Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch

Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch

•

Episode description

Ubiquiti UniFi OS Critical Flaws and ColdFusion Emergency Patch

Ubiquiti has released security updates addressing seven critical vulnerabilities in UniFi OS, including one rated CVSS 10.0 that permits unauthenticated remote code execution. The widespread deployment of UniFi hardware in UK small business networks makes this a priority patching event. Separately, CISA has added an Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalogue, issuing an emergency patch deadline for US federal agencies after confirming active exploitation in the wild. ColdFusion remains widely deployed in UK professional services, legal and accountancy firms, and public sector environments, often in legacy web applications where platform visibility is poor. Finally, an ongoing phishing campaign delivering AsyncRAT and Remcos trojans continues to target finance, procurement, and operations staff using macro-enabled Excel attachments and fileless execution techniques. Mauven MacLeod provides specific guidance on how to verify patching status with IT providers, configure email filtering to block macro-enabled attachments, and enforce Office macro policy across business environments.

Chapters

  • Introduction Mauven opens the eighth of July briefing with a direct question about firmware version awareness, highlighting seven critical Ubiquiti UniFi OS vulnerabilities including one rated CVSS 10.0, a CISA emergency patch order for Adobe ColdFusion, and an ongoing phishing campaign targeting finance and procurement staff.
  • Ubiquiti UniFi OS: Seven Critical Flaws, One at Maximum Severity Seven critical vulnerabilities in Ubiquiti UniFi OS have been disclosed, including a CVSS 10.0 command injection flaw permitting unauthenticated remote code execution. Given the widespread deployment of UniFi hardware in UK SMB networks and typically flat network architectures, successful exploitation provides attackers with perimeter-level access. Mauven advises requesting written confirmation of firmware updates from IT providers or checking firmware versions directly if self-managed.
  • Call to Action Mauven encourages listeners to follow the show and share the episode with others who may have unpatched Ubiquiti infrastructure.
  • Adobe ColdFusion: Actively Exploited, CISA Emergency Patch Deadline CISA has added a maximum-severity Adobe ColdFusion vulnerability to its Known Exploited Vulnerabilities catalogue, issuing an emergency patch deadline for US federal agencies by the end of the week. The flaw permits remote code execution and is confirmed exploited in the wild. ColdFusion remains widely deployed in UK professional services, legal, accountancy, and public sector environments, often in legacy web applications with poor platform visibility. Mauven recommends requesting written confirmation of patching from hosting providers and suppliers.
  • On the Radar: AsyncRAT and Remcos Phishing Campaign An ongoing phishing campaign delivers AsyncRAT and Remcos remote access trojans via macro-enabled Excel attachments, using fileless execution techniques including steganography to evade signature-based detection. The campaign specifically targets finance, procurement, and operations staff who routinely receive Excel files from external parties. Mauven recommends disabling macro execution by default, deploying Attack Surface Reduction rules, configuring email gateways to quarantine macro-enabled files, and briefing staff in targeted functions.
  • Closing Summary Mauven summarises three actionable items: obtain written confirmation of UniFi firmware updates, verify ColdFusion patching status with suppliers, and enforce Office macro policy with appropriate email filtering. None require significant budget, only deliberate follow-through.

Links

No chapters are available for this episode.