
India-Pakistan military conflict escalates amid strikes and counter strikes; major cricket tournament IPL suspended indefinitely
Section: News
A significant security vulnerability has been identified in CrushFTP, a widely used data transfer software, which could allow unauthorized access to attackers over the internet.
This vulnerability affects versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0, as noted in the CVE entry for the security flaw. The issue enables potential attackers to send unauthenticated HTTP requests to CrushFTP, granting them unauthorized access (CVE-2025-2825, CVSS score of 9.8, categorized as critical).
While the manufacturer has provided limited details about the vulnerability, it has been reported under a 'Responsible Disclosure' process. Currently, there are no confirmed exploits in the wild. However, users utilizing the DMZ feature in CrushFTP can be assured that their software remains secure against this flaw.
The company urges administrators to promptly update to versions 10.8.4 or 11.3.1, or any later releases. For those using previous versions, an automatic update option is available in the settings, requiring a manual entry in the prefs.XML file, specifically 'daily_check_and_auto_update_on_idle', starting from version 11.2.3_19. However, a bug may affect this feature in Windows systems. IT administrators can also find the updated software packages on the official CrushFTP download page, which is considered the most reliable method for applying the updates.
Cybercriminals often target data transfer software as it can serve as a gateway to sensitive information, enabling them to extort companies for ransom. Notably, the cyber gang Cl0p previously exploited a similar software, MOVEit Transfer, to exfiltrate data from numerous high-profile companies and demanded ransom payments.
CrushFTP has been flagged as a potential target for malicious actors looking to exploit its vulnerabilities. In late April, cybersecurity researchers observed attacks targeting a flaw within the software, with hundreds of instances accessible from the internet in Germany alone.
Section: News
Section: Arts
Section: Politics
Section: Politics
Section: News
Section: Politics
Section: Health Insurance
Section: Health
Section: Health
Section: Politics
Health Insurance in Germany is compulsory and sometimes complicated, not to mention expensive. As an expat, you are required to navigate this landscape within weeks of arriving, so check our FAQ on PKV. For our guide on resources and access to agents who can give you a competitive quote, try our PKV Cost comparison tool.
Germany is famous for its medical expertise and extensive number of hospitals and clinics. See this comprehensive directory of hospitals and clinics across the country, complete with links to their websites, addresses, contact info, and specializations/services.
Offene Wunde is a documentary theater piece about the attack at the Olympia Einkaufszentrum (OEZ) by Tunay Önder and Christine Umpfenbach. On July 22, 2016, a perpetrator motivated by racism killed nine young people from Munich: Armela, Can, Dijamant, Guiliano, Hüseyin, Roberto, Sabine, Selçuk,...
No comments yet. Be the first to comment!