A Chinese language-speaking risk actor tracked as UAT-6382 has been linked to the exploitation of a now-patched remote-code-execution vulnerability in Trimble Cityworks to ship Cobalt Strike and VShell.
“UAT-6382 efficiently exploited CVE-2025-0944, performed reconnaissance, and quickly deployed a wide range of net shells and custom-made malware to take care of long-term entry,” Cisco Talos researchers
Main Menu
Subscribe to Updates
Get the latest creative news from FooBar about art, design and business.