{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Daily Security Review","title":"CVE-2025-31324: A Critical SAP Zero-Day in Active Exploitation","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/5aa5147b\"></iframe>","width":"100%","height":180,"duration":733,"description":"A critical zero-day vulnerability — CVE-2025-31324 — is shaking the enterprise tech world.\n In this episode, we dive deep into the alarming exploit targeting SAP NetWeaver Java systems, specifically the Visual Composer component, now under active attack.\nThis vulnerability enables unauthorized file uploads, which attackers are using to deploy webshells, cryptominers (like XMRig), and potential infostealers. Threat actors are already exploiting this flaw in the wild, as confirmed by leading cybersecurity firms and SAP itself.\nYou’ll hear:\nHow attackers are weaponizing CVE-2025-31324 for remote code execution\nReal-world attack activity detected as early as April 26, 2025\nTools and indicators of compromise (IOCs) released by SAP, Onapsis, Mandiant, Pathlock, and WithSecure\nWhat defenders need to do right now to patch or mitigate\nWhy experts expect a second wave of attacks, as exploit code circulates publicly\nWe also cover:\nThe CVSS 10.0 criticality score and what it means\nHow attackers are using Living Off the Land (LOL) techniques, such as certutil, for lateral movement\nSAP’s emergency patch (Note #3594142) and temporary mitigation strategies\nIf your organization uses SAP, this is must-listen content. Even if it doesn’t, this episode is a masterclass in how fast zero-days go from discovery to weaponization — and how defenders can keep up.\n🔐 Patching isn't optional anymore — it's urgent.","thumbnail_url":"https://img.transistorcdn.com/pL79_MJFeJHamQ_ztImsGmDSMdl27VMk_30TAkieujE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNzg5/ZjlhNzM5Y2M4Njli/NjkxNzgyODA2Nzhi/MDI2ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}