CVE-2025-11371: Gladinet Triofox Critical Vulnerability
A critical flaw (CVSS 9.1) in Gladinet Triofox exploited by Storm-2603 for initial access in ransomware attacks. Used to probe for local…
A critical flaw (CVSS 9.1) in Gladinet Triofox exploited by Storm-2603 for initial access in ransomware attacks. Used to probe for local…
A threat actor known for deploying Warlock ransomware by exploiting vulnerabilities in on-premises SharePoint servers since mid-2025. Uses tools like Velociraptor, Cloudflare…
Ransomware deployed by threat actor Storm-2603, often exploiting known vulnerabilities in on-premises SharePoint servers. Used in parallel with other techniques to establish…
Gladinet's Triofox product was exploited via CVE-2025-11371 (CVSS 9.1) by Storm-2603 for initial access, probing for local file inclusion.
Velociraptor was deployed by Storm-2603 to blend malicious activity with trusted administrative behavior during ransomware attacks.
A vulnerable driver (NSecKrnl.sys) was used by Storm-2603 as a conduit to tamper with endpoint security protections and reduce visibility.
Gladinet Triofox was exploited via CVE-2025-11371 (CVSS 9.1) by Storm-2603, allowing probing for local file inclusion.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity remote code execution vulnerability, CVE-2026-45659 (CVSS 8.8), affecting Microsoft SharePoint…
Zoho Assist was used by Storm-2603 as one of multiple remote access channels during ransomware attacks, alongside Cloudflare tunneling and SSH.