Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Friday, June 27, 2025

Open-VSX Flaw; Airoha Bluetooth Vulnerability; Critical Cisco Identity Service Engine Vuln

https://isc.sans.edu/podcastdetail/9508 Open-VSX Flaw Puts Developers at Risk

A flaw in the open-vsx extension marketplace could have let to the compromise of any extension offered by the marketplace.

https://blog.koi.security/marketplace-takeover-how-we-couldve-taken-over-every-developer-using-a-vscode-fork-f0f8cf104d44

Bluetooth Vulnerability Could Allow Eavesdropping

A vulnerability in the widely used Airoha Bluetooth chipset can be used to compromise devices and use them for eavesdropping.

https://insinuator.net/2025/06/airoha-bluetooth-security-vulnerabilities/

Critical Cisco Identity Services Engine Vulnerability

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-rce-ZAd2GnJ6

SANS Internet Storm Center StormCast Thursday, June 26, 2025 Another NetScaler Vuln; CentOS Web Panel Vuln; Gogs Arbitrary File Deletion; IP Based Certs https://isc.sans.edu/podcastdetail/9506 NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2025-6543

Citrix patched a memory overflow vulnerability leading to unintended control flow and denial of service.

https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694788

Remote code execution in CentOS Web Panel - CVE-2025-48703

An arbitrary file upload vulnerability in the user (not admin) part of Web Panel can be used to execute arbitrary code

https://fenrisk.com/rce-centos-webpanel

Gogs Arbitrary File Deletion Vulnerability

Due to the insufficient patch for the CVE-2024-39931, it's still possible to delete files under the .git directory and achieve remote command execution.

https://github.com/gogs/gogs/security/advisories/GHSA-wj44-9vcg-wjq7

Let’s Encrypt Will Soon Issue IP Address-Based Certs

Let’s Encrypt is almost ready to issue certificates for IP address SANs from Let's Encrypt's production environment. They'll only be available under the short-lived profile (which has a 6-day validity period), and that profile will remain allowlist-only for a while.

https://community.letsencrypt.org/t/getting-ready-to-issue-ip-address-certificates/238777 SANS Internet Storm Center StormCast Wednesday, June 25, 2025 Telnet/SSH Scan Evolution; File-Fix vs Click-Fix; Fake SonicWall Software https://isc.sans.edu/podcastdetail/9504 Quick Password Brute Forcing Evolution Statistics

After collecting usernames and passwords from our ssh and telnet honeypots for about a decade, I took a look back at how scans changed. Attackers are attempting more passwords in each scans than they used to, but the average length of passwords did not change.

https://isc.sans.edu/diary/Quick+Password+Brute+Forcing+Evolution+Statistics/32068

Introducing FileFix – A New Alternative to ClickFix Attacks

Attackers may trick the user into copy/pasting strings into file explorer, which will execute commands similar to the ClickFix attack that tricks users into copy pasting the command into the start menu’s cmd feature.

https://www.mobile-hacker.com/2025/06/24/introducing-filefix-a-new-alternative-to-clickfix-attacks/

Threat Actors Modify and Re-Create Commercial Software to Steal User’s Information

A fake SonicWall NetExtender clone will steal user’s credentials

https://www.sonicwall.com/blog/threat-actors-modify-and-re-create-commercial-software-to-steal-users-information

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive