Security teams detect only 14% of successful attacks, leaving the majority unnoticed in your system. Discover how breach and attack simulation can enhance your security measures. Download the Picus whitepaper for more insights.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about active exploitation of vulnerabilities in Ubiquiti UniFi OS and Lantronix serial-to-ethernet servers by malicious hackers.
As per directive BOD 26-04, federal agencies are required to apply available security updates or vendor-recommended mitigations within three days to protect their systems.
CISA has identified specific flaws in Ubiquiti systems that are being actively exploited. These include:
Ubiquiti has released security updates for these vulnerabilities, emphasizing the potential for remote exploitation without privileges.
Researchers at Bishop Fox have demonstrated that these flaws can be combined to achieve full remote code execution on vulnerable UniFi OS devices.
Bishop Fox has also provided a free detection script on GitHub to help identify vulnerable instances.
The security issue affecting Lantronix servers is known as CVE-2025-67038, a critical root-level command injection flaw affecting EDS5000 models running firmware 2.1.0.0R3.
The vulnerability lies in the HTTP RPC module, allowing attackers to inject arbitrary commands into the system.
Lantronix has released a patch for CVE-2025-67038 and advises users to upgrade to EDS5000 version 2.2.0.0R1.
CISA has not disclosed details regarding the exploitation of these vulnerabilities, with the risk of their use in ransomware campaigns marked as “Unknown.”
System administrators are urged to promptly apply available updates and recommended mitigations to safeguard their systems.
Security teams detect only 14% of successful attacks, leaving the majority unnoticed in your system. Discover how breach and attack simulation can enhance your security measures. Download the Picus whitepaper for more insights.
EU Takes Action Against Instagram and Facebook for Violating Illegal Content Rules
Warning: Facebook Creators Face Monetization Loss for Stealing and Reposting Videos
Facebook’s New Look: A Blend of Instagram’s Style
Facebook Compliance: ICE-tracking Page Removed After US Government Intervention
Facebook and Instagram to Reduce Personalized Ads for European Users
InstaDub: Meta’s AI Translation Tool for Instagram Videos
Reclaim Your Account: Facebook and Instagram Launch New Hub for Account Recovery
Meta discontinues Messenger apps for Windows and macOS
Subscribe to our weekly newsletter below and never miss the latest News or an exclusive offer.