted.
Late last year, DataDog researchers discovered a threat actor targeting security researchers and offensive actors by setting up dozens of malicious GitHub repositories with fake or trojanized PoC exploit code.
In 2023, someone tried to push the VenomRat malware onto anyone who might be interested in a PoC exploit for a WinRAR remote code execution vulnerability.
While Kaspersky researchers suggest the campaign primarily targets budding security professionals, it may also be intended to compromise systems used by criminals attempting to integrate newly disclosed vulnerabilities into their own operations.
“This serves as a reminder that cybersecurity professionals, especially inexperienced researchers and students, must remain vigilant when handling exploits and any potentially malicious files. To prevent potential damage to work and personal devices containing sensitive information, we recommend analyzing these exploits and files within isolated environments like virtual machines or sandboxes,” Kaspersky researchers advised.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/12/23/fake-poc-exploits-webrat-malware/