Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

New catalysts show significant advances in PFA degradation

How Agent AI is configured to change workplaces

Apple Zero-Clock flaws in messages abused by journalist spies using Paragon Spyware

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Gladinet’s Triofox and Centrestack under aggressive exploitation through critical RCE vulnerabilities
Identity

Gladinet’s Triofox and Centrestack under aggressive exploitation through critical RCE vulnerabilities

userBy userApril 15, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 15, 2025Ravi LakshmananVulnerability/Endpoint Security

Critical RCE Vulnerabilities

According to Huntress, the security flaws recently revealed on Gladinet Centrestack have also affected Trifox’s remote access and collaboration solutions, which have compromised seven different organizations to date.

A vulnerability tracked as CVE-2025-30406 (CVSS score: 9.0) refers to the use of hard-coded encryption keys that allow Internet-accessible servers to be exposed to remote code execution attacks.

This is addressed in Centrestack version 16.4.10315.56368, released on April 3, 2025. The vulnerability is said to have been misused as a zero day in March 2025, but the exact nature of the attack is unknown.

Currently, according to Huntress, the weaknesses have also affected Gladinet Triofox up to version 16.4.10317.56372.

Cybersecurity

“By default, previous versions of Triofox software have the same hard-coded encryption key in their configuration files, allowing them to easily abuse remote code execution,” says John Hammond, Huntress’ chief cybersecurity researcher, in a report.

Gladinet's Triofox and Centrestack

Telemetry data collected from the partner base revealed that Centrestack software was installed on approximately 120 endpoints, with seven unique organizations being affected by vulnerability exploitation.

The oldest signs of compromise date back to 11 April 2025 at 16:59:44 UTC. It has been observed that attackers are exploiting flaws to download and sideload DLLs using encoded PowerShell scripts. This is an approach seen in a recent attack using a flaw in CrushFTP, then performs lateral movement and installs MeshCentral for remote access.

Huntress also said that the attacker has been identified as running in-packet PowerShell commands to install Meshagent by running various enumeration commands. That said, the exact scale and ultimate goal of the campaign is currently unknown.

In light of aggressive exploitation, it is essential for Gladinet Centrestack and Triofox users to update their instances to the latest version to prevent potential risks.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMeta resumes EU AI training using public user data after regulator approval
Next Article Harvard University faces $2.3 billion in funding, contrary to Trump’s demands | Education News
user
  • Website

Related Posts

Apple Zero-Clock flaws in messages abused by journalist spies using Paragon Spyware

June 13, 2025

How Vextrio and Affiliates run a global fraud network

June 12, 2025

New token break attacks bypass AI moderation with text changes for single characters

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

New catalysts show significant advances in PFA degradation

How Agent AI is configured to change workplaces

Apple Zero-Clock flaws in messages abused by journalist spies using Paragon Spyware

Israeli attacks on Iran could send oil prices above $100 as tensions rise

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Top Startups and High-Tech Funding News – June 12, 2025

AI Internet is down: Google Cloud outage breaks Firebase, Supabase, Cursor, Lovable, etc.

Digital banking startup Chime pops with IPO debut, raising $700 million at a valuation of $11.6 billion

Spanish AI Startup Multiverse raises $227 million to reduce LLMS and reduce inference costs by 80%

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.