Pirates are divided into critical servers used by global giants, and only one line of code is needed


  • The pirates launched attacks one day after the complete technical writing of the defect was made public
  • Many servers have remained vulnerable for weeks despite a corrected correction long before disclosure
  • The injection of zero bytes in the field of username allows attackers to bypass the connection and execute the Lua code

Security researchers have confirmed that attackers actively exploit critical vulnerability in the FTP Wing server, a widely used solution to manage file transfers.

Huntress researchers say that the flaw identified as CVE-2025-47812 was publicly disclosed on June 30, and the exploitation started almost immediately, just a day later.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top