Multi-Vector Cyber Threat Surge: Erlang/OTP, WinRAR, Citrix, and Telecom Breaches

·

·

2–4 minutes

Executive Summary

Between 11–12 August 2025, multiple high-impact vulnerabilities and breaches moved into active exploitation. Targets span OT infrastructureenterprise IT gateways, and telecom customer databases.

Immediate priorities: patch vulnerable systems, enforce network segmentation, and monitor for persistence artifacts.

Primary active threats:

  • Erlang/OTP SSH RCE (CVE-2025-32433) – OT infrastructure compromise
  • Bouygues Telecom breach – 6.4M records exposed
  • WinRAR zero-day (CVE-2025-8088) – ADS-based malware delivery
  • Citrix NetScaler exploits (CVE-2025-5777, CVE-2025-6543) – Web shell persistence
  • SAP S/4HANA & Landscape Transformation code injection – ERP takeover risk

Background

In the past 48 hours, exploitation tempo has accelerated across industrial control systemstelecom networks, and enterprise application stacks. Threat actors are combining zero-day vulnerabilities with credential theft and stealth persistence techniques.

Ransomware operators are increasingly bypassing encryption in favor of data theft and extortion.

When exploitation surges across OT infrastructure, enterprise gateways, and telecom systems simultaneously, organizations without a threat intelligence function are always the last to know.

Noorstream delivers threat intelligence, vulnerability management, and offensive security assessments for high-risk environments.

→ Book a Strategic Security Briefing

Active Campaigns

Erlang/OTP SSH Exploitation – CVE-2025-32433

  • CVSS: 10.0 – Remote Code Execution via SSH protocol message handling
  • Primary Targets: OT firewalls, SCADA-linked nodes
  • Detection Stats: 70% correlation with OT networks in Japan; U.S. leads detections (2,693, per ShadowServer/Noorstream correlation)
  • Risk: Remote attacker control of industrial environments

Bouygues Telecom Breach

  • Data Loss: 6.4M customer records (contact details, IBAN, contract data)
  • Access Vector: Likely credential compromise → internal admin systems
  • Risk: Exposure of sensitive customer communications and financial data

WinRAR Zero-Day – CVE-2025-8088

  • Technique: ADS path traversal → bypasses traditional scanners
  • Observed APTs: RomCom, Paper Werewolf
  • Payloads: SnipBot, RustyClaw, Mythic
  • Targeting: Spearphishing European and Canadian government/enterprise users

Citrix NetScaler Exploitation – CVE-2025-5777, CVE-2025-6543

  • Status: Dutch NCSC confirms ongoing exploitation
  • Exposure: ~7,000 vulnerable devices globally
  • Post-Exploitation: PHP web shells, rogue admin accounts, log tampering

SAP Patch Day – Critical Code Injection

  • CVE Impact: S/4HANA & Landscape Transformation
  • Severity: CVSS 9.9 – Remote execution with low privileges
  • Risk: ERP system takeover, theft of critical business data

TTPs

  • T1190 – Exploit Public-Facing Application (Erlang/OTP, Citrix)
  • T1059.006 – Command & Scripting Interpreter: Erlang Shell
  • T1566.001 – Spearphishing Attachment (WinRAR)
  • T1027.010 – Obfuscated Files: Alternate Data Streams (ADS)
  • T1505.003 – Server Software Component: Web Shell

Mitigation Priorities

  • Erlang/OTP: Update to OTP-27.3.3, OTP-26.2.5.11, or OTP-25.3.2.20; enforce OT/IT segmentation; monitor .beam anomalies
  • WinRAR: Upgrade to v7.13; enable ADS file monitoring; review COM/Startup registry keys
  • Citrix NetScaler: Patch immediately; run NCSC kill/clear scripts; audit for unknown admin accounts
  • SAP: Apply August 12 security updates; restrict ERP internet exposure
  • Telecom Security: Enforce MFA for all admin access; monitor for mass data exports

High-Risk Indicators

  • Ports/Domains: Port 4369 (EPMD), TCP 2222 (Ethernet/IP overlap)
  • Files: .beam payloads, ADS-hidden DLL/LNK, malicious .php in NetScaler directories
  • Registry: COM hijacks for msedge.dll
  • Hashes: Known malicious RAR archive signatures (available to authorized clients)

Noorstream Analysis

The past 48 hours confirm a strategic pivot by top-tier adversaries — from opportunistic vulnerability chaining to multi-surface campaigns deliberately engineered to stress multiple defensive layers at once.

  • Erlang/OTP in OT networks: This is a staging move. Compromising operational technology gives attackers a low-visibility platform to pivot into corporate IT without triggering standard detection tools.
  • WinRAR ADS exploitation: This bypasses most default security stacks and will persist in the wild long after patch adoption due to poor endpoint hygiene in mid-sized enterprises.
  • Citrix & SAP exploitation: Attackers are selecting gateway and ERP systems specifically because business continuity depends on them — maximizing leverage for extortion without encryption.

Operational takeaway: If your patching cycle is quarterly or longer, you will likely be compromised before you know these exploits exist. Treat this as an active threat environment, not a theoretical risk.

Latest Exploited Vulnerabilities

  • CVE-2026-85046
    Google Chromium V8 Type Confusion Vulnerability
    Vendor: Google
    Affected Product: Chromium V8
    Exploit Confirmed: 2026-09-04
  • CVE-2026-59822
    BerriAI LiteLLM Improper Authentication Vulnerability
    Vendor: BerriAI
    Affected Product: LiteLLM
    Exploit Confirmed: 2026-09-02
  • CVE-2026-48710
    Kludex Starlette HTTP Request/Response Smuggling Vulnerability
    Vendor: Kludex
    Affected Product: Starlette
    Exploit Confirmed: 2026-09-02
  • CVE-2026-49869
    Kestra OSS OS Command Injection Vulnerability
    Vendor: Kestra
    Affected Product: Kestra OSS
    Exploit Confirmed: 2026-09-02
  • CVE-2026-82329
    JFrog Artifactory Improper Authentication Vulnerability
    Vendor: JFrog
    Affected Product: Artifactory
    Exploit Confirmed: 2026-09-02

The Team Behind This Research Runs Every Briefing



© 2026 Noorstream Security. All Rights Reserved.

Discover more from Noorstream Security

Subscribe now to keep reading and get access to the full archive.

Continue reading