Active Exploits Strike Core Infrastructure
Executive Summary
Active Exploits Strike Core Infrastructure
Executive Summary
This week’s threat landscape saw a coordinated surge in real-world exploitation across multiple layers of enterprise infrastructure. CISA added nine vulnerabilities to its KEV catalog, flagging active abuse of three Qualcomm zero-days tied to Adreno GPU flaws, two ASUS router vulnerabilities (including token-based auth bypass and OS command injection), critical RCE chains in Craft CMS, and an improper authentication bug in ConnectWise ScreenConnect and a high-severity use-after-free flaw in Google Chrome’s V8 engine. Beyond the KEV additions, vBulletin forum software is under siege through template injection and unauthorized API access flaws, with public PoC exploit code raising serious concerns over unpatched deployments in the wild. Additionally, Roundcube Webmail is impacted by a critical authenticated RCE vulnerability stemming from improper validation in its upload mechanism, reports indicate the exploit has been actively sold on underground forums.
Botnet activity also surged significantly, as malware families like EnemyBot, Sysrv-K, Andoryu, and Androxgh0st ramped up exploitation efforts targeting known vulnerabilities in platforms including Cloud Gateway, GitLab, and various PHP-based services. In parallel, IoT-focused malware such as Bashlite, BrickerBot, Tsunami, and Mirai aggressively targeted Eir D1000 modems, rapidly expanding their control over exposed devices and amplifying the threat across internet-connected ecosystems.
Advanced threat activity surged as CISA flagged new TTPs used by the Play Ransomware group, including double-extortion tactics and the exploitation of a flaw in the SimpleHelp remote-access tool. Simultaneously, Sekoia reported that over 9,500 ASUS routers were compromised via exposed SSH services in attacks linked to the ViciousTrap threat actor, reflecting the growing overlap between ransomware and IoT-focused operations.
Trending / Critical Vulnerabilities
This week’s report highlights several critical vulnerabilities actively exploited in the wild and added to the CISA KEV catalog. CVE-2025–3935 ConnectWise ScreenConnect enables remote code execution via stolen machine keys, prompting a forensic probe by Google Mandiant. CVE-2025–5419 affects Chrome’s V8 engine, allowing heap corruption through crafted HTML; CVE-2025–21479 and CVE-2025–21480 target Qualcomm chipsets’ Adreno GPU with memory corruption flaws. Another Adreno GPU-related issue, CVE-2025–27038, involves use-after-free vulnerability during rendering. Craft CMS vulnerabilities (CVE-2025–35939 and CVE-2024–56145) permit unauthenticated remote code execution via session and CLI argument abuse. Two vBulletin RCE flaws (CVE-2025–48827, CVE-2025–48828) exploit unauthenticated API and template injection. CVE-2025–49113 in Roundcube Webmail allows authenticated code execution via PHP deserialization. ASUS routers are impacted by OS command injection (CVE-2023–39780) used in botnet activity, and improper authentication (CVE-2021–32030) granting admin access, despite being EoL. All issues demand immediate patching due to confirmed active exploitation. Read More
Exploit Activity and Mass Scanning Observed on Cytellite Sensors
Telemetry collected from Loginsoft sensors was analyzed to derive insights into vulnerabilities that are actively being exploited or scanned. Source IPv4 addresses and payloads are available upon request on a need-to-know basis. This week’s report highlights several critical vulnerabilities under active exploitation. CVE-2024–8503 in VICIdial enables SQL injection leading to data exposure, while CVE-2024–47176 in CUPS can result in remote code execution due to input validation flaws. A critical argument injection in PHP on Windows (CVE-2024–4577) and a command injection in Palo Alto Networks PAN-OS (CVE-2024–3400) are both listed in the CISA KEV catalog. ConnectWise ScreenConnect (CVE-2024–1709) suffers from an authentication bypass flaw, and NetScaler (CVE-2023–4966) is vulnerable to buffer overflow, both with confirmed exploitation. CVE-2023–38646 in Metabase and CVE-2023–26801 in LB-LINK devices pose high RCE risks, while Citrix ADC/Gateway is affected by XSS (CVE-2023–24488), and Ruijie routers (CVE-2023–4415) by improper authentication. TBK DVR devices (CVE-2024–3721) are also exposed to command injection. Immediate patching is advised due to ongoing threats. Read More
Vulnerabilities abused by Botnet
This week’s botnet activity reveals continued exploitation of several longstanding vulnerabilities across various products. CVE-2022–22947, a remote code execution flaw in Spring Cloud Gateway (prior to versions 3.1.1+ and 3.0.7+), is being actively abused by the EnemyBot and Sysrv-K botnets. CVE-2021–22205, a remote code execution vulnerability in GitLab’s ExifTool integration, is targeted by the Andoryu botnet. CVE-2017–9841, which allows arbitrary PHP code execution via PHPUnit’s eval-stdin.php script, is being exploited by AndroxGh0st. Additionally, CVE-2016–10372, an improper protocol access control vulnerability in Eir D1000 modems, continues to be leveraged by multiple botnets including Bashlite, BrickerBot, Tsunami, and Mirai, highlighting the ongoing threat posed by outdated and unpatched IoT infrastructure. Read More
Vulnerabilities Abused by Malware
CVE-2024–57727 affects SimpleHelp Remote Monitoring and Management software and is being leveraged by Play Ransomware operators in a double-extortion campaign targeting over 900 global organizations, as reported in a joint advisory from the FBI, CISA, and Australia’s ASD. Although patched in January 2024, unpatched systems remain at risk. Meanwhile, CVE-2021–32030 in ASUS routers is being actively exploited by the ViciousTrap threat actor, with Sekoia reporting over 9,500 devices potentially compromised via unauthorized SSH access on port 53282. Organizations are urged to apply patches and monitor indicators of compromise. Read More
PRE-NVD observed for this week
The LOVI Platform monitors vulnerabilities that are discovered and potentially exploited before their official inclusion in the National Vulnerability Database (pre-NVD). Aggregating data from open sources and social media, the platform currently tracks over 100 security alerts with plans for further expansion. Recent notable entries include CVE-2025–0088 (Privilege Escalation in Android), CVE-2025–0577 (Insufficient Entropy in glibc), CVE-2025–1272 (Sensitive Information Disclosure in the Linux Kernel), and CVE-2025–30199 (Code Execution affecting ECOVACS DEEBOT Vacuum and Base Station). Read More
For more details, check out the full report.
메타데이터
- post_id
- 9491b1c0443e
- slug
- active-exploits-strike-core-infrastructure-9491b1c0443e
- url
- https://medium.com/@Loginsoft/active-exploits-strike-core-infrastructure-9491b1c0443e
- canonical_url
- https://medium.com/@Loginsoft/active-exploits-strike-core-infrastructure-9491b1c0443e
- author_url
- https://medium.com/@Loginsoft
- status
- ok
- fetched_at
- 2026-06-15 20:49:13