Management Plane Exploits, Backup Wipers, and IT Helpdesk Vishing
Tools
Nuclei Template for Actively Exploited Ivanti EPMM RCE (CVE-2025-22457)
A new detection template has been released to identify CVE-2025-22457, a critical unauthenticated buffer overflow in Ivanti EPMM. If you run this Ivanti product, scanning should be immediate as CISA has confirmed active exploitation.
News
Aviatrix Controller RCE Exploit PoC Threatens Cloud Environments
A critical proof-of-concept has dropped for the Aviatrix Controller RCE vulnerability, which impacts major cloud deployments. If your cloud management plane isn't segmented, this is a potential full environment takeover waiting to happen.
Luna Moth Callback Phishing Targets Corporate Helpdesks
Luna Moth is running sophisticated callback campaigns where they pose as IT support to get victims to install remote tools. It's a reminder that social engineering attacks are becoming highly targeted and expensive for organizations.
Qilin Ransomware Releases New Linux Encryptor for ESXi
The Qilin ransomware group has expanded its arsenal to target Linux environments, specifically ESXi hosts. This trend continues to pressure defenders who need to secure virtualization infrastructure that often lacks robust monitoring.
Analysis
Ransomware Operators Systematically Erasing Cloud Backups
New analysis shows ransomware gangs are prioritizing the complete encryption or deletion of immutable cloud backups to force payouts. This changes the recovery math entirely, placing a premium on off-site, air-gapped copies.
Stay Ahead
Delivered each morning.