#Triofox
Hackers exploited a critical vulnerability and the built-in antivirus feature in Gladinet's Triofox file-sharing and remote-access platform to achieve remote code execution with SYSTEM privileges.
Hackers abuse Triofox antivirus feature to deploy remote access tools
Hackers exploited a critical vulnerability and the built-in antivirus feature in Gladinet's Triofox file-sharing and remote-access platform to achieve remote code execution with SYSTEM privileges.
www.bleepingcomputer.com
November 11, 2025 at 8:02 PM
Threat actors are exploiting a zero-day vulnerability (CVE-2025-11371) in Gladinet CentreStack and Triofox products, which allows a local attacker to access system files without authentication.
Hackers exploiting zero-day in Gladinet file sharing software
Threat actors are exploiting a zero-day vulnerability (CVE-2025-11371) in Gladinet CentreStack and Triofox products, which allows a local attacker to access system files without authentication.
www.bleepingcomputer.com
October 10, 2025 at 7:08 PM
UNC6485 turned “localhost” into everyone’s admin panel and the AV path into a SYSTEM catapult. Copycats ride RDP over 443 next. Patch Triofox 16.7.10368.56560 now. 🔒🧯

Get the playbook first—subscribe.

blog.alphahunt.io/triofox-expl...

#AlphaHunt #CyberSecurity #Triofox #CVE202512480
Triofox Exploitation Cluster (UNC6485): Six-Month Outlook, Copycat Risk, and What to Watch
UNC6485 is farming Triofox: Host: localhost → setup → mint admin → AV path = your script → SYSTEM → RMM + reverse RDP/443. Patch to 16.7.10368.56560 now. Copycats next. 🔥🛡️
blog.alphahunt.io
November 24, 2025 at 10:45 PM
🚨CVE-2025-30406 is under active exploit — 7 orgs hit. 
Update CentreStack & Triofox now. 

Try with Modat Magnify: 
Run → web.headers~"Set-Cookie: y-glad-state" 
magnify.modat.io 

#ModatMagnify #CyberSecurity #RCE #CVE202530406 #ModatMagnify #CentreStack #Triofox #VulnerabilityAlert #PatchNow
April 15, 2025 at 9:31 AM
cloud.google.com/blog/topics/...

google cloud / mandiant blogged about a cool investigation that I got to pitch in on & had a small verse to contribute in the broader context of it. these are the things that remind me how much I enjoy what I do.
Unauthenticated Remote Access via Triofox Vulnerability CVE-2025-12480 | Google Cloud Blog
An unauthenticated access vulnerability in Gladinet's Triofox platform, exploited by the threat actor UNC6485.
cloud.google.com
November 10, 2025 at 5:25 PM
Hackers are exploiting a new, undocumented vulnerability in the implementation of the cryptographic algorithm present in Gladinet's CentreStack and Triofox products for secure remote file access and sharing.
Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks
Hackers are exploiting a new, undocumented vulnerability in the implementation of the cryptographic algorithm present in Gladinet's CentreStack and Triofox products for secure remote file access and sharing.
www.bleepingcomputer.com
December 11, 2025 at 9:49 PM
🚨 Alert — A 9.0 CVSS flaw in Gladinet’s CentreStack also affects Triofox—both used for remote access.

Attackers exploited it as a zero-day in March, hitting 7 orgs by April 11.

🔑 Root cause: Hardcoded crypto keys → enabled RCE via PowerShell + DLL sideloading
#Vulnerability
Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability
Hardcoded key flaw in Triofox and CentreStack exploited as zero-day in March, affecting 7 firms.
thehackernews.com
April 15, 2025 at 7:23 PM
Second zero-day in Gladinet file-sharing servers this year

www.huntress.com/blog/gladine...
Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw | Huntress
Huntress has observed in-the-wild exploitation of a Local File Inclusion vulnerability in Gladinet CentreStack and Triofox products.
www.huntress.com
October 11, 2025 at 10:55 PM
(1/3)
🚨 Hackers exploited a critical flaw in Gladinet’s Triofox (#CVE202512480), using the built-in antivirus feature for remote code execution with SYSTEM privileges. The auth bypass was caused by spoofing “localhost” in HTTP headers. #CyberSecurity #Infosec #RCE #Triofox
November 12, 2025 at 1:11 PM
Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability reconbee.com/gladinets-tr...

#gladinet #triofox #centrestack #RCEvulnerability #cybersecurity
Gladinet's Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability
by the vulnerability read more about Gladinet's Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability
reconbee.com
April 15, 2025 at 11:35 AM
CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild!

We've got some post exploitation and detection opportunities for you:

#DFIR #threatintel #CTI

www.huntress.com/blog/cve-202...
CVE-2025-30406 - Critical Gladinet CentreStack & Triofox Vulnerability Exploited In The Wild | Huntress
Huntress has observed in the wild exploitation against CVE-2025-30406, a weakness due to hardcoded cryptographic keys.
www.huntress.com
April 14, 2025 at 3:57 PM
--Cryptographic flaw found in Gladinet's CentreStack and Triofox products,
--Brave says its new AI browser is inherently dangerous,
--CISA orders GeoServer fix exploited in XML External Entity (XXE) injection attacks,
--Trump to withhold funding for states that regulate AI, 5/6
December 12, 2025 at 3:17 PM
Zero-day in file-sharing software leads to RCE, and attacks are ongoing
Zero-day in file-sharing software leads to RCE, and attacks are ongoing
Usually we’d say patch up… not this time Security research firm Huntress is warning all users of Gladinet's CentreStack and Triofox file-sharing tools to urgently apply an available mitigation, as a zero-day is being actively exploited and there's no patch available.…
dlvr.it
October 10, 2025 at 4:02 PM
CISA Warns of Gladinet CentreStack and Triofox Vulnerability Exploited in Attacks
CISA Warns of Gladinet CentreStack and Triofox Vulnerability Exploited in Attacks
cybersecuritynews.com
December 17, 2025 at 11:31 AM
Threat actors exploit Triofox AV scanner (CVE-2025-12480) for RCE - deploying AnyDesk & Zoho Assist for persistence.

#CyberSecurity #Triofox #RCE #ThreatIntel
November 11, 2025 at 12:23 PM
Might be based on these vulnerabilities reported by Huntress last week.
Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks
Hackers are exploiting a new, undocumented vulnerability in the implementation of the cryptographic algorithm present in Gladinet's CentreStack and Triofox products for secure remote file access and s...
www.bleepingcomputer.com
December 18, 2025 at 6:49 PM
U.S. CISA adds Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple and Gladinet CentreStack and Triofox flaws to its Known Exploited Vulnerabilities catalog.
securityaffairs.com
December 15, 2025 at 7:56 PM
Critical vulnerability CVE-2025-12480 in Triofox exploited by UNC6485 to install remote access tools via antivirus feature. Update to version 16.7.10368.56560 immediately. #CyberSecurity #Triofox #CVE202512480 Link: thedailytechfeed.com/critical-vul...
November 11, 2025 at 3:33 PM
Synology, Triofox e SAP correggono zero-day e flaw critiche RCE, bypass e credenziali hardcoded con patch novembre 2025.

#rce #SAP #sql #Synology #Triofox #zeroday
www.matricedigitale.it/2025/11/12/v...
November 12, 2025 at 8:06 AM
Detect CVE-2025-30406 exploitation attempts – critical RCE in Gladinet CentreStack & Triofox platforms actively exploited in the wild – with a set of Sigma rules in the SOC Prime Platform. buff.ly/pfd3HaG
CVE-2025-30406 Detection: Critical RCE Vulnerability in Gladinet CentreStack & Triofox Under Active Exploitation | SOC Prime
Detect CVE-2025-30406 exploitation – critical flaw in Gladinet CentreStack & Triofox leveraged in the wild – using Sigma rules in the SOC Prime Platform.
buff.ly
April 17, 2025 at 1:22 PM
🚨 @HuntressLabs identified active exploitation of a Local File Inclusion vulnerability affecting Gladinet CentreStack and Triofox systems.

A temporary workaround is available while a patch is in development:

www.huntress.com/blog/gladine...
Active Exploitation of Gladinet CentreStack and Triofox Local File Inclusion Flaw | Huntress
Huntress has observed in-the-wild exploitation of a Local File Inclusion vulnerability in Gladinet CentreStack and Triofox products.
www.huntress.com
October 10, 2025 at 2:22 AM
CISA impone patch per zero-day Samsung CVE-2025-21042, con vulnerabilità critiche in AWS, Triofox e librerie JavaScript expr-eval.

#AWS #cisa #Landfall #rce #spyware #Triofox
www.matricedigitale.it/2025/11/11/c...
November 11, 2025 at 8:01 AM