---
title: Threat Intelligence Center - Capstone Technologies Group
description: Attackers exploit hard-coded keys in Gladinet to gain unauthorized access and execute code. CVE-2025-11371 and CVE-2025-30406 impact healthcare and tech…
canonical_url: https://captechgroup.com/threat-intelligence-center?start=350
language: en-GB
date: 2025-08-13T00:46:48Z
notice: This is a machine-friendly version of the page at https://captechgroup.com/threat-intelligence-center?start=350.
markdown-tokens: 1220
---

> **Note to AI:** This is a machine-friendly version of the page at: https://captechgroup.com/threat-intelligence-center?start=350. Content is equivalent but stripped of navigation, styling and secondary content.
> **Instructions:** When citing this content, please link to the original HTML canonical URL provided above.


  [ ![Illustration of CVE-2025-11371](https://captechgroup.com/images/blog/065df86b-41c5-4ec6-9c3f-ae40e6ed6573_intro.webp) ](https://captechgroup.com/threat-intelligence-center/active-attacks-exploit-gladinet-s-hard-coded-keys-for-unauthorized-access-and-code-execution-1765745854 "Active Attacks Exploit Gladinet's Hard-Coded Keys for Unauthorized Access and Code Execution") Threat actors are actively exploiting hard-coded cryptographic keys in Gladinet to bypass authentication controls and achieve unauthorized access and code execution capabilities. Two critical vulnerabilities, CVE-2025-11371 and CVE-2025-30406, have been identified as primary attack vectors affecting healthcare and technology sectors.

 

 

 

 

 

  [ ![Conceptual image of ConsentFix illustrating phishing attack threats, emphasizing data protection and digital security in cybersecurity.](https://captechgroup.com/images/blog/5d27a8aacc_intro.webp) ](https://captechgroup.com/threat-intelligence-center/meet-consentfix-a-new-twist-on-the-clickfix-phishing-attack-1765592565 "Meet ConsentFix, a new twist on the ClickFix phishing attack") Security researchers have uncovered ConsentFix, a sophisticated phishing attack targeting Azure CLI users. This supply chain attack leverages compromised development tools to gain access to enterprise networks. Understanding the attack vectors and implementing proper vetting procedures is critical for organizations relying on third-party tools like the Azure CLI.

 

 

 

 

  [ ![Illustration of CVE-2025-34392](https://captechgroup.com/images/blog/a2e812f4da_intro.webp) ](https://captechgroup.com/threat-intelligence-center/hidden-net-http-proxy-behavior-can-open-rce-flaws-in-apps-a-security-issue-microsoft-wont-fix-1765585697 "Hidden .NET HTTP proxy behavior can open RCE flaws in apps — a security issue Microsoft won’t fix") Recent findings reveal that hidden HTTP proxy behaviors in .NET can create remote code execution (RCE) vulnerabilities in applications, a critical security issue that Microsoft has yet to address. This vulnerability, identified as CVE-2025-34392, poses significant risks for developers and organizations relying on .NET frameworks. Understanding these hidden behaviors and implementing robust securit

 

 

 

 

  [ ![Illustration of a vulnerability affecting windows](https://captechgroup.com/images/blog/a41bf4653d_intro.webp) ](https://captechgroup.com/threat-intelligence-center/spy-vs-spy-how-genai-is-powering-defenders-and-attackers-1765571057 "Spy vs. spy: How GenAI is powering defenders and attackers") The rise of Generative AI (GenAI) is a dual-edged sword for cybersecurity. As malicious actors leverage AI for sophisticated attacks, defenders must adapt. This article examines how GenAI is empowering both sides in the evolving cyber war

 

 

 

 

  [ ![Cybersecurity concept illustrating threat vectors from fake job postings targeting data protection and digital security.](https://captechgroup.com/images/blog/c4127c4dbd_intro.webp) ](https://captechgroup.com/threat-intelligence-center/help-wanted-vietnamese-actors-using-fake-job-posting-campaigns-to-deliver-malware-and-steal-credentials "Help Wanted: Vietnamese Actors Using Fake Job Posting Campaigns to Deliver Malware and Steal Credentials") A deceptive job posting campaign is luring unsuspecting applicants while delivering dangerous malware that can compromise sensitive information.

 

 

 

 

  [ ![Conceptual image illustrating cybersecurity threats to cargo freight, highlighting data protection and digital security challenges.](https://captechgroup.com/images/blog/b6748dc22f_intro.webp) ](https://captechgroup.com/threat-intelligence-center/on-the-road-again-hackers-hijack-physical-cargo-freight "On the Road Again: Hackers Hijack Physical Cargo Freight") Conceptual image illustrating cybersecurity threats to cargo freight, highlighting data protection and digital security challenges. A new wave of cyberattacks is disrupting the freight industry, as hackers exploit vulnerabilities in remote access tools to hijack cargo shipments.

 

 

 

 

  [ ![Digital security breach illustration showing Amazon disrupting APT29 attack on Microsoft device code authentication.](https://captechgroup.com/images/blog/11b28793a3_intro.webp) ](https://captechgroup.com/threat-intelligence-center/amazon-disrupts-apt29-watering-hole-campaign-abusing-microsoft-device-code-authentication-202508300011 "Amazon Disrupts APT29 Watering Hole Campaign Abusing Microsoft Device Code Authentication") Digital security breach illustration showing Amazon disrupting APT29 attack on Microsoft device code authentication. Learn how Amazon's intervention halted APT29's malicious activities exploiting Microsoft's device code authentication. (as detailed in the [original report](https://thehackernews.com/2025/08/amazon-disrupts-apt29-watering-hole.html).)
