Huntress continues to observe in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in Gladinet CentreStack and Triofox
Mark
@sneakymonk3y.bsky.social
uber geek blue team cyber commando bad guy annihilator @CrowdStrike OSCP GREM GC|FA/FE/IH #DFIR - head in the clouds. https://you.sneakymonkey.net
One of my good friends and former SOC protégé—dropping 🔥 analysis on a Monday afternoon. Epic work, @thecyber.dad 🚀 www.thecyber.dad/p/detecting-...
Detecting Fake CAPTCHA Campaigns: ClickFix, ClearFake, and Etherhide
Summary
thecyber.dad
BREAKING. From a reliable source. MITRE support for the CVE program is due to expire tomorrow. The attached letter was sent out to CVE Board Members.
Update your VMware ESX farms ASAP. There's an in the wild exploit chain being used which does VM -> Hypervisor escape, across all versions of ESXi. Allows full cluster access. doublepulsar.com/use-one-virt...
Use one Virtual Machine to own them all — active exploitation of ESXicape
A chain of three zero days allow threat actors to escape a Virtual Machine.
doublepulsar.com