Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Critical CVEs and ransomware chaining: what practitioners need to act on


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20360
Topic starter  

TL;DR: A week of exploitation across Oracle E-Business Suite, Redis, GoAnywhere MFT, Unity, and SonicWall showed how zero-days, credential harvesting, and rapid post-exploitation chaining can compress attacker dwell time to minutes or hours, according to FireCompass. The lesson is that exposure management now has to account for exploit speed, not just patch backlog.

NHIMG editorial — based on content published by FireCompass: Weekly Report: New Hacking Techniques and Critical CVEs 7 Oct – 13 Oct 2025

By the numbers:

Questions worth separating out

Q: What breaks when an internet-facing access broker is vulnerable to pre-auth RCE?

A: The trust boundary breaks first.

Q: Why do credentials and privilege matter so much in ransomware incidents?

A: Ransomware operators usually need administrative access to disable security tools, stop services, move laterally, and encrypt at scale.

Q: How can security teams tell whether exploit activity has become an identity incident?

A: Look for account creation, privilege changes, anomalous administrative tools, directory reconnaissance, or sudden credential rotation needs on the affected host.

Practitioner guidance

  • Harden internet-facing enterprise applications Review ERP, MFT, and VPN platforms for pre-authentication execution paths, template processing, and deserialisation exposure.
  • Treat remote-management tools as privileged access Inventory RMM agents, tunnelling tools, and remote desktop pathways on critical servers, then define who is allowed to install or invoke them.
  • Compress patching around exploit-confirmed CVEs Move from generic patch backlog to exploit-confirmed remediation windows for internet-facing assets.

What's in the full article

FireCompass's full report covers the operational detail this post intentionally leaves for the source:

  • Step-by-step exploit breakdowns for Oracle E-Business Suite, Redis, GoAnywhere MFT, Unity, and SonicWall.
  • Indicator examples for hunting suspicious XML Publisher activity, Lua abuse, RMM deployment, and tunnel creation.
  • Incident-by-incident timelines showing how exploitation progressed into persistence, lateral movement, and ransomware.
  • Threat-actor context and tool usage details that help SOC teams build detections and triage priorities.

👉 Read FireCompass's weekly report on new hacking techniques and critical CVEs →

Critical CVEs and ransomware chaining: what practitioners need to act on?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19951
 

Exploit speed is now a governance variable, not just an operational one. The report shows attackers moving from flaw discovery to active exploitation fast enough that traditional patch calendars can lose the race. In NHI terms, this is the same problem seen with exposed secrets and standing credentials, where access survives long enough to be abused before controls react. Practitioners should treat time-to-exploit as a control input, not a post-incident metric.

A few things that frame the scale:

  • 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.

A question worth separating out:

Q: Should organisations prioritise patching or identity hardening first after active exploitation is detected?

A: They should do both, but identity hardening often limits the fastest spread while patching addresses the root entry point. If the exploit path already includes SSO, tokens, or privileged credentials, revocation and containment can reduce impact before the patch cycle completes.

👉 Read our full editorial: Critical CVEs and ransomware chaining expose enterprise attack paths



   
ReplyQuote
Share: