Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Active exploitation, Play Store trojans, and perimeter compromise


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: The week of 18 to 25 December 2025 was dominated by active exploitation of Cisco and Fortinet flaws, alongside Cellik Android RAT’s Play Store trojanization, elevated ransomware claims, and continued targeting of email security gateways, according to FireCompass. The pattern shows why exposed perimeter controls and trusted app channels now create immediate identity and access risk, not just patching debt.

NHIMG editorial — based on content published by FireCompass: Weekly Report on New Hacking Techniques and Critical CVEs, 18 Dec to 25 Dec 2025

By the numbers:

Questions worth separating out

Q: What breaks when a perimeter appliance is exploited before patching is complete?

A: When an internet-facing gateway is exploited before patching finishes, the trust boundary itself becomes the failure point.

Q: Why do exposed gateways and SSO appliances create so much downstream risk?

A: They sit on privileged traffic paths and often see credentials, tokens, and authenticated sessions in transit.

Q: How can security teams tell whether mobile trojans are becoming an identity problem?

A: Watch for overlay-driven phishing, unusual permission grants, sideloading attempts, and business logins that coincide with abnormal device behaviour such as camera, microphone, or data spikes.

Practitioner guidance

  • Prioritise internet-facing appliance exposure review Inventory all exposed email gateways, VPN concentrators, and firewall management surfaces, then validate whether patching, feature flags, or quarantine services create unauthenticated or low-friction entry points.
  • Enforce mobile application control on BYOD Block sideloaded APKs through MDM, require device compliance for business access, and alert on overlay behaviour, anomalous permission requests, or unusual sensor use.
  • Review SSO and federation trust assumptions Check whether forged or replayed authentication assertions could still be accepted on perimeter devices, then tighten certificate validation, logging, and config export protections.

What's in the full article

FireCompass's full weekly report covers the operational detail this post intentionally leaves for the source:

  • Exact attack flow for Cisco AsyncOS RCE, including the quarantine path and backdoor behaviour
  • Technical request and response patterns for the Fortinet SSO bypass that exposed admin sessions
  • The darkweb claim mix by family, including the 64 tracked claims and ransomware distribution
  • CISO takeaways on specific defensive actions for SEG exposure, mobile threat hunting, and perimeter validation

👉 Read FireCompass's weekly report on active exploitation and critical CVEs →

Active exploitation, Play Store trojans, and perimeter compromise?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

Active exploitation is now an identity governance problem, not just a vulnerability problem. The report shows attackers using exposed appliances to intercept or forge access, which means the control failure is often trust in the system boundary itself. When gateways and SSO layers are compromised, IAM assumptions about authenticated sessions become unreliable. Practitioners should manage externally reachable systems as part of identity risk, not as separate infrastructure hygiene.

A few things that frame the scale:

A question worth separating out:

Q: Should organisations prioritise perimeter hardening or mobile controls first?

A: Do both, but prioritise whichever path currently exposes the most privileged access. If external gateways and SSO appliances are internet-facing, hardening them first reduces immediate blast radius. If BYOD is a major access channel, mobile application control and posture enforcement become equally urgent because they protect the credentials users bring into the environment.

👉 Read our full editorial: Weekly report on active exploitation and mobile trojans



   
ReplyQuote
Share: