CVE-2025-68670: discovering an RCE vulnerability in xrdp
2026-05-08T08:52:04Z•497cd8f51248944803975e6ebba2112232af6da719f0295d97d6803497e63486
ABCDoorAPTAmazon SESApp StoreBECCVE-2025-68670FakeWalletJanelaRATKasperskyOceanLotusPhantomRPCPyPIRPCSilver FoxValleyRATZiChatBotcrypto stealeriOSindustrial threatsphishingpre-auth RCEprivilege escalationremote code executionsupply-chainxrdp
What happened
Kaspersky published multiple mid‑2026 investigations and reports. Notable items: researchers disclosed CVE-2025-68670, a pre‑authentication remote code execution in the xrdp server (promptly patched); uncovered OceanLotus using malicious PyPI wheel packages to deliver a dropper and ZiChatBot (supply‑chain abuse); documented Silver Fox tax‑themed lures delivering ValleyRAT and a new ABCDoor backdoor; exposed PhantomRPC, a Windows RPC privilege‑escalation technique that enables creation of a fake RPC server; and reported widespread abuse of Amazon SES for sophisticated phishing/BEC. Additional K
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 497cd8f51248944803975e6ebba2112232af6da719f0295d97d6803497e63486
- Enrichment time
- 2026-05-08T08:52:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.