CISA has added a critical vulnerability in Wing FTP Server, identified as CVE-2025-47812, to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation.
This flaw allows unauthenticated remote attackers to achieve complete system compromise.
Vulnerability Details
Affected Product: Wing FTP Server versions prior to 7.4.4
Identifier: CVE-2025-47812
CVSS Score: 10.0 (Critical)
Exploitation Status: Actively Exploited
Risk & Impact
Triage:Urgent. Immediate patching is required due to active, widespread exploitation and the availability of public exploits.
Attack Vector: An unauthenticated remote attacker can send a crafted login request with a NULL byte and malicious Lua code in the username parameter. The server improperly processes this input, allowing the injected code to be written to a session file and executed with SYSTEM or root privileges.
Ease of Exploit:Low. The attack complexity is low, requires no privileges, and no user interaction.
Action Plan
Immediate Action: Upgrade to Wing FTP Server version 7.4.4 or later.
Workaround: If immediate patching is not possible, restrict HTTP/HTTPS access to the web interface, disable anonymous login functionality, and monitor session directories for unusual file activity.
Detection: Monitor for unauthorized user accounts (e.g., "wing," "wingftp") and review logs for login attempts where the username is not properly terminated, which may indicate a NULL-byte injection attempt.
Relevant professional terms
Remote Code Execution (RCE)
The ability of an attacker to execute arbitrary commands or code on a target machine over a network, often leading to full system compromise.
NULL Byte Injection
A security exploit where an attacker injects a NULL character (%00) into user-supplied data to bypass security checks. In this case, it tricks the application into truncating the input string, allowing malicious code that follows the NULL byte to be processed.
A series of high-severity vulnerabilities, including CVE-2025-61591 and CVE-2025-59944, have been disclosed in the Cursor AI code editor.
These flaws allow for remote code execution through various methods, such as the abuse of Model Context Protocol (MCP) deeplinks and prompt injection, and have been patched in updated versions.
Vulnerability Details
Affected Product: Cursor IDE (versions 1.7 and below).
Identifier: CVE-2025-61591, CVE-2025-59944, and others.
CVSS Score: Up to 8.8 (High).
Exploitation Status: Proof-of-concept code is available.
Risk & Impact
Triage: Urgent. Developers operate with elevated permissions, and a compromise could expose sensitive assets like API keys, credentials, and source code.
Attack Vector: Social engineering is used to trick a user into clicking a malicious deeplink. This action, when combined with approving a subsequent installation prompt, can lead to the execution of arbitrary commands with the user's privileges.
Ease of Exploit: The attack is not zero-click and relies on user interaction. However, the installation dialogues do not distinguish between trusted and untrusted sources, making it easier to disguise malicious payloads.
Action Plan
Immediate Action: Users on versions 1.6.23 or below should upgrade to Version 1.7 immediately. Users on version 1.7 should apply security patch 2025.09.17-25b418f.
Workaround: For some vulnerabilities, enabling "Workspace Trust" within Cursor can prevent automatic code execution upon opening a project.
Detection: Monitor for unusual command-line executions originating from the Cursor IDE, especially those involving the modification of configuration files like `.cursor/mcp.json`.
Relevant professional terms
Deeplink
A custom URL scheme that, when clicked, launches a specific application (in this case, the Cursor IDE) and can be used to pass data or commands directly to it.
Attack Vector
The method or pathway a malicious actor uses to gain unauthorized access to a computer system or network to exploit its vulnerabilities.
South Korea's National Tax Service (NTS) inadvertently published the mnemonic recovery phrase for a seized cryptocurrency wallet in a press release.
This error allowed an unknown individual to steal approximately $4.8 million in digital assets.
Attack Overview
Attack Path: The NTS included high-resolution photos in a press release that showed a handwritten note with the wallet's mnemonic recovery phrase, providing direct access to the funds.
Attacker: Unknown/Opportunistic Actor.
Impact Assessment
Data Stolen: Approximately $4.8 million in Pre-Retogeum (PRTG) tokens were transferred from the compromised wallet.
Strategic Takeaway
This incident underscores the critical failure of operational security, highlighting that sensitive data like cryptographic keys requires stringent handling protocols to prevent immediate and irreversible loss.
Relevant professional terms
Mnemonic Recovery Phrase
A sequence of words that stores all the information needed to recover a cryptocurrency wallet, acting as a master key.
Cold Wallet
A cryptocurrency wallet that is not connected to the internet, designed to provide greater security against online threats like hacking.
Medical technology giant Stryker suffered a major cyberattack where an Iran-linked group wiped tens of thousands of employee devices by abusing the company's internal Microsoft Intune environment. The attack caused a global network disruption without using traditional malware.
Attack Overview
Attack Path: Attackers compromised an administrative account for Microsoft Intune and used its legitimate remote wipe functionality to erase all managed devices.
Attacker:Handala (Iran-linked group).
Impact Assessment
Operational Impact: Tens of thousands of devices, including laptops and mobile phones, were remotely wiped, causing a global system outage and forcing office shutdowns in 79 countries.
Strategic Takeaway
This incident highlights the critical risk of "living-off-the-land" attacks, where legitimate administrative tools are weaponized to bypass traditional security controls and cause widespread disruption.
Relevant professional terms
Wiper Attack
A type of cyberattack intended to permanently destroy or erase data on a target's systems, often for sabotage rather than financial gain.
Microsoft Intune
A cloud-based endpoint management service that allows organizations to manage and secure devices like laptops and mobile phones.
Boggy Serpens (MuddyWater), an Iranian state-sponsored cyberespionage group, is enhancing its campaigns with AI-generated malware and refined social engineering.
The group targets government, military, and critical infrastructure entities across the Middle East and other strategic locations to gather intelligence.
Key TTPs
Initial Access: Spear phishing campaigns and exploiting trusted relationships by hijacking legitimate internal accounts.
Execution: Abusing legitimate remote monitoring and management (RMM) tools and using malicious macros in weaponized documents.
Defense Evasion: Using AI-enhanced malware with anti-analysis features and leveraging the Telegram API for C2 communications to blend in with legitimate traffic.
Campaign Analysis
Boggy Serpens has shifted from high-volume, low-sophistication attacks to stealthier operations focused on long-term persistence. The group now employs AI-generated code and custom backdoors to rapidly develop and deploy implants, indicating a significant increase in technological capability and resources.
Targeting & Infrastructure
Target Profile: Government, military, diplomatic missions, and critical infrastructure, including maritime, aviation, energy, and finance sectors.
Infrastructure: Utilizes compromised accounts, VPN services, and the Telegram Bot API for command and control (C2).
Actionable Intelligence
Domains:googleonlinee[.]com
Relevant Terms
Cyberespionage: The use of computer networks to gain illicit access to confidential information, typically held by a government or other organization.
C2 (Command and Control): The infrastructure (servers and software) used by threat actors to communicate with and control compromised devices (bots, implants).
Iranian state-sponsored threat actors are evolving their tactics, shifting from deploying custom wiper malware to sophisticated identity-based attacks.
These campaigns leverage legitimate administrative tools to achieve destructive effects at scale, targeting organizations globally.
Key TTPs
Initial Access: Spear-phishing, password spraying, and exploiting public-facing applications are common methods to gain initial entry.
Execution: Abusing legitimate remote management and cloud administration tools (e.g., MDM/RMM platforms) to issue destructive commands like remote wipes.
Defense Evasion: Using "living-off-the-land" (LotL) techniques by operating through legitimate tools and compromised high-privilege identities to blend in with normal network activity.
Campaign Analysis
This strategic shift from custom malware to identity weaponization allows attackers to bypass traditional endpoint security and achieve greater scale and evasion. By compromising administrative accounts, actors can use built-in system features as weapons, making detection significantly more challenging for defenders.
Targeting & Infrastructure
Target Profile: Broad targeting includes government, defense, telecommunications, energy, and technology sectors, with a focus on the U.S., Europe, and the Middle East.
Infrastructure: Actors leverage cloud services for command and control and often operate under hacktivist personas like "Void Manticore" (Handala) to create plausible deniability.
Relevant Terms
MBR Wipers: Malicious software designed to erase the Master Boot Record of a hard drive, which contains information on how the operating system loads, rendering the system unbootable.
Identity Weaponization: A tactic where attackers compromise and misuse high-privilege user accounts and administrative credentials to control and damage systems, effectively turning legitimate access into a weapon.
A novel attack technique uses custom fonts and CSS to display malicious commands to a user while hiding them from AI assistants that analyze the underlying HTML. This creates a dangerous perception gap between what a human sees and what the AI model processes.
Key Findings
The technique, developed by researchers at LayerX, uses custom fonts to remap characters via glyph substitution, making the malicious text unreadable to AI in the HTML.
Attackers can use social engineering to convince a user to execute a command that appears harmless on-screen, but which an AI assistant would incorrectly validate as safe.
As of December 2025, the method was effective against numerous AI assistants, including ChatGPT, Gemini, and Copilot.
The Bottom Line
This attack vector exposes a fundamental flaw in how AI models ingest and interpret web content. It bypasses content filters by exploiting the browser's rendering layer, creating a new attack surface.
This method proves that security models cannot blindly trust the raw HTML of a page and must account for visual deception, fundamentally challenging the reliability of AI-driven webpage analysis and summarization tools.
Relevant Terms
Font Rendering: The process by which a computer system interprets font data and displays text on a screen. Attackers can manipulate this process to show different content to the user than what exists in the source code.
Glyph: An individual letter, number, or symbol within a font. This attack substitutes the expected glyphs with malicious ones that appear correct to the user but are represented by different, harmless characters in the code.