logo

Patch Now: Attackers Target OT Networks via Critical RCE Flaw

ID: 83d18035-2b21-545f-8a87-43c15deb7acf

STIX ID: report--83d18035-2b21-545f-8a87-43c15deb7acf

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2025-08-13

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Unit 42 has observed active exploitation of a critical RCE in Erlang/OTP (CVE-2025-32433, CVSS 10.0) that allows unauthenticated SSH protocol messages (post-authentication codes) to trigger remote command execution. Since May 1 attackers have used the flaw to deliver reverse shells and other payloads against OT and critical-infrastructure networks across multiple countries and industries (notably healthcare, agriculture, media, and high technology), with 3,376 detection signatures observed globally and ~70% originating from OT firewalls; vendors have released patches (OTP-27.3.3, OTP-26.2.5.11, OTP-25.3.2.20) and mitigations include IPS signature updates, restricting SSH access, or disabling SSH until patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.