Clop Ransomware Group Exploiting Gladinet CentreStack Servers to Steal Data
ID: 7a9c072f-5954-507a-a5ff-c93cb9087d92
STIX ID: report--7a9c072f-5954-507a-a5ff-c93cb9087d92
Feed Name: cybersecurityNews.com
Threat Score
**Clop is actively exploiting CentreStack/Triofox (CVE-2025-11371 and CVE-2025-14611) to obtain machine keys via an LFI endpoint, perform ViewState deserialization for RCE, forge persistent access tickets and exfiltrate data; organizations should update to version 16.12.10420.56791, rotate machine keys, and review web logs for suspicious GET requests containing the encrypted Web.config path.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
