Bruteforce Scans for CrushFTP , (Tue, Mar 3rd)

2026-03-04T21:38:19Zc2b9d98884ff9c31fcd5eddd866b9394a161603a6ee762c5091b08ff34d11585
CVE-2024-4040CVE-2025-31161CVE-2025-54309bruteforcecritical-infrastructurecrushftpexploitationhoneypotincident-responsemalwarepatchingphishingrtfscan-detectionscanningvulnerability-managementwiresharkzip

What happened

SANS ISC diary (late Feb–early Mar 2026) highlights active brute-force scanning against CrushFTP instances and recalls multiple serious CrushFTP vulnerabilities (CVE-2024-4040, CVE-2025-31161, and the July 2025 zero-day CVE-2025-54309 that was actively exploited). Other notable entries: a FedEx-themed phishing email delivering malware, a how‑to on ZIP files inside RTFs (malicious document technique), release of Wireshark 4.6.4 (fixes three vulnerabilities), and guest diaries on honeypot usage with AI and a framework for mapping critical infrastructure interdependencies. Operators should treat:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
c2b9d98884ff9c31fcd5eddd866b9394a161603a6ee762c5091b08ff34d11585
Enrichment time
2026-03-04T21:38:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Bruteforce Scans for CrushFTP , (Tue, Mar 3rd) · Baitaphish