Security researchers warn that hackers are exploiting a critical vulnerability in Wing FTP Server to gain control of affected systems.
The vulnerability identified as CVE-2025-47812 can allow remote code execution at the root level due to a null byte and Lua injection issue, according to Huntress researchers.
By infosecbulletin
/ Monday , August 24 2026
A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
By infosecbulletin
/ Monday , August 24 2026
A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
By infosecbulletin
/ Monday , August 24 2026
A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
By infosecbulletin
/ Sunday , August 23 2026
More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
By infosecbulletin
/ Sunday , August 23 2026
US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
By infosecbulletin
/ Friday , August 21 2026
Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
By infosecbulletin
/ Friday , August 21 2026
T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
By infosecbulletin
/ Friday , August 21 2026
Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
By infosecbulletin
/ Friday , August 21 2026
Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
By infosecbulletin
/ Thursday , August 20 2026
CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Huntress researchers noticed a customer being exploited on July 1, just one day after the previous vulnerability research was published.
Attackers can exploit the vulnerability by crafting a specific input in Lua, the programming language used for handling sessions in Wing FTP.

Wing FTP has about 10,000 customers, including major companies. They informed Cybersecurity Dive that they’ve emailed customers with instructions to fix the vulnerability through an upgrade.
Shadowserver Foundation researchers noted that exploitation of a vulnerability has been occurring since July 1. They estimate about 2,000 computers use Wing FTP and are currently identifying how many may be vulnerable.
The U.S., China and Germany have the most potential exposures, according to Shadowserver.
RCE Security said it discovered the problem while performing a test for one of its customers.
The company warned that the flaw could enable root-level access, allowing attackers to gain significant control.
“Ultimately, this means that an unauthenticated attacker can escalate their privileges to the highest possible ones, which usually always means a total server compromise, including all secrets such as passwords,” said Julien Ahrens, a penetration tester at RCE security. “They can read, modify and delete any file.”
This could not only enable data to be quietly exfiltrated, but systems are also potentially vulnerable to ransomware.