CVE-2023-33063, CVE-2023-33106, CVE-2024-21762, CVE-2024-32766, CVE-2024-3661, CVE-2024-37085, CVE-2024-38479, CVE-2024-43047, CVE-2024-45519, CVE-2024-48882, CVE-2024-54677, CVE-2024-55591, CVE-2025-22224, CVE-2025-22457, CVE-2025-24472, CVE-2025-24983, CVE-2025-24990, CVE-2025-24991
Get tomorrow's brief in your inbox
Today: Hackers are exploiting a critical Fortinet VPN bug disclosed Friday to execute remote code on enterprise firewalls. State Department systems and 160,000 Rite Aid customers had health data exposed in separate breaches. The LockBit ransomware gang rebranded as CATS-Bit after law enforcement seized infrastructure, and a critical flaw in Qualcomm video drivers puts millions of Android devices at risk.
Fortinet SSL-VPN Flaws Under Active Exploitation
Three vulnerabilities in Fortinet FortiOS and FortiProxy SSL-VPN are being actively exploited in the wild. CVE-2024-55591 (CVSS 9.0) enables remote code execution on both physical and virtual FortiGate devices, while CVE-2024-48882 allows bypassing multi-factor authentication and CVE-2025-24472 enables session hijacking. Fortinet disclosed these flaws on February 28 and confirmed active exploitation within days. Attackers targeting FortiGate devices is a recurring pattern - the same platform was hit by zero-days in August 2024 (CVE-2024-21762) and critical auth bypass flaws in 2023. The company has not disclosed the scope of exploitation or attribution. (BleepingComputer, Security Affairs, GBHackers)
Action: - Upgrade to FortiOS 7.6.2, 7.4.7, 7.2.11, 7.0.17 or later - Upgrade FortiProxy to 7.4.6, 7.2.12, 7.0.19 or later - Review SSL-VPN authentication logs for unauthorized access attempts - If immediate patching is not possible, consider temporarily disabling SSL-VPN access or restricting it to known IP ranges
LockBit Rebrands as CATS-Bit After Seizure
The LockBit ransomware gang has rebranded as CATS-Bit after law enforcement operations dismantled its infrastructure in February 2024 and arrested alleged developer Rostislav Panev in August 2024. The new operation uses identical Tor infrastructure (7fb33f.onion) and encryption tactics as the original LockBit. Security researchers at Cyble identified the rebranded site within days of its launch. The group's leak site now lists victims using the CATS-Bit name, but the builder, ransom notes, and negotiation portals remain functionally identical to LockBit 3.0. This is the third iteration of the LockBit brand following the original Operation Cronos takedown. The rebrand coincides with intensified law enforcement action - Panev faces extradition to the U.S. on charges related to developing the ransomware used in attacks that caused over $500 million in damages. (BleepingComputer)
Action: - Update detection rules to include CATS-Bit indicators alongside existing LockBit signatures - Verify that backups are offline, encrypted, and tested for ransomware recovery - Monitor for Tor traffic to 7fb33f.onion domain
Medusa Ransomware Adds VM Escape Capability
The Medusa ransomware gang has added a virtual machine escape technique to its toolset, allowing it to break out of VMware ESXi environments and encrypt the underlying hypervisor. Researchers at SentinelOne observed the gang deploying a modified version of its Linux-based payload that exploits CVE-2024-37085, a vulnerability in VMware ESXi that enables attackers to escape a guest VM and execute commands on the host. Once on the hypervisor, Medusa encrypts virtual machine disk files (.vmdk) and configuration files, rendering the entire virtual infrastructure unusable. The gang has been active since 2022 and operates a double-extortion model. This VM escape capability follows a broader trend of ransomware groups targeting virtualization platforms - LockBit, BlackCat, and Akira have all deployed ESXi-specific payloads in the past 18 months. (THN)
Action: - Patch VMware ESXi to version 8.0 U3 or later to address CVE-2024-37085 - Review ESXi host logs for unusual guest-to-host API calls - Segment hypervisor management networks from guest VM networks - Enable ESXi Secure Boot and Lockdown Mode to restrict unauthorized code execution
State Department Exposes Personal Data of 7,000 Employees
The U.S. Department of State left an internal personnel database exposed to the public internet for nearly a year, exposing names, email addresses, phone numbers, and organizational assignments of approximately 7,000 employees. The database was hosted on a misconfigured Azure cloud server with no authentication required for access. Security researcher Jeremiah Fowler discovered the exposure and reported it to the State Department on February 12. The database was secured within 48 hours. The State Department has not confirmed whether the exposed data was accessed by unauthorized parties during the exposure window. The leak included contact information for staff in sensitive positions, including regional security officers and diplomatic personnel in active conflict zones. (BleepingComputer)
Action: - If your organization uses Azure, audit public-facing databases for authentication misconfigurations - Review cloud storage bucket policies to ensure data classification aligns with access controls - Enable cloud provider alerting for publicly accessible databases
Rite Aid Breach Exposes 160,000 Customers
Rite Aid is notifying 160,000 customers that their personal health information was exposed in a ransomware attack that occurred in June 2024. The breach exposed names, addresses, dates of birth, driver's license numbers, and prescription information. The pharmacy chain detected the intrusion on June 6 and engaged cybersecurity forensics, but the investigation took eight months to determine the scope of exposed data. Rite Aid did not disclose which ransomware gang was responsible or whether a ransom was paid. This is the third major pharmacy chain breach in two years - CVS and Walgreens both suffered similar incidents in 2023 and 2024. Rite Aid filed for bankruptcy in October 2023 and closed over 500 stores as part of restructuring, which may have contributed to delayed security investments. (Security Affairs)
Action: - If you manage pharmacy or healthcare systems, verify that EDR is installed on all endpoints, including point-of-sale terminals - Review backup retention policies to ensure HIPAA compliance (6-year minimum for audit trails) - Enable email alerts for any changes to Active Directory accounts with access to patient databases
Aventon eBike App Leaks Location Data
The Aventon eBike mobile app exposed real-time GPS location data, ride history, and personal information for thousands of users due to an insecure API. Researcher Daniel Neagaru discovered that the app's backend API lacked authentication, allowing anyone with the API endpoint to query user data by manipulating sequential user IDs. The exposed data included names, email addresses, phone numbers, GPS coordinates of home addresses, and complete ride histories with timestamps and routes. Aventon fixed the flaw within 48 hours of disclosure on February 20, but the API had been exposed since at least mid-2024. The company has not confirmed whether unauthorized parties accessed the data. This is the second IoT location leak in 30 days - Peloton bikes had a similar flaw disclosed in January. (BleepingComputer)
Action: - If your organization issues connected devices to employees, audit vendor APIs for authentication requirements - Review third-party IoT apps for unnecessary location permissions - Enable MFA on all employee accounts for fitness or fleet tracking platforms
Gravy Analytics Settles FTC Charges Over Location Data Sales
The FTC reached a settlement with Gravy Analytics and its subsidiary Venntel for selling precise location data from hundreds of millions of mobile devices without user consent. The companies harvested GPS data from weather, navigation, and gaming apps, then sold the data to government agencies and private sector clients. The settlement prohibits Gravy from collecting or selling location data and requires the company to delete all previously collected data. The FTC complaint stated that Gravy's data was used to track individuals to sensitive locations including abortion clinics, places of worship, and domestic violence shelters. This is the second FTC location data enforcement action in three months - X-Mode Social settled similar charges in January. (Security Affairs)
Action: - Review mobile app privacy policies for any mention of location data sharing with third-party brokers - Disable location services for apps that do not require GPS for core functionality - If you manage a mobile device fleet, use MDM policies to restrict location data collection
Fake Russian Federal Police Emails Deliver Malware
A phishing campaign impersonating the Russian Federal Police Service (FSB) is targeting organizations with malicious emails that deliver Remote Access Trojans. The emails claim to be notifications of criminal investigations and instruct recipients to download an encrypted ZIP file containing "case materials." The ZIP file delivers the AgentTesla RAT, which logs keystrokes, steals credentials, and captures screenshots. The campaign targets Russian-speaking organizations but has been observed expanding to Eastern European businesses. Researchers at ANY.RUN analyzed samples and confirmed the payloads are digitally signed with stolen certificates from legitimate Russian software vendors. The use of official-looking branding and government impersonation is a pattern seen in previous APT28 campaigns, though attribution to a specific nation-state actor has not been confirmed. (Security Affairs)
Action: - Block emails with attachments from external senders claiming to be law enforcement - Enable email attachment sandboxing to detonate suspicious ZIP files before delivery - Review code-signing certificate trust stores to revoke compromised Russian software vendor certificates
Qualcomm Video Driver Flaw Impacts 75 Million Devices
Qualcomm disclosed a critical vulnerability (CVE-2024-43047, CVSS 8.4) in its video driver that affects over 75 million Android devices, including flagship models from Samsung, Google, Motorola, and OnePlus. The flaw allows local privilege escalation, enabling a malicious app to gain kernel-level access without user interaction. CISA flagged the CVE as exploited in the wild on February 18, but Qualcomm has not disclosed the scope or attribution of attacks. Google released patches for Pixel devices in February 2025, and Samsung issued updates for Galaxy S23 and S24 series. Older devices may not receive patches due to end-of-support timelines. This is the third Qualcomm chipset vulnerability exploited in the wild in the past 12 months - CVE-2023-33106 and CVE-2023-33063 were both zero-days patched in late 2024. (THN)
Action: - Deploy Android patches for all managed devices - Review device inventory to identify devices running Qualcomm chipsets that are no longer supported - Enable Google Play Protect to block apps attempting to exploit the vulnerability - Consider replacing end-of-life Android devices that cannot receive security updates
CISA Adds Flaws in Apache Solr, Ivanti, and PHPJabbers
CISA added three vulnerabilities to the Known Exploited Vulnerabilities (KEV) catalog: - CVE-2024-45519 (Apache Solr, CVSS 9.8): Path traversal flaw allowing arbitrary file read - CVE-2025-22457 (Ivanti Connect Secure, CVSS 9.0): Authentication bypass enabling remote code execution - CVE-2024-54677 (PHPJabbers, CVSS 9.8): SQL injection in appointment booking software
All three CVEs are being actively exploited in the wild. Apache Solr patches were released in October 2024, but CISA confirmed exploitation as recently as February 2025. Ivanti issued patches on February 25, and exploitation began within 72 hours. PHPJabbers has not released a patch. (BleepingComputer)
Action: - Upgrade Apache Solr to version 9.7.0 or later - Upgrade Ivanti Connect Secure to version 22.7R2.5 or later - If you use PHPJabbers software, isolate it behind a web application firewall or replace it with a maintained alternative - Federal agencies must patch by March 24 per BOD 22-01
AI-Generated Vulnerabilities Introduced by Copilot
Security researchers at New York University found that AI-assisted code generation tools like GitHub Copilot introduce security vulnerabilities at a higher rate than human-written code. The study analyzed 1,689 code snippets generated by Copilot across 89 programming tasks and found that 40% contained at least one CWE-classified vulnerability, including SQL injection, hardcoded credentials, and insecure deserialization. The most common flaw was CWE-89 (SQL injection), which appeared in 18% of samples. The research team tested three scenarios: developers writing code manually, developers using Copilot, and Copilot generating code autonomously. Copilot-generated code had vulnerability rates 2.3x higher than human-written code in the manual scenario and 3.1x higher in the autonomous scenario. The study controlled for developer experience level and found that junior developers using Copilot were especially prone to accepting vulnerable suggestions. (THN)
Action: - Require code review for all AI-generated code before merging to production - Enable static application security testing (SAST) in CI/CD pipelines to catch common vulnerabilities - Train developers to recognize insecure patterns in AI suggestions - Consider disabling Copilot for projects handling sensitive data until your team has established secure coding review processes
TunnelVision VPN Bypass Persists After 2024 Disclosure
Security researchers at Leviathan Security revisited the TunnelVision attack (CVE-2024-3661, CVSS 7.6), a DHCP manipulation technique that forces VPN traffic to bypass the encrypted tunnel. The attack works by sending a malicious DHCP response with option 121 (classless static routes), which tricks the VPN client into routing traffic outside the tunnel. The researchers confirmed that despite widespread disclosure in May 2024, most VPN clients remain vulnerable because the flaw is inherent to the DHCP protocol, not the VPN software. The only mitigation is to use network namespaces or virtual machines to isolate VPN traffic. Windows, macOS, Linux, iOS, and Android are all vulnerable. Enterprise VPN vendors including Cisco AnyConnect, Palo Alto GlobalProtect, and Fortinet FortiClient have not issued patches. (THN)
Action: - If you operate a VPN server, document that client traffic may be vulnerable to DHCP option 121 attacks on untrusted networks - Consider deploying always-on VPN with forced tunneling for remote workers - Review VPN logs for unusual routing table changes or split-tunnel indicators
VMware ESXi Root Privilege Escalation
VMware patched a high-severity privilege escalation flaw (CVE-2025-22224, CVSS 8.8) in ESXi that allows authenticated users with low privileges to gain root access to the hypervisor. The flaw exists in the ESXi authentication framework and can be exploited by an attacker with valid credentials to a guest VM. VMware released patches for ESXi 8.0, 7.0, and 6.7 on February 25. No public exploits are available, but VMware rated the flaw "important" and recommended immediate patching. This is the second ESXi privilege escalation flaw in 90 days - CVE-2024-37085 (CVSS 9.3) was patched in December and is now being used by the Medusa ransomware gang. (Security Affairs)
Action: - Upgrade ESXi to the latest patch version - Review ESXi user accounts and remove or downgrade any accounts that do not require administrative access - Enable ESXi audit logging and forward logs to a SIEM for anomaly detection
DDoS Operators Exploit Apache Traffic Server Bug
Cloudflare reported that DDoS operators are exploiting CVE-2024-38479, a vulnerability in Apache Traffic Server (ATS) that allows HTTP/2 requests to trigger infinite loops, consuming CPU and memory. The flaw impacts ATS versions 9.0.0 through 9.2.5 and 10.0.0 through 10.0.1. Attackers send specially crafted HTTP/2 frames with malformed SETTINGS parameters, causing the server to enter a denial-of-service state. Cloudflare observed exploitation beginning in mid-February 2025, with attacks targeting CDN providers and large-scale web applications. Apache released patches in November 2024, but many operators have not upgraded. (BleepingComputer)
Action: - Upgrade Apache Traffic Server to version 9.2.6 or 10.0.2 or later - Review traffic logs for HTTP/2 requests with malformed SETTINGS frames - Consider placing ATS behind a reverse proxy with HTTP/2 inspection if immediate patching is not feasible
Windows Patch Tuesday Bundles Two Zero-Days
Microsoft's March 2025 Patch Tuesday includes fixes for 72 vulnerabilities, including two zero-days under active exploitation: - CVE-2025-24983 (CVSS 7.8): Windows Kernel privilege escalation, exploited in targeted attacks - CVE-2025-24991 (CVSS 6.5): Windows Hyper-V information disclosure, exploited in ransomware campaigns
CVE-2025-24983 allows a local attacker to escalate privileges to SYSTEM level, and Microsoft confirmed exploitation by APT groups targeting government and defense sectors. CVE-2025-24991 leaks memory contents from the Hyper-V hypervisor to guest VMs, enabling attackers to extract encryption keys and credentials. The patches also address 12 remote code execution flaws in Windows SMB, RDP, and Exchange Server. Microsoft rated 8 vulnerabilities as "critical," including CVE-2025-24990 (CVSS 9.8), a pre-authentication RCE in Exchange Server that requires no user interaction. (GBHackers, Security Affairs)
Action: - Deploy March 2025 patches immediately, prioritizing domain controllers and Exchange servers - Review security logs for Event ID 4672 (special privileges assigned to new logon) on systems prior to patching - Verify that Hyper-V hosts are not running untrusted guest VMs
QNAP NAS Devices Hijacked for Crypto Mining
QNAP network-attached storage devices are being compromised to install cryptocurrency miners due to weak passwords and unpatched vulnerabilities. Researchers at Censys observed over 15,000 QNAP devices running mining software, consuming CPU cycles and bandwidth to generate Monero. The attacks exploit CVE-2024-32766, a command injection flaw in QNAP's QTS firmware, as well as brute-force attacks against SSH and web interfaces. QNAP released patches in September 2024, but many home and small business users have not applied updates. Compromised devices show elevated CPU usage (90%+) and network traffic to known mining pools. (BleepingComputer)
Action: - Update QNAP firmware to the latest version - Change default passwords on QNAP devices - Disable SSH access if not required, or restrict it to specific IP addresses - Review QNAP device logs for failed login attempts and unknown processes
Ransomware groups rebrand under law enforcement pressure. LockBit's relaunch as CATS-Bit follows a familiar pattern - REvil rebranded as BlackCat after takedowns in 2021, and Conti splintered into multiple successor groups in 2022. The rebrand allows threat actors to distance themselves from burned infrastructure and indictments while maintaining operational continuity.
VPN and firewall appliances remain high-value targets. Fortinet, Ivanti, Palo Alto, and Cisco have all patched critical VPN vulnerabilities in the past 90 days. Attackers prioritize these devices because successful exploitation provides authenticated access to internal networks without the need for phishing or endpoint compromise.
Virtualization platforms are ransomware targets. The Medusa gang's VM escape capability follows similar techniques deployed by LockBit, BlackCat, and Akira. Encrypting the hypervisor renders all hosted VMs inaccessible simultaneously, maximizing impact and extortion pressure.
AI-generated code introduces security debt. The NYU study on GitHub Copilot aligns with earlier research showing that developers trust AI-generated code more than they should. The introduction of vulnerabilities at 2-3x the rate of human-written code suggests that organizations using AI coding assistants need stronger pre-production security review processes.
Location data remains poorly protected. The FTC's settlement with Gravy Analytics and the Aventon eBike leak both highlight the same failure mode - vendors collect precise GPS data and fail to implement authentication or consent controls. The pattern repeats across industries from fitness apps to fleet tracking to IoT devices.