Bleepingcomputer
Hackers Exploit ArrayOS AG VPN Vulnerability to Deploy Webshells
First seen 5 Dec 2025, 13:44 UTC
•


•38.3
Export
Article Content
Browse articles
Threat actors are exploiting a command injection vulnerability in ArrayOS AG VPN devices to deploy webshells and create unauthorized user accounts. The vulnerability has been actively targeted since at least August 2025, affecting various organizations. Array Networks issued a security update in May 2025 to address the flaw, but it remains untracked due to the lack of an assigned identifier.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
China-linked Cyber Group Expands Targeting to Southeastern Europe
China-Nexus APT UAT-7290 Targets South Asia Telecoms in Cyber Espionage Campaign
China-linked UAT-7290 Targets Telcos in Cyberespionage Campaign
UAT-7290 Cyber Espionage Targets South Asian Telecoms
Cisco Fixes Critical AsyncOS Vulnerability Under Attack