• Menu
  • Skip to main content
  • Skip to primary sidebar

All Tech News

Latest Technology News

Critical Update: CrushFTP Zero-Day Flaw Exploited in Targeted Attacks

You are here: Home / Cyber Security News / Critical Update: CrushFTP Zero-Day Flaw Exploited in Targeted Attacks

People of the CrushFTP business file transfer software program are getting urged to update to the most recent version adhering to the discovery of a security flaw that has arrive below focused exploitation in the wild.

“CrushFTP v11 versions below 11.1 have a vulnerability exactly where users can escape their VFS and obtain system files,” CrushFTP stated in an advisory unveiled Friday. “This has been patched in v11.1..”

That claimed, customers who are operating their CrushFTP instances within just a DMZ (demilitarized zone) restricted ecosystem are shielded towards the attacks.

Simon Garrelou of Airbus CERT has been credited with identifying and reporting the flaw. It has however to be assigned a CVE identifier.

Cybersecurity corporation CrowdStrike, in a publish shared on Reddit, mentioned it has observed an exploit for the flaw being utilized in the wild in a “specific vogue.”

These intrusions are said to have largely focused U.S. entities, with the intelligence gathering exercise suspected to be politically motivated.

“CrushFTP customers should really proceed to observe the vendor’s internet site for the most up-to-date guidance and prioritize patching,” CrowdStrike reported.

Discovered this short article intriguing? Stick to us on Twitter  and LinkedIn to read much more exclusive material we put up.

Some parts of this article are sourced from:
thehackernews.com

Previous Post: « BlackTech Targets Tech, Research, and Gov Sectors New ‘Deuterbear’ Tool
Next Post: Palo Alto Networks Discloses More Details on Critical PAN-OS Flaw Under Attack »

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)
  • PerfektBlue Bluetooth Vulnerabilities Expose Millions of Vehicles to Remote Code Execution
  • Securing Data in the AI Era
  • Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild
  • Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals

Copyright © 2025 · AllTech.News, All Rights Reserved.