CrushFTP: Patch critical vulnerability ASAP! (CVE-2025-2825)Help Net Security·Jun 8, 10:31 UTC · Jun 8, 2026Vulnerability in the wildCVE-2025-282560
Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched ServersThe Hacker News·Sep 2, 04:43 UTC · Sep 2, 2025Vulnerability in the wildCVE-2025-54309CVE-2025-31161CVE-2024-404060
Critical CrushFTP vulnerability exploited. Have you been targeted? (CVE-2025-54309)Help Net Security·Jun 8, 10:30 UTC · Jun 8, 2026VulnerabilityCVE-2025-54309CVE-2024-4040CVE-2025-282560
New Security Flaws Found in VMware Tools and CrushFTP — High Risk, PoC ReleasedThe Hacker News·Apr 8, 08:12 UTC · Apr 8, 2025Exploit / PoC in the wildCVE-2025-22230CVE-2025-2825CVE-2025-3116160
Critical Update: CrushFTP ZeroThe Hacker News·Apr 27, 05:01 UTC · Apr 27, 2024Exploit / PoC in the wildCVE-2024-404060
CrushFTP Vulnerability Exploited Following Disclosure IssuesInfosecurity Magazine·Apr 3, 16:00 UTC · Apr 3, 2025Vulnerability in the wildCVE-2025-31161CVE-2025-282560
CrushFTP zero-day exploited by attackers, upgrade immediately! (CVE-2024-4040)Help Net Security·Apr 23, 00:00 UTC · Apr 23, 2024Exploit / PoCCVE-2024-404060
New CrushFTP Critical Vulnerability Exploited in the WildInfosecurity Magazine·Jul 21, 14:00 UTC · Jul 21, 2025Exploit / PoC in the wildCVE-2025-54309CVE-2025-3116160
Attackers are targeting CrushFTP vulnerability with public PoC (CVE-2025-2825)Help Net Security·Apr 7, 09:29 UTC · Apr 7, 2025Exploit / PoC in the wildCVE-2025-2825CVE-2025-3116160
CrushFTP Zero-Day actively exploited at least since July 18Security Affairs·Jul 22, 10:31 UTC · Jul 22, 2025Exploit / PoC in the wildCVE-2025-5430960
CrushFTP CVE-2025Security Affairs·Apr 1, 14:09 UTC · Apr 1, 2025Ransomware in the wildCVE-2025-282560
CrushFTP File Transfer Vulnerability Lets Attackers Download System FiInfosecurity Magazine·Apr 22, 12:00 UTC · Apr 22, 2024Vulnerability in the wild60
CISA Warns of CrushFTP Vulnerability Exploitation in the WildInfosecurity Magazine·Apr 8, 12:20 UTC · Apr 8, 2025Exploit / PoC in the wildCVE-2025-31161CVE-2025-2825CVE-2024-282560
+1,400 CrushFTP servers vulnerable to CVE-2024Security Affairs·Apr 26, 09:08 UTC · Apr 26, 2024Exploit / PoC in the wildCVE-2024-404060
CISA adds Cisco ASA and FTD and CrushFTP VFS flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 25, 20:17 UTC · Apr 25, 2024Exploit / PoC in the wildCVE-2024-20353CVE-2024-20359CVE-2024-4040+1 CVEs60
CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active ExploitationThe Hacker News·Apr 8, 15:56 UTC · Apr 8, 2025Exploit / PoC in the wildCVE-2025-31161CVE-2025-2825CVE-2024-282560
U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 24, 06:48 UTC · Jul 24, 2025Exploit / PoC in the wildCVE-2025-54309CVE-2025-6558CVE-2025-2776+2 CVEs60
CISA: Cisco and CrushFTP vulnerabilities are being actively exploitedThe Record·Apr 24, 19:07 UTC · Apr 24, 2024Vulnerability in the wildCVE-2024-20353CVE-2024-20359CVE-2024-404060
CrushFTP urges customers to patch file transfer tool ‘ASAP’The Record·Apr 22, 21:19 UTC · Apr 22, 2024VulnerabilityCVE-2024-404060
CISA, experts warn of Crush file transfer attacks as ransomware gang makes threatsThe Record·Apr 8, 18:07 UTC · Apr 8, 2025Ransomware in the wildCVE-2025-3116160
⚡ Weekly Recap: SharePoint 0-Day, Chrome Exploit, macOS Spyware, NVIDIA Toolkit RCE and MoreThe Hacker News·Jun 10, 04:47 UTC · Jun 10, 2026Vulnerability in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+36 CVEs60
Warning: 3 Critical Vulnerabilities Expose ownCloud Users to Data BreachesThe Hacker News·Nov 29, 03:36 UTC · Nov 29, 2023Data breach in the wildCVE-2023-49103CVE-2023-49105CVE-2023-49104+1 CVEs60
Week in review: Microsoft SharePoint servers under attack, landing your first cybersecurity jobHelp Net Security·Jul 27, 00:00 UTC · Jul 27, 2025Ransomware in the wildCVE-2025-40599CVE-2025-5430960
RCE flaw in MSP-friendly file sharing platform exploited by attackers (CVE-2025-30406)Help Net Security·Apr 14, 16:25 UTC · Apr 14, 2025Vulnerability in the wildCVE-2025-30406CVE-2025-3116160
Week in review: Probing activity on Palo Alto Networks GlobalProtect portals, Patch Tuesday forecastHelp Net Security·Apr 6, 00:00 UTC · Apr 6, 2025Vulnerability in the wildCVE-2025-22457CVE-2024-20439CVE-2025-2825+1 CVEs60
Week in review: Chrome sandbox escape 0-day fixed, Microsoft adds new AI agents to Security CopilotHelp Net Security·Mar 30, 00:00 UTC · Mar 30, 2025RansomwareCVE-2025-2783CVE-2025-2857CVE-2025-2825+1 CVEs160
Week in review: Two Cisco ASA zero-days exploited, MITRE breach, GISEC Global 2024Help Net Security·Apr 28, 00:00 UTC · Apr 28, 2024Policy & legalCVE-2024-20353CVE-2024-20359CVE-2023-46805+4 CVEs60
Fast-moving Storm-1175 uses new exploits to breach networks and drop MedusaSecurity Affairs·Apr 7, 13:21 UTC · Apr 7, 2026Ransomware in the wildCVE-2026-1731CVE-2023-21529CVE-2023-27351+13 CVEs60
Storm-1175 Exploits Flaws in HighInfosecurity Magazine·Apr 7, 10:02 UTC · Apr 7, 2026RansomwareCVE-2025-1003560
China-Linked Storm-1175 Exploits ZeroThe Hacker News·Apr 7, 09:42 UTC · Apr 7, 2026RansomwareCVE-2023-21529CVE-2023-27351CVE-2023-27350+13 CVEs60
The ransomware economy is shifting toward straightCyberScoop·Mar 16, 14:25 UTC · Mar 16, 2026Ransomware in the wild60
CLOP targets Gladinet CentreStack servers in largeSecurity Affairs·Dec 19, 11:48 UTC · Dec 19, 2025Ransomware in the wildCVE-2025-11371CVE-2025-30406CVE-2025-61882+2 CVEs160
Half of Ransomware Access Due to Hijacked VPN CredentialsInfosecurity Magazine·Nov 19, 09:40 UTC · Nov 19, 2025RansomwareCVE-2025-53770CVE-2025-54309CVE-2025-20333+2 CVEs60
Attackers exploited another Gladinet Triofox vulnerability (CVE-2025-12480)Help Net Security·Nov 11, 00:00 UTC · Nov 11, 2025VulnerabilityCVE-2025-12480CVE-2025-30406CVE-2025-31161+1 CVEs60
⚡ Weekly Recap: Chrome 0-Day, IngressNightmare, Solar Bugs, DNS Tactics, and MoreThe Hacker News·Aug 19, 13:08 UTC · Aug 19, 2025Ransomware in the wildCVE-2025-2783CVE-2025-2857CVE-2025-1974+11 CVEs60
Exploited Wing file transfer bug risks ‘total server compromise,’ CISA warnsThe Record·Jul 14, 21:00 UTC · Jul 14, 2025Advisory in the wildCVE-2025-4781260
SentinelOne Warns Cybersecurity Vendors of Chinese AttacksInfosecurity Magazine·Jun 10, 10:30 UTC · Jun 10, 2025VulnerabilityCVE-2024-8963CVE-2024-819060
⚡ Weekly Recap: Chrome 0-Day, IngressNightmare, Solar Bugs, DNS Tactics, and MoreThe Hacker News·May 17, 13:56 UTC · May 17, 2025Ransomware in the wildCVE-2025-2783CVE-2025-2857CVE-2025-1974+11 CVEs60