Brahim[verified]@IBthecoderActive Exploitation
CVE-2025-4632 was actively exploited in September 2026 to compromise a Samsung MagicINFO server, enabling attackers to deploy cryptomining malware. While Samsung released a fix in May 2025, the vulnerability remained exploitable in unpatched systems exposed to the internet.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The text reports active exploitation of CVE-2025-4632 by a threat actor, with detailed post-exploitation behavior and tooling used to deploy a Monero miner. The central focus is real-world abuse rather than patching, PoC sharing, or false-positive clarification.
The Daily Tech Feed[verified]@dailytechonxActive Exploitation
The tweet reports an active attack chain exploiting CVE-2025-4632 to deploy cryptominers on Windows machines via remote access tools, while explicitly advising users to patch MagicINFO.
Cybersecurity News Everyday[verified]@TweetThreatNewsActive Exploitation
Huntress observed an intrusion exploiting CVE-2025-4632 in Samsung MagicINFO, leading to further malicious activity including AnyDesk installations and a Monero miner. The report does not detail the vulnerability itself or mention any available patches.
Dark Web Informer@DarkWebInformerActive Exploitation
The tweet reports an active exploitation of a small MSSQL database using CVE-2025-4632, resulting in a data leak and the deployment of a crypto miner on the compromised server.
@pedri77@pedri77Patch
Samsung released a patch for the high‑severity CVE-2025-4632 affecting MagicINFO 9 Server, which is already being exploited in the wild.
DailyCVE@dailycveDisclosure
The post announces a critical path traversal vulnerability (CVE‑2025‑4632) in Samsung MagicINFO 9 Server, but does not provide details on exploits, patches, or real‑world attacks.