
Vulnerabilities of Western logistics. On May 21, Western intelligence agencies released joint advisory AA25-141A about attacks targeting infrastructure of Western logistics and tech companies. Alongside the usual Five Eyes, intelligence services from Germany, Czech Republic, Poland, Denmark, Estonia, France, and the Netherlands also contributed.
The document mentions the exploitation of vulnerabilities:
Remote Code Execution – WinRAR (CVE-2023-38831)
Elevation of Privilege – Microsoft Outlook (CVE-2023-23397)
Remote Code Execution – Roundcube (CVE-2020-12641)
Code Injection – Roundcube (CVE-2021-44026)
Cross Site Scripting – Roundcube (CVE-2020-35730)
Patches, exploits, and signs of in-the-wild exploitation have been available for years for these vulnerabilities.