Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Friday, April 11, 2025

Network Infraxploit; Windows Hello Broken; Dell Update; Langflow Exploit

https://isc.sans.edu/podcastdetail/9404

Network Infraxploit

Our undergraduate intern, Matthew Gorman, wrote up a walk-through of

CVE-2018-0171, an older Cisco vulnerability, that is still actively being

exploited. For example, VOLT TYPHOON recently exploited this problem.

https://isc.sans.edu/diary/Network+Infraxploit+Guest+Diary/31844

Windows Update Issues / Windows 10 Update

Microsoft updated its "Release Health" notes with details regarding issues

users experiences with Windows Hello, Citrix, and Roblox. Microsoft also released an emergency update for Office 2016 which has stability problems after applying the most recent update.

https://support.microsoft.com/en-us/topic/april-8-2025-kb5055523-os-build-26100-3775-277a9d11-6ebf-410c-99f7-8c61957461eb

https://learn.microsoft.com/en-us/windows/release-health/windows-message-center#3521

https://support.microsoft.com/en-us/topic/april-10-2025-update-for-office-2016-kb5002623-d60c1f31-bb7c-4426-b8f4-69186d7fc1e5

Dell Updates

Dell releases critical updates for its Powerscale One FS product. In particular, it fixes a default password problem.

https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities

Langflow Vulnerability (possible exploit scans sighted) CVE-2025-3248

Langflow addressed a critical vulnerability end of March. This writeup by Horizon3 demonstrates how the issue is possibly exploited. We have so far seen one "hit" in our honeypot logs for the vulnerable API endpoint URL.

https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai/

SANS Internet Storm Center StormCast Thursday, April 10, 2025

Getting Past PyArmor; CenterStack RCE; Android 0-Day Patch; VMware Tanzu Patches; Odd Win11 Directory; WhatsApp File Confusion; SANS AI Guide

https://isc.sans.edu/podcastdetail/9402

Getting Past PyArmor

PyArmor is a python obfuscation tool used for malicious and non-malicious software. Xavier is taking a look at a sample to show what can be learned from these obfuscated samples with not too much work.

https://isc.sans.edu/diary/Obfuscated+Malicious+Python+Scripts+with+PyArmor/31840

CentreStack RCE CVE-2025-30406

GladinetÕs CentreStack secure file-sharing software suffers from an inadequately protected machine key vulnerability that can be used to modify ViewState data. This vulnerability may lead to remote code execution, which is already exploited.

https://gladinetsupport.s3.us-east-1.amazonaws.com/gladinet/securityadvisory-cve-2005.pdf

Google Patches two zero-day vulnerabilities CVE-2024-53150 CVE-2024-53197

Google released its monthly patches for Android. Two of the patched vulnerabilities are already exploited. One of them was used by Serbian law enforcement.

https://www.malwarebytes.com/blog/news/2025/04/google-fixes-two-actively-exploited-zero-day-vulnerabilities-in-android

Broadcom VMWare Tenzu Updates

Broadcom released updates for VMWare Tenzu. Many vulnerabilities affect the backup component and allow for arbitrary command execution.

https://support.broadcom.com/web/ecx/security-advisory?

Windows 11 April Update ads inetpub directory

The April Windows 11 update appears to create a new /inetpub directory. It is unclear why, and removing it appears to have no bad effects.

https://www.bleepingcomputer.com/news/microsoft/windows-11-april-update-unexpectedly-creates-new-inetpub-folder/

WhatsApp File Type Confusion/Spoofing

WhatsApp patched a file type confusion vulnerability. A victim may be tricked into downloading an executable disguised as an image

https://www.whatsapp.com/security/advisories/2025/

SANS Critical AI Security Guidelines

https://www.sans.org/mlp/critical-ai-security-guidelines

SANS Internet Storm Center StormCast Wednesday, April 9, 2025

Microsoft Patch Tuesday; Adobe Patches; OpenSSL 3.5 with PQC; Fortinet FortiSwitch

https://isc.sans.edu/podcastdetail/9400

Microsoft Patch Tuesday

Microsoft patched over 120 vulnerabilities this month. 11 of these were rated critical, and one vulnerability is already being exploited.

https://isc.sans.edu/diary/Microsoft+April+2025+Patch+Tuesday/31838

Adobe Updates

Adobe released patches for 12 different products. In particular important are patches for ColdFusion addressing several remote code execution vulnerabilities. Adobe Commerce got patches as well, but none of the vulnerabilities are rated critical.

https://helpx.adobe.com/security/security-bulletin.html

OpenSSL 3.5 Released

OpenSSL 3.5 was released with support to post quantum ciphers. This is a long term support release.

https://groups.google.com/a/openssl.org/g/openssl-project/c/9ZYdIaExmIA

FortiSwitch Update

Fortinet released an update for FortiSwitch addressing a vulnerability that may be used to reset a password without verification.

https://fortiguard.fortinet.com/psirt/FG-IR-24-435

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive