More

    Hackers hijacked antivirus features to install malware – here’s what we know



    • CVE-2025-12480 in Triofox allowed zero-day exploitation via improper access control
    • UNC6485 attackers deployed Zoho Assist, AnyDesk, and SSH tunneling for remote access
    • Patch released July 26; newer Triofox version available October 14 for mitigation

    Popular remote file sharing and collaboration platform Triofox carried a critical vulnerability that was exploited as a zero-day used to deploy a remote access tool which granted the attackers lateral movement capabilities.

    Security researchers from Google’s Mandiant and its Threat Intelligence Group (GTIG) flagged that Triofox comes with a built-in antivirus feature, which carried an “improper access control” flaw that allowed access to initial setup pages even after setup is complete.


    https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-2560-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img