#crushFTP
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
blog.netomize.ca
September 28, 2026 at 12:39 AM
-SMS blasting incidents are rising
-Iranian security firm behind APT39
-Chinese hackers breach Singapore critical infra
-new SharePoint and CrushFTP zero-days
-Japan releases free decrypters for Phobos and 8base ransomware

Newsletter: news.risky.biz/risky-bullet...
Podcast: risky.biz/RBNEWS454/
July 21, 2025 at 9:16 AM
New CrushFTP zero-day. CrushFTP candidly admits its error from a previous patch

www.crushftp.com/crush11wiki/...
July 20, 2025 at 12:48 PM
CrushFTP warned customers of an unauthenticated HTTP(S) port access vulnerability and urged them to patch their servers immediately.
CrushFTP warns users to patch unauthenticated access flaw immediately
CrushFTP warned customers of an unauthenticated HTTP(S) port access vulnerability and urged them to patch their servers immediately.
www.bleepingcomputer.com
March 25, 2025 at 8:11 PM
The CrushFTP project has released a security update for a vulnerability that can allow attackers to access the FTP server without authentication

www.rapid7.com/blog/post/20...
March 25, 2025 at 6:28 PM
In der Datentransfer-Software CrushFTP klafft eine Sicherheitslücke, die Angreifern aus dem Netz unbefugten Zugriff verschafft. #Security
Datentransfer-Software CrushFTP ermöglicht unbefugten Zugriff
In der Datentransfer-Software CrushFTP klafft eine Sicherheitslücke, die Angreifern aus dem Netz unbefugten Zugriff verschafft.
www.heise.de
March 27, 2025 at 8:25 AM
🚨 Hackers are exploiting a CrushFTP Zero-Day (CVE-2025-54309) to gain admin access and take over servers. Update to v10.8.5 or v11.3.4 now!

Read: hackread.com/hackers-expl...

#CyberSecurity #CrushFTP #Vulnerability #0day
Hackers Exploit CrushFTP Zero-Day to Take Over Servers
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
August 30, 2025 at 12:24 PM
pwning my FTP server is a weird way to say you have a Crush on me but okay 🥰

anyways check out our analysis of some CrushFTP CVE-2025-31161 post exploitation activity!

www.huntress.com/blog/crushft...
https://www.huntress.com/blog/crushftp-cve-2025-31161-auth-bypass-and-post-exploitation
t.co
April 4, 2025 at 9:57 PM
Over 1,000 CrushFTP instances currently exposed online are vulnerable to hijack attacks that exploit a critical security bug, providing admin access to the web interface.
Over 1,000 CrushFTP servers exposed to ongoing hijack attacks
Over 1,000 CrushFTP instances currently exposed online are vulnerable to hijack attacks that exploit a critical security bug, providing admin access to the web interface.
www.bleepingcomputer.com
July 21, 2025 at 11:34 AM
CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers.
CrushFTP zero-day exploited to gain admin access on servers
CrushFTP is warning that threat actors are actively exploiting a zero-day vulnerability tracked as CVE-2025-54309, which allows attackers to gain administrative access via the web interface on vulnerable servers.
www.bleepingcomputer.com
July 18, 2025 at 10:24 PM
Project Discovery has published a technical write-up and PoC for a recent CrushFTP authentication bypass tracked as CVE-2025-2825

Let the attacks begin, I guess!

projectdiscovery.io/blog/crushft...
CrushFTP Authentication Bypass - CVE-2025-2825 — ProjectDiscovery Blog
Enterprise file transfer solutions are critical infrastructure for many organizations, facilitating secure data exchange between systems and users. CrushFTP, a widely used multi-protocol file transfer...
projectdiscovery.io
April 1, 2025 at 11:10 AM
CrushFTP hat einen neuen CVE-Eintrag für die bereits angegriffene Sicherheitslücke angelegt. Darin finden sich nun auch Details. #Security
CrushFTP: Neuer CVE-Eintrag und Details zu attackierter Schwachstelle
CrushFTP hat einen neuen CVE-Eintrag für die bereits angegriffene Sicherheitslücke angelegt. Darin finden sich nun auch Details.
www.heise.de
April 8, 2025 at 6:20 AM
Notícia da SecurityWeek

"Details Emerge on CVE Controversy Around Exploited CrushFTP Vulnerability " #bolhasec
Two CVEs, One Critical Flaw: Inside the CrushFTP Vulnerability Controversy
Two CVEs now exist for an actively exploited CrushFTP vulnerability and much of the security industry is using the ‘wrong one’.
www.securityweek.com
May 21, 2025 at 1:30 AM
👉🏻 After exploitation, here'a s detailed #CrushFTP RCE explanation.

🔗 pwn.guide/free/web/cru...
July 31, 2025 at 7:01 AM
Two CVEs, One Critical Flaw: Inside the CrushFTP Vulnerability Controversy - (CVE-2025-31161 vs. CVE-2025-2825)
#CyberAlerts #CyberSecurity
www.securityweek.com/details-emer...
Two CVEs, One Critical Flaw: Inside the CrushFTP Vulnerability Controversy
Two CVEs now exist for an actively exploited CrushFTP vulnerability and much of the security industry is using the ‘wrong one’.
www.securityweek.com
April 3, 2025 at 4:57 PM
Alert! We are scanning for unpatched CrushFTP instances vulnerable to CVE-2025-54309. This vulnerability is exploited in the wild: www.crushftp.com/crush11wiki/...

We see 1040 instances unpatched on 20th July. Top countries affected: US, Germany, Canada

dashboard.shadowserver.org/statistics/c...
July 21, 2025 at 10:21 AM
Attackers are now targeting a critical authentication bypass vulnerability in the CrushFTP file transfer software using exploits based on publicly available proof-of-concept code.
Critical auth bypass bug in CrushFTP now exploited in attacks
Attackers are now targeting a critical authentication bypass vulnerability in the CrushFTP file transfer software using exploits based on publicly available proof-of-concept code.
www.bleepingcomputer.com
April 1, 2025 at 12:46 PM
We are observing CrushFTP CVE-2025-2825 exploitation attempts based on publicly available PoC exploit code. You can track attempts on our Dashboard at dashboard.shadowserver.org/statistics/h...

Still 1512 unpatched instances vulnerable to CVE-2025-2825

dashboard.shadowserver.org/statistics/h...
March 31, 2025 at 5:01 PM
We are now sharing CrushFTP CVE-2024-4040 (CrushFTP VFS Sandbox Escape Vulnerability) vulnerable instances. At least 1400 vulnerable on 2024-04-24. CVE-2024-4040 is currently exploited in the wild & on US CISA KEV.

Top affected: US, Germany, Canada

dashboard.shadowserver.org/statistics/c...
April 25, 2024 at 7:47 AM
CrushFTP CVE-2025-2825 flaw actively exploited in the wild
CrushFTP CVE-2025-2825 flaw actively exploited in the wild
Attackers exploit CrushFTP CVE-2025-2825 flaw, enabling unauthenticated access to unpatched devices using public proof-of-concept code.
securityaffairs.com
April 1, 2025 at 2:42 PM
Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers 🔥🕵️‍♂️

A newly disclosed critical security flaw in CrushFTP has come under active exploitation in the wild!🤪👀

#cybersecurity #cybersecuritynews #technews #news #sundaynews #sundaymorning

thehackernews.com/2025/07/hack...
Hackers Exploit Critical CrushFTP Flaw to Gain Admin Access on Unpatched Servers
CrushFTP flaw CVE-2025-54309 exploited in wild, giving attackers admin access. Older builds before July 1 are at high risk
thehackernews.com
July 20, 2025 at 8:16 AM
0-day (cve-2025-54309) in CrushFTP - wird angegriffen - deutsche Firmen wohl schon betroffen

www.borncity.com/blog/2025/07...
CrushFTP mit 0-Day-Schwachstelle CVE-2025-54309
[English]Jemand aus der Blog-Leserschaft, der das Programm CrushFTP zum Dateitransfer verwendet? Inzwischen haben sich mehrere Leser gemeldet (danke dafür), dass es Meldungen über eine 0-Day…
www.borncity.com
July 19, 2025 at 11:50 AM