CISA has added CVE-2025-47813, an information disclosure vulnerability in Wing FTP Server, to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation.
The flaw allows authenticated attackers to discover the full local installation path of the application.
Vulnerability Details
Affected Product: Wing FTP Server versions prior to 7.4.4
Identifier: CVE-2025-47813
CVSS Score: 4.3 (Medium)
Exploitation Status: Actively Exploited
Risk & Impact
Triage: Immediate patching is required due to inclusion in the CISA KEV catalog.
Attack Vector: An authenticated attacker can send a long value in the UID cookie to the `loginok.html` endpoint, causing the server to return an error message that contains the full local installation path.
Ease of Exploit: The exploit requires low privileges, as an authenticated session is necessary to manipulate the session cookie.
Action Plan
Immediate Action: Upgrade Wing FTP Server to version 7.4.4 or later.
Workaround: Restrict access to the web interface to trusted IP addresses to limit exposure.
Detection: Monitor web server logs for requests to `loginok.html` with unusually long UID cookie values.
Relevant professional terms
Known Exploited Vulnerabilities (KEV) Catalog
A list curated by CISA of vulnerabilities that have been confirmed through evidence to be actively exploited in the wild, helping organizations prioritize remediation.
Information Disclosure Vulnerability
A security flaw where an application unintentionally reveals sensitive information, such as system paths or configuration details, to unauthorized users.
A security issue has been identified in AWS Bedrock's Code Interpreter that could allow for data exfiltration from sandboxed environments.
AWS has reviewed the issue and states it is intended functionality, updating documentation to clarify that the sandbox mode has limited network access.
Triage: Medium - Immediate review of IAM policies for Bedrock agents is recommended.
Attack Vector: An attacker can craft malicious instructions within files processed by the interpreter. These instructions leverage DNS resolution, which remains active in the sandbox, to create a covert channel for exfiltrating data, such as credentials or S3 bucket contents.
Ease of Exploit: Trivial, if an attacker can influence code execution within the interpreter.
Action Plan
Immediate Action: AWS has updated its documentation to clarify the networking capabilities of the sandbox mode. Customers should review and apply the principle of least-privilege to IAM roles assigned to code interpreters.
Workaround: Administrators should inventory all active AgentCore Code Interpreter instances and migrate any that handle sensitive data to environments with stricter network controls.
Detection: Monitor CloudTrail for unusual invocation activity, though this may require enabling Data Events which can incur extra costs. Basline and monitor for anomalous agent behavior, data access, and tool invocation patterns.
Relevant professional terms
Data Exfiltration
The unauthorized transfer of data from a computer or server. In this context, it refers to using DNS queries to sneak sensitive information out of the supposedly isolated AWS environment.
Sandbox
A security mechanism for separating running programs, usually in an effort to mitigate system failures or software vulnerabilities from spreading. In this case, the AWS Bedrock sandbox's network restrictions were not as complete as might be assumed.
Poland's National Centre for Nuclear Research (NCBJ) successfully detected and blocked a cyberattack targeting its IT infrastructure.
Early detection by security systems prevented any data compromise or operational impact on the facility, including its MARIA research reactor.
Attack Overview
Attack Path: The specific initial access vector has not been disclosed; however, officials noted that the entry points were traced to Iranian infrastructure.
Attacker:Iranian-linked actors (Suspected)
Impact Assessment
Data Stolen: No data was leaked from the center.
Operational Impact: No operational, production, or research processes were disrupted. The MARIA reactor remained safe and at full power.
Strategic Takeaway
The successful defense highlights the importance of robust, pre-emptive security monitoring for critical infrastructure, though attribution remains cautious as the indicators could be a false flag.
Relevant professional terms
False Flag
A clandestine operation designed to deceive in such a way that activities appear as though they are being carried out by entities, groups, or nations other than those who actually planned and executed them.
Critical Infrastructure
Assets, systems, and networks, whether physical or virtual, that are considered so vital to a country that their incapacitation or destruction would have a debilitating effect on security, national economic security, or public health and safety.
Threat actors are compromising WordPress websites to display fake verification pages, tricking Windows users into downloading and installing the Vidar information stealer.
This malware is designed to harvest a wide range of sensitive data from browsers, cryptocurrency wallets, and other applications.
Key TTPs
Initial Access: Delivered via social engineering on compromised websites, malvertising, and phishing emails containing malicious attachments.
Execution: A user is tricked into running a malicious installer disguised as legitimate software or a verification step.
Defense Evasion: Employs file bloating to exceed antivirus scan limits, uses obfuscation techniques like control flow flattening, and may self-destruct after data exfiltration to remove traces.
Campaign Analysis
This campaign leverages trusted, albeit compromised, infrastructure to bypass user suspicion and distribute malware effectively.
Vidar continues to evolve, with newer versions rewritten for efficiency and incorporating advanced methods to bypass browser security features.
Targeting & Infrastructure
Target Profile: Windows operating system users.
Infrastructure: Utilizes compromised WordPress sites for distribution and social media platforms like Telegram for Command and Control (C2) communications.
Relevant Terms
Infostealer: A type of malware designed specifically to collect and exfiltrate sensitive information from a victim's computer, such as login credentials, financial data, and browser history.
C2 (Command and Control): The server infrastructure that attackers use to send commands to compromised systems and receive stolen data.
The GoPix banking trojan targets Brazilian users of the PIX instant payment system through malvertising. It employs sophisticated, memory-only implants and clipboard hijacking to intercept and redirect financial transactions to attacker-controlled accounts.
Key TTPs
Initial Access: Malicious ads on search engines, often impersonating "WhatsApp Web," lead to fake download pages.
Execution: Injects payload into the legitimate 'svchost.exe' process using process hollowing.
Defense Evasion: Uses multiple obfuscation layers and checks for security software before deploying different payload versions.
Campaign Analysis
GoPix represents a significant evolution in Brazilian banking malware, adopting techniques from APT groups to enhance stealth and persistence. The malware uses short-lived C2 infrastructure and abuses legitimate anti-fraud services to filter its victims, indicating a targeted and sophisticated operation.
Targeting & Infrastructure
Target Profile: Users of Brazil's PIX payment system, including customers of financial institutions and cryptocurrency users.
Infrastructure: Abuses Google Ads for distribution and legitimate services like IPQualityScore to vet targets and evade analysis environments.
Relevant Terms
Process Hollowing: A defense evasion technique where an attacker creates a new process in a suspended state and replaces its legitimate code with malicious code.
Malvertising: The use of online advertising to spread malware, where malicious ads are placed on legitimate websites to redirect users to malware-hosting sites.
Threat actors are abusing the legitimate LiveChat SaaS platform in a social engineering campaign. By impersonating trusted brands like PayPal and Amazon, they engage victims in real-time chats to steal credentials, credit card details, and other sensitive personal information.
Key TTPs
Initial Access: Phishing emails with lures of refunds or pending orders contain links that direct users to a malicious LiveChat page.
Execution: A human operator, likely following a script, uses social engineering during the live chat to manipulate the victim into divulging financial and personal data.
Campaign Analysis
This campaign marks an evolution in phishing tactics by leveraging a trusted, real-time communication platform to build rapport and disarm victims. The interactive nature of the attack makes it harder to detect compared to traditional static phishing pages.
Targeting & Infrastructure
Target Profile: Customers of major brands such as PayPal and Amazon.
Infrastructure: The attack abuses legitimate LiveChat services, with phishing URLs often containing the domain lc[.]chat.
Relevant Terms
Social Engineering: A manipulation technique used to trick individuals into divulging confidential information or performing specific actions.
Phishing: A cybercrime where attackers impersonate legitimate organizations via email, text, or other channels to steal sensitive data like login credentials and credit card numbers.
The threat actor Storm-2561 is using SEO poisoning to lead users to malicious websites that distribute trojanized VPN client installers. The goal is to harvest VPN credentials from unsuspecting users searching for legitimate enterprise software.
Key TTPs
Initial Access: SEO poisoning redirects users searching for VPN software to attacker-controlled websites.
Execution: A malicious MSI installer side-loads a trojanized DLL (inspector.dll), a variant of the Hyrax infostealer.
Defense Evasion: The malware is digitally signed with a legitimate, now-revoked, certificate to appear trustworthy.
Campaign Analysis
This campaign abuses trust in search engine rankings and software branding to deliver malware. After stealing credentials, the malware displays a fake error and directs the user to the legitimate VPN software, reducing suspicion of compromise.
Targeting & Infrastructure
Target Profile: Users of enterprise VPN software from vendors like Ivanti (Pulse Secure), Fortinet, and Cisco.
Infrastructure: Malicious ZIP files were hosted on GitHub and distributed via spoofed domains.
Actionable Intelligence
IPs:194.76.226[.]93
Domains:vpn-fortinet[.]com, ivanti-vpn[.]org
Relevant Terms
SEO Poisoning: The technique of manipulating search engine results to promote malicious websites to the top of rankings for specific keywords.
DLL Side-Loading: An attack where a legitimate application is tricked into loading a malicious Dynamic Link Library (DLL), allowing the malware to execute under the trusted application's process.