Hackers are breaking into critical servers used by global giants, and it only takes one line of code




  • Hackers launched attacks just one day after the flaw’s full technical write-up was made public
  • Many servers stayed vulnerable for weeks despite a fix being released long before the disclosure
  • Null byte injection in the username field lets attackers bypass login and run Lua code

Security researchers have confirmed attackers are actively exploiting a critical vulnerability in Wing FTP Server, a widely used solution for managing file transfers.

Researchers at Huntress say the flaw identified as CVE-2025-47812 was disclosed publicly on June 30, and exploitation began almost immediately, just a day later.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *