Updaten: Warnung vor Angriffen auf Apple-Lücken und Gladinet

Die CISA warnt vor laufenden Angriffen auf Schwachstellen in Apples iOS und macOS sowie auf Gladinet CentreStack und Triofox.

heise online
CLOP targets Gladinet CentreStack servers in large-scale extortion campaign

The Clop ransomware group is targeting Gladinet CentreStack file servers in a new large-scale extortion campaign.

Security Affairs
CVE Alert: CVE-2025-14611 - Gladinet - CentreStack and TrioFox - RedPacket Security

Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades

RedPacket Security
CRITICAL: Active exploitation of Gladinet CentreStack & Triofox via hard-coded keys in GenerateSecKey(). Attackers gain persistent access + RCE by forging tickets at /storage/filesvr.dn. Patch to v16.12.10420.56791 & rotate machine keys now! https://radar.offseq.com/threat/active-attacks-exploit-gladinets-hard-coded-keys-f-43cb43d6 #OffSeq #CyberSecurity #Gladinet #RCE
⚠️ CISA adds Gladinet & CWP flaws Cybersecurity and Infrastructure Security Agency (#CISA) has officially added vulnerabilities in #Gladinet Cloud Enterprise and #CWP to its Known Exploited Vulnerabilities list, urging immediate patching across US organizations and supply chains. #ransomNews #CVE
U.S. CISA adds Gladinet CentreStack, and CWP Control Web Panel flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Gladinet CentreStack, and CWP Control Web Panel flaws to its Known Exploited Vulnerabilities catalog.

Security Affairs
CVE Alert: CVE-2025-11371 - Gladinet - CentreStack and TrioFox - RedPacket Security

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows

RedPacket Security
Une zero day exploitée dans les serveurs de partage de fichiers Gladinet - Le Monde Informatique

Déjà touchés en avril dernier par une faille de sécurité, les serveurs de partage de fichiers CentreStack et Triofox de Gladinet sont encore exposés...

LeMondeInformatique
🚨 CRITICAL zero-day in Gladinet file sharing software being actively exploited. No patch or CVE yet. All organizations using Gladinet—especially in Europe—should restrict usage, monitor for anomalies, and prep IR. https://radar.offseq.com/threat/hackers-exploiting-zero-day-in-gladinet-file-shari-edeb0bb5 #OffSeq #ZeroDay #Gladinet #ThreatIntel

A single overlooked line of code turned a trusted file-sharing platform into a ticking time bomb. How can proactive defenses and real-time threat detection keep our data safe?

https://thedefendopsdiaries.com/mitigation-strategies-for-zero-day-vulnerability-in-gladinet-file-sharing-software/

#zero-day
#gladinet
#vulnerabilitymanagement
#threatdetection
#cybersecurity
#patchmanagement
#localfileinclusion
#incidentresponse
#zerotrust

Mitigation Strategies for Zero-Day Vulnerability in Gladinet File Sharing Software

Explore effective mitigation strategies for the Gladinet zero-day vulnerability, including code fixes, patching, and advanced threat detection.

The DefendOps Diaries