Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature
On Monday, Google’s Mandiant Threat Defense announced that it had identified the n-day exploitation of a security vulnerability in Gladinet’s Triofox file-sharing and remote access platform, which has since been fixed.
The serious vulnerability, identified as CVE-2025-12480 (CVSS score: 9.1), enables an attacker to circumvent authentication and reach the configuration pages, which leads to the uploading and execution of arbitrary payloads.
The technology behemoth stated that it had seen a threat cluster monitored as UNC6485 using the vulnerability as a weapon dating back to August 24, 2025—this was almost one month after Gladinet issued fixes for the vulnerability in version 16.7.10368.56560. CVE-2025-12480 marks the third vulnerability in Triofox that has been actively exploited th...


