CVE-2025-68670: discovering an RCE vulnerability in xrdp

2026-05-08T08:52:04Z497cd8f51248944803975e6ebba2112232af6da719f0295d97d6803497e63486
ABCDoorAPTAmazon SESApp StoreBECCVE-2025-68670FakeWalletJanelaRATKasperskyOceanLotusPhantomRPCPyPIRPCSilver FoxValleyRATZiChatBotcrypto stealeriOSindustrial threatsphishingpre-auth RCEprivilege escalationremote code executionsupply-chainxrdp

What happened

Kaspersky published multiple mid‑2026 investigations and reports. Notable items: researchers disclosed CVE-2025-68670, a pre‑authentication remote code execution in the xrdp server (promptly patched); uncovered OceanLotus using malicious PyPI wheel packages to deliver a dropper and ZiChatBot (supply‑chain abuse); documented Silver Fox tax‑themed lures delivering ValleyRAT and a new ABCDoor backdoor; exposed PhantomRPC, a Windows RPC privilege‑escalation technique that enables creation of a fake RPC server; and reported widespread abuse of Amazon SES for sophisticated phishing/BEC. Additional K

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
497cd8f51248944803975e6ebba2112232af6da719f0295d97d6803497e63486
Enrichment time
2026-05-08T08:52:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.