A major Chinese espionage group targeted some 80 nations—and likely more than just telecommunications companies—in a sweeping hack discovered last year, U.S. investigators said Wednesday.
At least 600 organizations were notified by the FBI that the group — known as Salt Typhoon — had interest in their systems, the FBI's cybersecurity division director Brett Leatherman said in media interviews Wednesday that dovetailed with a release of a technical advisory about the hacking activity. Nextgov/FCW previously reported that hundreds of entities — telecom providers and others — were notified of potential compromise.
Salt Typhoon breached major telecom carriers in a global, multi-year espionage operation that, in part, targeted the phone conversations of key American officials, including now-President Donald Trump and Vice President JD Vance. Additional discoveries about its scope and scale have trickled out over the past year.
The hackers are “targeting networks globally, including, but not limited to, telecommunications, government, transportation, lodging and military infrastructure networks,” the advisory says. It lists Canada, the United Kingdom, Germany, Japan and other allied nations’ cyberintelligence directorates as co-signers.
The document is among the most lengthy guidance to date designed to help known or potential victims of the hackers.
“It’s great to finally see such a useful, actionable hunt guide released on this threat. This document should start to level the playing-field for networks that have been struggling to evict these threat actors for a year or more,” said Marc Rogers, a seasoned telecommunications cybersecurity expert.
The intrusions have been happening since at least 2019, Leatherman said in a video statement, allowing the Chinese cyberspies to quietly burrow across telecom operators’ internet infrastructure and collect intelligence about prime targets.
Some of the vulnerabilities exploited by Salt Typhoon go back to 2018, Nextgov/FCW previously reported. Security patches were issued, but many telecom companies never implemented them.
Between January and March of last year, Salt Typhoon also “exfiltrated configuration files associated with other U.S. government and critical infrastructure entities, including at least two U.S. state government agencies,” according to a declassified DHS memo released in July the revealed a state’s National Guard systems were compromised by the hackers.
Salt Typhoon breached several U.S. telecom providers’ “lawful intercept” systems that house wiretap requests used to surveil suspected criminals and spies. Telecom providers are required to engineer their networks for these legal access requests under the 1994 Communications Assistance for Law Enforcement Act. Many other nations have similar laws.
Every year, the State Department completes a thorough, multi-layered process to determine who in the Foreign Service will get promoted. This year, news of impending promotion came as a surprise for some employees: just a month ago, State laid them off.
At least 10 people have been promoted since receiving layoff notices in July, according to the American Foreign Service Association, which represents the workers. They work in areas throughout the department: one was a deputy assistant secretary in the Energy Resources Bureau; others were in European and Eurasian Affairs, Economic and Business Affairs, International Narcotics and Law Enforcement Affairs, and other areas.
The laid-off employees remain on the payroll; they are on paid administrative leave through Nov. 8. If their promotions go through before then, they will separate at a higher grade.
“That the department would simultaneously recognize individuals for exemplary service and eliminate their positions as no longer needed defies logic,” AFSA said in a statement. “Together, these actions send a chilling message: In today’s State Department, even excellence cannot protect your career.”
Under the Trump administration, State has laid off 1,350 employees, including 264 Foreign Service Officers, as part of plans to shed a total of 3,000 employees through reductions-in-force, attrition, and incentivized separations.
State officials said ahead of the layoffs that the department’s reorganization was meant to “refocus” its mission on core objectives and modern needs. One official said the layoffs did not mean that the employees “weren't doing a good job or weren't valuable members of the State Department family,” but rather reflected the administration's obligation to “do what's right for the mission and what's right for the American people.”
“Headcount reductions have been carefully tailored to affect non-core functions, duplicative or redundant offices, and offices where considerable efficiencies may be found from centralization or consolidation of functions and responsibilities,” the department said in a notice to staff on the day it sent the reduction-in-force notices.
State determines promotions of Foreign Service staff through selection boards that review each employee's qualifications every one to four years after their last advancement. The department promotes about 1,400 Foreign Service personnel per year, according to a recent Government Accountability Office report. The undersecretary for management at State, a role currently filled by Jose Cunningham, must approve each promotion. Cunningham helped oversee the reorganization efforts and the resulting layoffs.
Selection boards began their reviews before the layoffs and did not know who would be affected when making their recommendations. Cunningham and the State officials who signed off on those recommendations in recent weeks opted not to remove those who were laid off from the approved promotion list.
AFSA reiterated its call for State to reverse the reductions in force, saying the cuts are causing chaos throughout the department.
Employees to be judged on 'fidelity'
The Global Talent Management bureau, which oversees State’s promotion process, recently put out new guidance for determining whether employees should be promoted. It created a new section called “fidelity,” which will measure employees’ commitment to “zealously executing [U.S. government] policy” and “completely aligning oneself and one’s team to the most current [U.S. government] goals.” Employees expressed concern that the new standards would prohibit the tradition of constructive dissent and force selection boards to judge FSOs on their willingness to bend to political winds.
The new standards will go into effect for the 2025-2026 review cycle.
Path traversal flaws like Zip Slip, which give hackers the ability to alter file systems while decompressing, remain a serious danger in the ever-changing world of cybersecurity threats. This vulnerability, stemming from inadequate input validation in compression utilities, enables adversaries to embed malicious paths within archive files, leading to unauthorized file creation, overwriting, or execution […]
A second B-21 Raider will likely fly before the end of the year, according to an Air Force official who gave a small update on the highly classified program.
“I believe it will happen before the end of the year, but we're not going to ever give them an artificial date that they have to make if it doesn't bring the test program along to where they need to be. We're going to proceed as we can, efficiently, effectively, and with a sense of urgency, but we're also going to be event-based,” said Lt. Gen. Andrew Gebara, deputy chief of staff for strategic deterrence and nuclear integration.
The stealthy B-21 first flew in November 2023, a pre-production test aircraft that has since been flying up to twice a week, builder Northrop Grumman said last year.
Northrop received the green light last year to begin B-21 production. Now the company is talking with the Air Force to speed up production after the program got an additional $4.5 billion in the reconciliation bill.
Those additional funds from Congress will go a “long way” to help the service build the bomber at scale, Gebara said today during an event hosted by the Mitchell Institute.
“We've done the initial R&D work, we've started the flight test…all these things are great indicators of success and a program that's on time, on budget and producing, but eventually you have to get to the point where we scale this thing and so that's very important,” he said.
The Air Force plans to buy 100 B-21s by the mid- to late 2030s, but top military officials have advocated for buying up to 145. The original program of record may be “insufficient for the future,” but Gebara said it will be a “long time” before the service comes to a conclusion on increasing the buy.
Gebara also gave an update on another nuclear modernization effort led by Northrop: the Sentinel intercontinental ballistic missile program. That program, which will replace the nation’s aging Minuteman III missiles, is being restructured after projected costs increased to $141 billion—81% above original estimates. The Air Force halted some work on Sentinel’s launch facilities after the Nunn-McCurdy breach, but has since reached an agreement with Northrop to resume work.
The service said this summer that it would have to dig hundreds of new holes for the missiles instead of reusing Minuteman silos, a major change from original plans. But Gebara said the move will save the service time and money because it can avoid the logistical and operational problems with modifying active silos.
Most of the new silos will be built on land that the U.S. already owns, but in some cases the U.S. will need to buy more land to fit the silos, Gebara said.
“I believe building all-new silos is actually not an extender of time and cost. It's actually saving time and cost,” he said.
Nukes back in the UK?
Gebara declined to comment on recent reports that American nuclear weapons are back in the UK after almost two decades. But he did say the B61-12 nuclear gravity bomb is “fully deployed throughout the continent,” almost but not precisely echoing a statement by a senior nuclear-weapons official earlier this year.
In July, flight trackers noted that an Air Force C-17 airlifter appeared to be moving nuclear bombs to RAF Lakenheath. The F-35A is stationed at Lakenhealth and was certified to carry the B61-12 last year. Pentagon and NATO officials have a longstanding policy not to confirm the whereabouts of nuclear warheads.
“We now have F-35, 5th-gen sensor-fused aircraft, many of our allies purchasing the same aircraft, common training, common TTPs [tactics, techniques, and procedures], with our modernized B61-12 weapon that has been fully deployed throughout the continent,” Gebara said Wednesday.
That nearly echoed a January speech by Jill Hruby, who was then the administrator of the National Nuclear Safety Administration, the agency that oversees the nuclear- weapons stockpile.
“The new B61-12 gravity bombs are fully forward deployed, and we have increased NATO’s visibility to our nuclear capabilities through visits to our enterprise and other regular engagements,” she said.
Hruby stepped down as NNSA director at the beginning of the Trump administration. Brandon Williams, a former GOP congressman, was quickly named as her successor but has not been confirmed by the U.S. Senate. The NNSA website says an acting director is in place.
The financially motivated threat actor known as Storm-0501 has been observed refining its tactics to conduct data exfiltration and extortion attacks targeting cloud environments.
“Unlike traditional on-premises ransomware, where the threat actor typically deploys malware to encrypt critical files across endpoints within the compromised network and then negotiates for a decryption key,
A critical zero-day remote code execution (RCE) vulnerability, tracked as CVE-2025-7775, is affecting over 28,000 Citrix instances worldwide.
The flaw is being actively exploited in the wild, prompting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add it to its Known Exploited Vulnerabilities (KEV) catalog.
The Shadowserver Foundation discovered that as of August 26, 2025, more than 28,200 servers remain unpatched, with the highest concentrations of vulnerable systems located in the United States and Germany.
Vulnerable servers by country
Citrix has released patches and urges administrators to apply them immediately to prevent system compromise. The active exploitation of this vulnerability poses a significant threat, as it allows unauthenticated attackers to execute arbitrary code on affected servers, potentially leading to full system takeover, data theft, and further network infiltration.
CVE-2025-7775: A Critical RCE Flaw
Remote code execution vulnerabilities are among the most severe security flaws, and CVE-2025-7775 is no exception. It allows a remote attacker, without needing any credentials, to run malicious code on a vulnerable Citrix server.
Vulnerability Details
Information
CVE ID
CVE-2025-7775
Vulnerability Type
Unauthenticated Remote Code Execution (RCE)
Status
Actively Exploited in the Wild (CISA KEV)
Affected Instances
Over 28,200 (as of Aug 26, 2025)
Primary Mitigation
Apply patches from Citrix Security Bulletin CTX694938
Top Affected Countries
United States, Germany
This level of access could enable threat actors to deploy ransomware, install backdoors for persistent access, exfiltrate sensitive corporate data, or use the compromised server as a pivot point to attack other systems within the network.
The “zero-day” designation indicates that attackers were exploiting the flaw before an official patch was made available by Citrix. This gave threat actors a critical window of opportunity to compromise exposed systems.
Given the widespread use of Citrix products for secure remote access and application delivery in enterprise environments, the potential impact of this vulnerability is substantial. A successful exploit could disrupt business operations and result in significant financial and reputational damage.
The confirmation of in-the-wild exploitation by CISA underscores the urgency for immediate action. By adding CVE-2025-7775 to the KEV catalog, CISA has mandated that U.S. Federal Civilian Executive Branch (FCEB) agencies patch their systems by a specified deadline, a directive that all organizations should follow.
The widespread nature of the vulnerability, affecting tens of thousands of servers globally, means that automated attacks are likely to escalate as more attackers weaponize the exploit.
Citrix has published a security bulletin, CTX694938, which contains the necessary patch information and guidance. The primary and most effective mitigation is to apply the updates to all affected instances without delay.
For organizations that cannot patch immediately, it is crucial to review server logs for any indicators of compromise (IoCs), such as unusual processes or outbound network connections.
Isolating vulnerable servers from the internet and deploying web application firewall (WAF) rules to block exploit attempts can serve as temporary compensating controls.
Tired of Filling Forms for security & Compliance questionnaires? Automate them in minutes with 1up! Start Your Free Trial Now!
A weaponized proof-of-concept exploit has been publicly released targeting CVE-2025-54309, a severe authentication bypass vulnerability affecting CrushFTP file transfer servers.
The flaw enables remote attackers to gain administrative privileges through a race condition in AS2 validation processing, circumventing authentication mechanisms entirely.
Key Takeaways 1. Race-condition exploit lets attackers bypass CrushFTP authentication. 2. Public PoC on GitHub confirms vulnerable instances without adding backdoors. 3. Upgrade, enable DMZ proxy, and watch for POST spikes.
First exploited in the wild in July 2025, the vulnerability affects CrushFTP versions 10 before 10.8.5 and 11 before 11.3.4_23 when the DMZ proxy feature remains disabled, a configuration that affects the majority of deployed instances across enterprise environments.
CrushFTP 0-day Vulnerability
The vendor postmortem published on July 18, 2025, acknowledged active targeting of CrushFTP instances but blamed users for failing to apply a silent patch that was never publicly announced.
With over 30,000 instances exposed online, attackers exploited the mishandling of AS2 validation to gain administrative access via HTTPS.
Specifically, the flaw resides in the WebInterface/function/ endpoint, where two sequential HTTP POST requests race to set session state:
By issuing Request 1 (with the AS2-TO: \crushadmin header) immediately followed by Request 2 (omitting the header but reusing the same session cookies), attackers win a race condition that impersonates the built-in crushadmin user and successfully invokes setUserItem to create a new administrative account.
Standalone requests return 404, but when executed at high concurrency, Request 2 returns a 200 OK response confirming administrative user creation.
Risk Factors
Details
Affected Products
CrushFTP 10 versions before 10.8.5 CrushFTP 11 versions before 11.3.4_23
Impact
Authentication bypass, Remote code execution
Exploit Prerequisites
DMZ proxy feature disabled;ability to send sequential HTTPS POST requestsValid CrushAuth and currentAuth cookies
CVSS 3.1 Score
9.8 (Critical)
PoC Exploit
WatchTowr Labs has published a fully functional PoC exploit on GitHub, enabling security teams to verify vulnerable CrushFTP instances without adding persistent backdoors.
The PoC simply extracts the user list to confirm exploitation:
Additionally, researchers recommend monitoring for anomalous spikes in POST requests to /WebInterface/function/ with repetitive AS2-TO and cookie patterns.
Security teams should deploy intrusion detection signatures matching this race condition and implement network rate-limiting to mitigate high-frequency exploit attempts.
Mitigation includes:
Upgrading to CrushFTP 10.8.5 or 11.3.4_23 (or later).
Enable the DMZ proxy feature if not already configured.
Audit administrative user additions and validate session reuse patterns.
Organizations leveraging CrushFTP must treat CVE-2025-54309 as a critical risk and act swiftly to defend against in-the-wild exploitation.
Tired of Filling Forms for security & Compliance questionnaires? Automate them in minutes with 1up! Start Your Free Trial Now!
August 2025 has marked a significant evolution in cybercrime tactics, with threat actors deploying increasingly sophisticated phishing frameworks and social engineering techniques that are successfully bypassing traditional security defenses.
Security researchers at ANY.RUN has identified three major campaign families that represent a fundamental shift in how cybercriminals approach credential theft and system compromise: the multi-stage Tycoon2FA phishing framework, ClickFix-delivered Rhadamanthys stealer operations, and the emergence of Salty2FA, a new Phishing-as-a-Service (PhaaS) platform linked to the notorious Storm-1575 group.
These campaigns demonstrate an alarming trend toward highly targeted, multi-layered attacks that combine advanced evasion techniques with psychological manipulation to defeat both automated security systems and human vigilance.
Unlike traditional mass phishing attempts, these sophisticated frameworks specifically target high-value accounts in government, financial, and critical infrastructure sectors.
Tycoon2FA: Seven-Stage Phishing Chain
The Tycoon2FA campaign represents a paradigm shift in phishing sophistication, employing a seven-stage execution chain that systematically defeats automated security tools while exhausting human targets.
This framework has emerged as one of the most effective credential harvesting operations observed in 2025, specifically targeting government agencies, military installations, and major financial institutions across the United States, the United Kingdom, Canada, and Europe.
The attack methodology begins with carefully crafted voicemail-themed phishing emails that initiate a complex redirection chain. Victims are guided through multiple validation screens, including Cloudflare Turnstile CAPTCHAs and “press-and-hold” anti-bot checks, before reaching the final Microsoft login spoofing panel. Each stage serves dual purposes: filtering out automated analysis tools while building psychological commitment from human targets.
Tycoon2FA seven-stage phishing execution chain
Analysis data reveals that 26% of Tycoon2FA campaigns specifically target banking sector employees, indicating deliberate focus on high-value financial credentials rather than opportunistic credential harvesting.
The framework’s selectivity extends to government and military personnel, where single compromised accounts can provide access to classified systems and sensitive national security information.
With ANY.RUN’s Automated Interactivity features a seven-stage execution flow that operates as follows: initial phishing email delivery, fake PDF attachment download, embedded hyperlink activation, Cloudflare CAPTCHA challenge, manual interaction verification, email validation requirement, and finally, credential harvesting through spoofed authentication panels.
Phishing exposure through a deceptive voice message download prompt.
This methodology effectively defeats signature-based detection systems while requiring sustained human engagement that builds trust and reduces suspicion.
Identify cyber threats and empower SOC Performance with Cutting-edge Tools => Get Started
ClickFix Evolution
The ClickFix technique has evolved significantly beyond its original NetSupport RAT and AsyncRAT delivery mechanisms, now serving as a sophisticated vector for deploying advanced information stealers like Rhadamanthys.
This evolution represents a concerning escalation in both technical complexity and evasion capabilities, combining social engineering psychology with advanced malware deployment techniques.
Recent campaigns utilize ClickFix flows to deliver Rhadamanthys stealer through Microsoft Installer (MSI) packages that execute silently in memory, bypassing traditional file-based detection systems with ANY.RUN Sandbox, we can see how the Rhadamanthys was delivered via ClickFix.
Rhadamanthys malware delivery vector via ClickFix, illustrating the malicious code execution and payload extraction process.
The attack chain employs anti-virtual machine checks to evade sandbox analysis while establishing TLS connections directly to IP addresses, circumventing DNS monitoring and domain reputation systems.
Stage
Technique
MITRE ATT&CK ID
Evasion Method
Initial Delivery
ClickFix Social Engineering
T1566
Human Interaction Required
Installation
MSI Silent Execution
T1218.007
In-Memory Processing
Evasion
Anti-VM Detection
T1497.001
Environment Analysis
Communication
Direct IP TLS
T1071.001
DNS Bypass
Payload Delivery
PNG Steganography
T1027.003
Visual Obfuscation
The most sophisticated aspect of these campaigns involves steganography-based payload delivery through compromised PNG image files.
Attackers embed additional malware components within image data, allowing secondary payload deployment while appearing as legitimate graphic content to security scanners. This technique effectively bypasses content inspection systems that focus on executable file types.
Threat actors have also implemented self-signed TLS certificates with deliberately mismatched Issuer/Subject fields, creating unique network artifacts while maintaining encrypted communication channels.
These certificates serve dual purposes: avoiding commercial certificate authority oversight while providing distinctive hunting signatures for advanced threat detection teams.
Salty2FA: Next-Generation PhaaS Framework
The discovery of Salty2FA represents perhaps the most significant development in phishing infrastructure evolution, introducing a comprehensive Phishing-as-a-Service platform capable of bypassing virtually all current multi-factor authentication implementations.
First identified in June 2025, this framework has rapidly expanded to target Microsoft 365 accounts across multiple continents, with particular focus on North American and European enterprise environments.
Salty2FA derives its name from distinctive source code “salting” techniques that disrupt both static analysis tools and manual reverse engineering efforts.
The framework implements adversary-in-the-middle capabilities that can intercept push notifications from mobile authentication applications, SMS-based one-time passwords, and even two-way voice authentication calls. This comprehensive 2FA bypass capability represents a fundamental threat to current enterprise authentication strategies.
Salty2FA phishing kit execution chain
Infrastructure analysis reveals consistent patterns in Salty2FA deployment, utilizing compound subdomain structures paired with Russian top-level domains for command and control operations.
The framework utilizes chained server architectures, which provide resilient communication channels but complicate attribution and takedown efforts.
Attribution evidence suggests connections between Salty2FA and the Storm-1575 threat group, previously responsible for the Dadsec phishing kit operations. Here is the example of an analysis session, Salty2FA behavior download, and an actionable report.
Phishing attempt targeting Microsoft login credentials.
However, infrastructure overlaps also indicate potential relationships with Storm-1747, the group behind Tycoon2FA campaigns. These connections suggest possible collaboration between previously distinct threat actors or evolution within existing criminal organizations.
Financial services and insurance organizations
Energy production and manufacturing facilities
Healthcare systems and telecommunications providers
Government agencies, educational institutions, and logistics networks
These campaign developments represent a fundamental shift in cybercriminal capabilities, moving beyond opportunistic attacks toward sustained, targeted operations against high-value institutional targets.
The sophistication demonstrated in multi-stage evasion, advanced steganography, and comprehensive 2FA bypass techniques indicates significant investment in research and development within criminal organizations.
Traditional security approaches focused on signature-based detection and static analysis prove inadequate against these evolved threats.
The combination of human psychological manipulation with advanced technical evasion creates attack vectors that require behavioral analysis, interactive sandbox environments, and continuous threat intelligence integration for effective detection and response.
Organizations must implement layered security strategies that combine advanced behavioral analytics, interactive malware analysis capabilities, and comprehensive threat intelligence integration.
The shift toward PhaaS models suggests that these sophisticated techniques will become increasingly accessible to lower-skilled threat actors, thereby significantly expanding the overall threat landscape.
Security teams should prioritize the development of detection rules based on behavioral indicators rather than static IOCs, as these campaigns demonstrate rapid infrastructure turnover and evasion technique evolution.
Integrate ANY.RUN solutions to interact with malware in the sandbox => Start Your Free Trial
A stored cross-site scripting (XSS) flaw identified in IPFire 2.29’s web-based firewall interface (firewall.cgi).
Tracked as CVE-2025-50975, the vulnerability allows any authenticated administrator to inject persistent JavaScript into firewall rule parameters.
Once stored, the payload executes automatically when another administrator loads the rules page, potentially resulting in session hijacking, unauthorized actions within the interface, or even deeper network pivoting.
According to the report, IPFire’s firewall management CGI script fails to sanitize multiple user-supplied parameters before rendering them in the HTML response.
The affected fields include PROT, SRC_PORT, TGT_PORT, dnatport, key, ruleremark, src_addr, std_net_tgt and tgt_addr.
An attacker with high-privilege GUI access can craft a malicious rule entry such as:
Adding the payload inside the ruleremark parameter:
Upon submission, the JavaScript snippet is stored in the firewall rule set. When any administrator subsequently views https://<IPFire-host>:444/cgi-bin/firewall.cgi, the script executes in their browser context.
This simple yet potent exploit requires no social engineering beyond valid credentials, and its complexity is relatively low.
Authenticated administrator access to firewall CGI Web GUI
CVSS 3.1 Score
Not specified
Mitigations
Demonstrations of the attack leverage a test instance at https://192.168.124.92:444/cgi-bin/firewall.cgi, where a GIF walkthrough illustrates payload injection and session cookie exfiltration.
Since the flaw resides in the lack of HTML escaping for multiple parameters, IPFire deployments in multi-admin environments are particularly at risk.
To mitigate the issue, all firewall.cgi parameters must be HTML-escaped or passed through a whitelisting routine.
IPFire maintainers have released version 2.29.1, which implements proper sanitation for PROT, SRC_PORT, TGT_PORT, dnatport, key, ruleremark, src_addr, std_net_tgt, and tgt_addr.
Limit administrative GUI access to trusted operators and networks and deploy a strict CSP header to restrict inline script execution within the firewall interface.
While other XSS variants exist in IPFire 2.29, this stored XSS path represents the most straightforward vector for real-world exploitation.
Administrators should prioritize patching and hardening their firewall management interfaces to prevent malicious JavaScript persistence and subsequent internal network compromise.
Tired of Filling Forms for security & Compliance questionnaires? Automate them in minutes with 1up! Start Your Free Trial Now!