URGENT: Critical CrushFTP Auth Bypass Vulnerability Now Under Active Attack
A critical authentication bypass vulnerability (CVE-2025-2825) in CrushFTP file transfer software is under active exploitation, with attackers using publicly available proof-of-concept code. Shadowserver detected numerous attacks targeting over 1,500 vulnerable internet-exposed servers. Cr...
