Active Campaign Against Triofox: How Attackers Bypassed Setup and Gained SYSTEM Execution

Executive Summary A cyber-espionage group, identified as UNC6485, is actively exploiting a critical vulnerability in Gladinet’s Triofox file-sharing platform. This campaign aims to gain initial network access, steal data, and establish long-term persistence. Attackers are bypassing authentication to create administrator accounts and deploy remote access tools. Organizations using Triofox are strongly advised to apply the […]

The post Active Campaign Against Triofox: How Attackers Bypassed Setup and Gained SYSTEM Execution appeared first on SecPod Blog.