
CERT Orange Cyberdefense
@certcyberdef
First Private CERT in Europe. Tweets are about vulnerability and cyber threats. Corporate account: @OrangeCyberDef / @OrangeCyberFR GPG KeyID: 0xBD54B276
ID: 30185673
https://research.cert.orangecyberdefense.com/ 10-04-2009 08:25:21
190 Tweet
9,9K Followers
415 Following

#CVE-2025-32432 #0day #CraftCMS discovered by CERT Orange Cyberdefense 💥Unauthenticated Remote Code Execution. No CVSS yet, we suggest to give it a 10 📌40,000 IP addresses representing over 37,000 domain names exposed, 12,168 unique domains vulnerable Blog: blog.onyphe.io/en/cve-2025-32…


🆕 Just released a blogpost on a #Sorillus RAT campaign our CERT Orange Cyberdefense observed in March. Likely 🇧🇷 threat actors, use of numerous tunneling services like ngrok[.]app, ngrok[.]dev, ngrok[.]pro, localto[.]net, ply[.]gg, campaign still active… ➡️ orangecyberdefense.com/global/blog/ce…
![Mar_Pich (@mar_pich) on Twitter photo 🆕 Just released a blogpost on a #Sorillus RAT campaign our <a href="/CERTCyberdef/">CERT Orange Cyberdefense</a> observed in March.
Likely 🇧🇷 threat actors, use of numerous tunneling services like ngrok[.]app, ngrok[.]dev, ngrok[.]pro, localto[.]net, ply[.]gg, campaign still active…
➡️ orangecyberdefense.com/global/blog/ce… 🆕 Just released a blogpost on a #Sorillus RAT campaign our <a href="/CERTCyberdef/">CERT Orange Cyberdefense</a> observed in March.
Likely 🇧🇷 threat actors, use of numerous tunneling services like ngrok[.]app, ngrok[.]dev, ngrok[.]pro, localto[.]net, ply[.]gg, campaign still active…
➡️ orangecyberdefense.com/global/blog/ce…](https://pbs.twimg.com/media/GtvhD8yWcAAc1df.jpg)
