Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability

State-Sponsored Hackers Exploiting Libraesva Email Security Gateway Vulnerability

Posted on September 24, 2025September 24, 2025 By CWS

Sep 24, 2025Ravie LakshmananVulnerability / E mail Safety
Libraesva has launched a safety replace to handle a vulnerability in its E mail Safety Gateway (ESG) answer that it stated has been exploited by state-sponsored menace actors.
The vulnerability, tracked as CVE-2025-59689, carries a CVSS rating of 6.1, indicating medium severity.
“Libraesva ESG is affected by a command injection flaw that may be triggered by a malicious e mail containing a specifically crafted compressed attachment, permitting potential execution of arbitrary instructions as a non-privileged consumer,” Libraesva stated in an advisory.
“This happens on account of an improper sanitization throughout the elimination of lively code from recordsdata contained in some compressed archive codecs.”
In a hypothetical assault state of affairs, an attacker might exploit the flaw by sending an e mail containing a specifically crafted compressed archive, permitting a menace actor to leverage the appliance’s improper sanitization logic to in the end execute arbitrary shell instructions.

The shortcoming impacts Libraesva ESG variations 4.5 by 5.5.x earlier than 5.5.7, with fixes launched in 5.0.31, 5.1.20, 5.2.31, 5.3.16, 5.4.8, and 5.5.7. Libraesva famous within the alert that variations under 5.0 have reached end-of-support and should be manually upgraded to a supported launch.
The Italian e mail safety firm additionally acknowledged that it has recognized one confirmed incident of abuse, and that the menace actor is “believed to be a overseas hostile state entity.” It didn’t share any additional particulars on the character of the exercise, or who could also be behind it.
“The one‑equipment focus underscores the precision of the menace actor (believed to be a overseas hostile state) and highlights the significance of fast, complete patch deployment,” Libraesva stated, including it deployed a repair inside 17 hours of flagging the abuse.
In gentle of lively exploitation, it is important that customers of the ESG software program replace their situations to the newest model as quickly as potential to mitigate potential threats.

The Hacker News Tags:Email, Exploiting, Gateway, Hackers, Libraesva, Security, StateSponsored, Vulnerability

Post navigation

Previous Post: Chrome High-severity Vulnerabilities Let Attackers Access Sensitive Data and Crash System
Next Post: Kali Linux 2025.3 Released With New Features and 10 New Hacking Tools

Related Posts

How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines How To Automate Alert Triage With AI Agents and Confluence SOPs Using Tines The Hacker News
ZAST.AI Secures M to Enhance AI-Driven Code Security ZAST.AI Secures $6M to Enhance AI-Driven Code Security The Hacker News
Google Pixel 10 Adds C2PA Support to Verify AI-Generated Media Authenticity Google Pixel 10 Adds C2PA Support to Verify AI-Generated Media Authenticity The Hacker News
Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack The Hacker News
KadNap Malware Uses Asus Routers for Stealth Botnet KadNap Malware Uses Asus Routers for Stealth Botnet The Hacker News
CISOs Tackle Burnout and Reduce MTTR Without Extra Staff CISOs Tackle Burnout and Reduce MTTR Without Extra Staff The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark