Executive Summary
Between 11–12 August 2025, multiple high-impact vulnerabilities and breaches moved into active exploitation. Targets span OT infrastructure, enterprise IT gateways, and telecom customer databases.
Immediate priorities: patch vulnerable systems, enforce network segmentation, and monitor for persistence artifacts.
Primary active threats:
- Erlang/OTP SSH RCE (CVE-2025-32433) – OT infrastructure compromise
- Bouygues Telecom breach – 6.4M records exposed
- WinRAR zero-day (CVE-2025-8088) – ADS-based malware delivery
- Citrix NetScaler exploits (CVE-2025-5777, CVE-2025-6543) – Web shell persistence
- SAP S/4HANA & Landscape Transformation code injection – ERP takeover risk
Background
In the past 48 hours, exploitation tempo has accelerated across industrial control systems, telecom networks, and enterprise application stacks. Threat actors are combining zero-day vulnerabilities with credential theft and stealth persistence techniques.
Ransomware operators are increasingly bypassing encryption in favor of data theft and extortion.
When exploitation surges across OT infrastructure, enterprise gateways, and telecom systems simultaneously, organizations without a threat intelligence function are always the last to know.
Noorstream delivers threat intelligence, vulnerability management, and offensive security assessments for high-risk environments.
Active Campaigns
Erlang/OTP SSH Exploitation – CVE-2025-32433
- CVSS: 10.0 – Remote Code Execution via SSH protocol message handling
- Primary Targets: OT firewalls, SCADA-linked nodes
- Detection Stats: 70% correlation with OT networks in Japan; U.S. leads detections (2,693, per ShadowServer/Noorstream correlation)
- Risk: Remote attacker control of industrial environments
Bouygues Telecom Breach
- Data Loss: 6.4M customer records (contact details, IBAN, contract data)
- Access Vector: Likely credential compromise → internal admin systems
- Risk: Exposure of sensitive customer communications and financial data
WinRAR Zero-Day – CVE-2025-8088
- Technique: ADS path traversal → bypasses traditional scanners
- Observed APTs: RomCom, Paper Werewolf
- Payloads: SnipBot, RustyClaw, Mythic
- Targeting: Spearphishing European and Canadian government/enterprise users
Citrix NetScaler Exploitation – CVE-2025-5777, CVE-2025-6543
- Status: Dutch NCSC confirms ongoing exploitation
- Exposure: ~7,000 vulnerable devices globally
- Post-Exploitation: PHP web shells, rogue admin accounts, log tampering
SAP Patch Day – Critical Code Injection
- CVE Impact: S/4HANA & Landscape Transformation
- Severity: CVSS 9.9 – Remote execution with low privileges
- Risk: ERP system takeover, theft of critical business data
TTPs
- T1190 – Exploit Public-Facing Application (Erlang/OTP, Citrix)
- T1059.006 – Command & Scripting Interpreter: Erlang Shell
- T1566.001 – Spearphishing Attachment (WinRAR)
- T1027.010 – Obfuscated Files: Alternate Data Streams (ADS)
- T1505.003 – Server Software Component: Web Shell
Mitigation Priorities
- Erlang/OTP: Update to OTP-27.3.3, OTP-26.2.5.11, or OTP-25.3.2.20; enforce OT/IT segmentation; monitor .beam anomalies
- WinRAR: Upgrade to v7.13; enable ADS file monitoring; review COM/Startup registry keys
- Citrix NetScaler: Patch immediately; run NCSC kill/clear scripts; audit for unknown admin accounts
- SAP: Apply August 12 security updates; restrict ERP internet exposure
- Telecom Security: Enforce MFA for all admin access; monitor for mass data exports
High-Risk Indicators
- Ports/Domains: Port 4369 (EPMD), TCP 2222 (Ethernet/IP overlap)
- Files: .beam payloads, ADS-hidden DLL/LNK, malicious .php in NetScaler directories
- Registry: COM hijacks for msedge.dll
- Hashes: Known malicious RAR archive signatures (available to authorized clients)
Noorstream Analysis
The past 48 hours confirm a strategic pivot by top-tier adversaries — from opportunistic vulnerability chaining to multi-surface campaigns deliberately engineered to stress multiple defensive layers at once.
- Erlang/OTP in OT networks: This is a staging move. Compromising operational technology gives attackers a low-visibility platform to pivot into corporate IT without triggering standard detection tools.
- WinRAR ADS exploitation: This bypasses most default security stacks and will persist in the wild long after patch adoption due to poor endpoint hygiene in mid-sized enterprises.
- Citrix & SAP exploitation: Attackers are selecting gateway and ERP systems specifically because business continuity depends on them — maximizing leverage for extortion without encryption.
Operational takeaway: If your patching cycle is quarterly or longer, you will likely be compromised before you know these exploits exist. Treat this as an active threat environment, not a theoretical risk.

