Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT Firewalls

Researchers Spot Surge in Erlang/OTP SSH RCE Exploits, 70% Target OT Firewalls

Posted on August 11, 2025August 11, 2025 By CWS

Aug 11, 2025Ravie LakshmananVulnerability / Community Safety
Malicious actors have been noticed exploiting a now-patched important safety flaw impacting Erlang/Open Telecom Platform (OTP) SSH as early as starting of Might 2025, with about 70% of detections originating from firewalls defending operational know-how (OT) networks.
The vulnerability in query is CVE-2025-32433 (CVSS rating: 10.0), a lacking authentication subject that may very well be abused by an attacker with community entry to an Erlang/OTP SSH server to execute arbitrary code. It was patched in April 2025 with variations OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20.
Then in June 2025, the U.S. Cybersecurity and Infrastructure Safety Company (CISA) added the flaw to its Identified Exploited Vulnerabilities (KEV) catalog, based mostly on proof of lively exploitation.
“On the coronary heart of Erlang/OTP’s safe communication capabilities lies its native SSH implementation — answerable for encrypted connections, file transfers and most significantly, command execution,” Palo Alto Networks Unit 42 researchers Adam Robbie, Yiheng An, Malav Vyas, Cecilia Hu, Matthew Tennis, and Zhanhao Chen mentioned.

“A flaw on this implementation would enable an attacker with community entry to execute arbitrary code on susceptible methods with out requiring credentials, presenting a direct and extreme danger to uncovered property.”
The cybersecurity firm’s evaluation of telemetry knowledge has revealed that over 85% of exploit makes an attempt have primarily singled out healthcare, agriculture, media and leisure, and excessive know-how sectors within the U.S., Canada, Brazil, India, and Australia, amongst others.

Within the assaults noticed, the profitable exploitation of CVE-2025-32433 is adopted by the risk actors utilizing reverse shells to realize unauthorized distant entry to focus on networks. It is at present not identified who’s behind the efforts.
“This widespread publicity on industrial-specific ports signifies a major world assault floor throughout OT networks,” Unit 42 mentioned. “Evaluation of affected industries demonstrates variance within the assaults.”
“Attackers are trying to use the vulnerability in brief, high-intensity bursts. These are disproportionately focusing on OT networks and making an attempt to entry uncovered companies over each IT and industrial ports.”

The Hacker News Tags:ErlangOTP, Exploits, Firewalls, RCE, Researchers, Spot, SSH, Surge, Target

Post navigation

Previous Post: Hackers Poison Google Paid Ads With Fake Tesla Websites to Deliver Malware
Next Post: SoupDealer Malware Bypasses Every Sandbox, AV’s and EDR/XDR in Real-World Incidents

Related Posts

WindRelay Malware Uses NFC for Payment Fraud on Android WindRelay Malware Uses NFC for Payment Fraud on Android The Hacker News
100+ Fake Chrome Extensions Found Hijacking Sessions, Stealing Credentials, Injecting Ads 100+ Fake Chrome Extensions Found Hijacking Sessions, Stealing Credentials, Injecting Ads The Hacker News
Silver Dragon APT41 Targets Governments with Advanced Techniques Silver Dragon APT41 Targets Governments with Advanced Techniques The Hacker News
RabbitMQ Vulnerabilities Expose OAuth Secrets, Threaten Security RabbitMQ Vulnerabilities Expose OAuth Secrets, Threaten Security The Hacker News
AI’s Impact on SOC Efficiency and Alert Management AI’s Impact on SOC Efficiency and Alert Management The Hacker News
How AI-Enabled Workflow Automation Can Help SOCs Reduce Burnout How AI-Enabled Workflow Automation Can Help SOCs Reduce Burnout The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F-Droid 2.0 Debuts with Major Redesign for App Discovery
  • China and US to Create AI Safety Channel Amid Ongoing Talks
  • Lunex Stealer Exploits AMD Driver for Credential Theft
  • Local AI Model Evades EDR Detection with Modified Credential Dumper
  • Enhancing AI Agent Security with Zero Trust Principles

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark