On March 21st, CrushFTP released an announcement that their file transfer software suite was affected by a critical HTTP authentication bypass vulnerability that could result in unauthorized access to sensitive data hosted on CrushFTP servers. The vulnerability was later identified as CVE-2025-31161 and affects CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0.
Apr 17, 2025 - 4 Min Read
On or about April 3rd, 2025 a critical deserialization vulnerability in Gladinet’s CentreStack and Triofox platforms was publicly released as CVE-2025-30406. The vulnerability arises from the use of hardcoded machineKey values in both their underlying Internet Information Services (IIS) configuration files.
Apr 17, 2025 - 4 Min Read
On April 3rd, Ivanti released an advisory for a critical vulnerability in their VPN and network access control products Connect Secure, Policy Secure, and ZTA Gateways. Successfully exploiting the vulnerability would enable an unauthenticated threat actor to achieve remote code execution (RCE) on a target device. This family of products are, by design, deployed on customer networks as internet facing, so this vulnerability can provide threat actors initial access to organization networks.
Apr 4, 2025 - 3 Min Read
On March 20th, a user on BreachForums claimed to have compromised Oracle Cloud Infrastructure (OCI). The breach reportedly affected servers responsible for authenticating users to Oracle Cloud services. The individual provided sample data to support their claim and offered to sell access to “about 6 million” credentials and authentication materials for 100,000 Monero (XMR), a cryptocurrency considered more difficult to trace than bitcoin. The threat actor is offering to remove any compromised accounts from the data dump for an unspecified payment and to trade breach information for 0-day exploits. This post was updated on March 26th, 2025 with additional information.
Mar 24, 2025 - 12 Min Read
On March 19th, backup solution vendor Veeam published an advisory detailing a critical vulnerability in their Backup and Replication product. This product is used as a data backup and restoration solution, and the vulnerability is due to a deserialization bug that would allow an authenticated attacker to achieve remote code execution (RCE) on a targeted device. Ransomware threat actors often target Veeam to steal and destroy backups, and they could opportunistically leverage this vulnerability to enhance the impact and destruction of victim files.
Mar 21, 2025 - 3 Min Read
Beazley Security has identified multiple cybercriminal campaigns leveraging deceptive advertisements and fake CAPTCHA pages to distribute malware.
Mar 17, 2025 - 3 Min Read
A path traversal flaw in Ivanti Endpoint Manager running versions 2024 November Security Update and prior or 2022 SU6 November Security Update and prior allows for leakage of sensitive information by a remote, unauthenticated attacker.
Mar 13, 2025 - 5 Min Read
On March 4th, 2025, Broadcom published an advisory detailing multiple critical vulnerabilities in VMWare ESXi. Two of the vulnerabilities (CVE-2025-22224 and CVE-2025-22225) can be used together to allow a successful attacker with local administrator privileges on a hosted virtual machine to escape the virtual machine and execute code on the hypervisor. Beazley Security is aware of active exploitation of this vulnerability by sophisticated attackers and strongly recommends affected organizations apply updates from Broadcom to their ESXi clusters as soon as possible.
Mar 5, 2025 - 4 Min Read
On January 15th, multiple vulnerabilities were reported in SimpleHelp’s Remote Support Software product. One of the vulnerabilities, CVE-2024-57727, would allow successful attackers to access arbitrary files on a victim’s server, including sensitive configuration files containing passwords.
Feb 26, 2025 - 4 Min Read
On January 7th, Sonicwall published an advisory regarding an improper authentication vulnerability in their SonicOS SSL VPN service. Criticality of this vulnerability was enhanced February 10, 2025 when trivial proof-of-concept code emerged, and attacks began being observed in the wild.
Feb 20, 2025 - 4 Min Read