#CentreStack
Threat actors are exploiting a zero-day vulnerability (CVE-2025-11371) in Gladinet CentreStack and Triofox products, which allows a local attacker to access system files without authentication.
Hackers exploiting zero-day in Gladinet file sharing software
Threat actors are exploiting a zero-day vulnerability (CVE-2025-11371) in Gladinet CentreStack and Triofox products, which allows a local attacker to access system files without authentication.
www.bleepingcomputer.com
October 10, 2025 at 7:08 PM
Huntress has observed in-the-wild exploitation of CVE-2025-30406, a critical vulnerability in the Gladinet CentreStack enterprise file-sharing platform.
April 14, 2025 at 12:53 AM
Hackers are exploiting a new, undocumented vulnerability in the implementation of the cryptographic algorithm present in Gladinet's CentreStack and Triofox products for secure remote file access and sharing.
Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks
Hackers are exploiting a new, undocumented vulnerability in the implementation of the cryptographic algorithm present in Gladinet's CentreStack and Triofox products for secure remote file access and sharing.
www.bleepingcomputer.com
December 11, 2025 at 9:49 PM
Might be based on these vulnerabilities reported by Huntress last week.
Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks
Hackers are exploiting a new, undocumented vulnerability in the implementation of the cryptographic algorithm present in Gladinet's CentreStack and Triofox products for secure remote file access and s...
www.bleepingcomputer.com
December 18, 2025 at 6:49 PM
The Clop ransomware gang is targeting Internet-exposed Gladinet CentreStack file servers in a new data theft extortion campaign.
Clop ransomware targets Gladinet CentreStack servers for extortion
The Clop ransomware gang is targeting Internet-exposed Gladinet CentreStack file servers in a new data theft extortion campaign.
www.bleepingcomputer.com
December 18, 2025 at 8:17 PM
Today in the SUN we feature an article from @bleepingcomputer.com on Clop ransomware targeting Gladinet CentreStack in data theft attacks.

Read more below:
www.bleepingcomputer.com/news/securit...

#cybersecurity
@andyjabbour.bsky.social
Clop ransomware targets Gladinet CentreStack in data theft attacks
The Clop ransomware gang is targeting Internet-exposed Gladinet CentreStack file servers in a new data theft extortion campaign.
www.bleepingcomputer.com
December 19, 2025 at 5:08 PM
🚨CVE-2025-30406 is under active exploit — 7 orgs hit. 
Update CentreStack & Triofox now. 

Try with Modat Magnify: 
Run → web.headers~"Set-Cookie: y-glad-state" 
magnify.modat.io 

#ModatMagnify #CyberSecurity #RCE #CVE202530406 #ModatMagnify #CentreStack #Triofox #VulnerabilityAlert #PatchNow
April 15, 2025 at 9:31 AM
--NHS tech company hit with cyber incident,
--BeaverTail infostealer emerges,
--Clop is targeting Gladinet CentreStack file servers,
--Incident response supervisor and ransomware negotiator plead guilty to extortion, 3/4
December 19, 2025 at 2:32 PM
Second zero-day in Gladinet file-sharing servers this year

www.huntress.com/blog/gladine...
Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw | Huntress
Huntress has observed in-the-wild exploitation of a Local File Inclusion vulnerability in Gladinet CentreStack and Triofox products.
www.huntress.com
October 11, 2025 at 10:55 PM
🚨 Alert — A 9.0 CVSS flaw in Gladinet’s CentreStack also affects Triofox—both used for remote access.

Attackers exploited it as a zero-day in March, hitting 7 orgs by April 11.

🔑 Root cause: Hardcoded crypto keys → enabled RCE via PowerShell + DLL sideloading
#Vulnerability
Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability
Hardcoded key flaw in Triofox and CentreStack exploited as zero-day in March, affecting 7 firms.
thehackernews.com
April 15, 2025 at 7:23 PM
CVE-2025-30406 in CentreStack lets attackers compromise MSPs, impacting many clients. A single exploit enables widespread data theft, ransomware, and outages. Immediate patching and client communication are crucial due to multi-tenancy's cascading risk.#CentreStackVulnerability
April 15, 2025 at 4:15 PM
Zero-day in file-sharing software leads to RCE, and attacks are ongoing
Zero-day in file-sharing software leads to RCE, and attacks are ongoing
Usually we’d say patch up… not this time Security research firm Huntress is warning all users of Gladinet's CentreStack and Triofox file-sharing tools to urgently apply an available mitigation, as a zero-day is being actively exploited and there's no patch available.…
dlvr.it
October 10, 2025 at 4:02 PM
--Cryptographic flaw found in Gladinet's CentreStack and Triofox products,
--Brave says its new AI browser is inherently dangerous,
--CISA orders GeoServer fix exploited in XML External Entity (XXE) injection attacks,
--Trump to withhold funding for states that regulate AI, 5/6
December 12, 2025 at 3:17 PM
CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild!

We've got some post exploitation and detection opportunities for you:

#DFIR #threatintel #CTI

www.huntress.com/blog/cve-202...
CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild | Huntress
Huntress has observed in the wild exploitation against CVE-2025-30406, a weakness due to hardcoded cryptographic keys.
www.huntress.com
April 14, 2025 at 3:57 PM
Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability reconbee.com/gladinets-tr...

#gladinet #triofox #centrestack #RCEvulnerability #cybersecurity
Gladinet's Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability
by the vulnerability read more about Gladinet's Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability
reconbee.com
April 15, 2025 at 11:35 AM
-NSO's 2019 WhatsApp hacks impacted 1,223 victims in 51 countries
-Smishing Triad has a new phishing kit (Lighthouse)
-New AkiraBot spam service
-APT reports on Sapphire Werewolf, GOFFEE, SideCopy, APT-Q-12, and Shuckworm
-Active exploitation of Gladinet CentreStack
-New RemoteMonologue technique
April 11, 2025 at 8:53 AM
Clop ransomware targets Gladinet CentreStack in data theft attacks
Clop ransomware targets Gladinet CentreStack in data theft attacks
The Clop ransomware gang is targeting Internet-exposed Gladinet CentreStack file servers in a new data theft extortion campaign.
www.bleepingcomputer.com
December 18, 2025 at 8:31 PM
CISA Warns of Gladinet CentreStack and Triofox Vulnerability Exploited in Attacks
CISA Warns of Gladinet CentreStack and Triofox Vulnerability Exploited in Attacks
cybersecuritynews.com
December 17, 2025 at 11:31 AM
CLOP targets Gladinet CentreStack servers in large-scale extortion campaign
CLOP targets Gladinet CentreStack servers in large-scale extortion campaign
The Clop ransomware group is targeting Gladinet CentreStack file servers in a new large-scale extortion campaign.
securityaffairs.com
December 19, 2025 at 1:11 PM
Gladinet has released security updates for its CentreStack business solution to address a local file inclusion vulnerability (CVE-2025-11371) that threat actors have leveraged as a zero-day since late September.
Gladinet fixes actively exploited zero-day in file-sharing software
Gladinet has released security updates for its CentreStack business solution to address a local file inclusion vulnerability (CVE-2025-11371) that threat actors have leveraged as a zero-day since late September.
www.bleepingcomputer.com
October 16, 2025 at 3:11 PM
米国CISAがGladinet CentreStackとCWP Control Web Panelの脆弱性を既知の脆弱性カタログに追加

U.S. CISA adds Gladinet CentreStack, and CWP Control Web Panel flaws to its Known Exploited Vulnerabilities catalog #SecurityAffairs (Nov 5)

securityaffairs.com/184226/secur...
U.S. CISA adds Gladinet CentreStack, and CWP Control Web Panel flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Gladinet CentreStack, and CWP Control Web Panel flaws to its Known Exploited Vulnerabilities catalog.
securityaffairs.com
November 6, 2025 at 1:26 AM