Tag: Remote Access Tools

Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature
News

Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature

On Monday, Google’s Mandiant Threat Defense announced that it had identified the n-day exploitation of a security vulnerability in Gladinet’s Triofox file-sharing and remote access platform, which has since been fixed. The serious vulnerability, identified as CVE-2025-12480 (CVSS score: 9.1), enables an attacker to circumvent authentication and reach the configuration pages, which leads to the uploading and execution of arbitrary payloads. The technology behemoth stated that it had seen a threat cluster monitored as UNC6485 using the vulnerability as a weapon dating back to August 24, 2025—this was almost one month after Gladinet issued fixes for the vulnerability in version 16.7.10368.56560. CVE-2025-12480 marks the third vulnerability in Triofox that has been actively exploited th...
Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools
News

Hackers Exploiting Critical Fortinet EMS Vulnerability to Deploy Remote Access Tools

Malicious actors are using a now-patched serious security issue that affects Fortinet FortiClient EMS as part of a cyber campaign that installs remote desktop programs like AnyDesk and ScreenConnect. The SQL injection vulnerability in question is CVE-2023-48788 (CVSS score: 9.3), which enables attackers to submit specially constructed data packets and execute unauthorized code or commands. The October 2024 attack, according to Russian cybersecurity firm Kaspersky, targeted a Windows server belonging to an unidentified corporation that was open to the internet and had two open ports connected to FortiClient EMS. According to a Thursday investigation, the targeted organization uses this technology to enable staff members read more about Hackers Exploiting Critical Fortinet EMS Vuln...