A Samsung signage flaw at least 476 days old led to AnyDesk on try three and a miner built on the host
Huntress describes one managed endpoint: a MagicINFO flaw published at least 476 days earlier, AnyDesk on the third try, Defender switched off, then a Monero miner compiled on the host. It names no actor and no version; the useful part is how much each step left behind.
By Parminder Kumar Sharma · · 18 min read

476 days, three tries and eight days
Samsung's CVE record for CVE-2025-4632, a flaw in its MagicINFO 9 Server digital signage software, was published on 13 May 2025. Huntress's write-up of 24 September 2026 says an incident that began with exploitation of a known MagicINFO flaw, reportedly this one, started in "early September 2026". From 13 May 2025 to 1 September 2026 is 476 days, so the CVE record was at least 476 days old when the incident began. To the day of Huntress's write-up it is 499 days. CISA's due date for US federal agencies to fix it was 12 June 2025, which is 446 days before 1 September 2026. All day counts here are our arithmetic, shown in the factcheck.
The rest of the incident also comes in counts. The attacker needed three attempts to download the AnyDesk remote access tool, and Microsoft Defender removed the first two. After the first alert the customer was told how to remediate. Eight days later the same endpoint was reported again, tied to the same access vector. The attacker then created a local administrator account, disabled Defender, and ran a miner builder that compiled a Monero miner on the machine itself. That last step is what Huntress calls unique. The Hacker News, in its ThreatsDay bulletin of 1 October 2026, calls it a "novel attack".
Here is what none of that establishes. Huntress describes one managed endpoint, so it gives no victim count and no sector, size or country. It names no actor. It says the activity was "reportedly associated with" CVE-2025-4632, and it does not say which MagicINFO version the host ran or whether the server faced the internet. "Unique" is a statement about Huntress's own casework, not a finding that compiling on the victim's machine is spreading. And nothing in the write-up, or in anything else we found, says whether this flaw is being used against signage estates in the United Kingdom. This briefing makes no claim about UK victims.
What the story does show is how far a friendly label travels. "Digital signage" and "content management" sound like marketing tools. The record describes a Java web application on Tomcat, on a Windows host, where one path traversal flaw lets an attacker write files with the server's own system authority. Add a well-known remote access tool and the intruder starts to look like IT's own tooling. A comforting label is not a control.
The incident as Huntress describes it
Huntress published The Not So Silent Miner on 24 September 2026. It describes one managed endpoint, alerted in early September for activity that came from its Samsung MagicINFO Premium installation. Huntress's text names the installation "Premium", while the CVE record names "MagicINFO 9 Server"; the write-up does not state a version. The diagram puts the steps in Huntress's order and pairs each with the trace it left, using only what the write-up says.
Three details matter more than they first look.
First, the AnyDesk download that worked had tomcat9.exe as its grandparent process. That is the Apache Tomcat service on which MagicINFO runs, and it is how Huntress's analysts tied the commands back to the signage software.
Second, Defender worked twice. It detected and removed the first download, which used a built-in Windows certificate utility, and the second, which used a PowerShell web request. Huntress does not say why the third was not stopped. The actor then disabled Defender through a Windows settings component, and Huntress does not say whether tamper protection was switched on.
Third, the miner ran under the name explorer.exe with mining arguments on its command line. Huntress says legitimate Explorer does not use mining arguments, which it reads as a sign of an injected process.
Why compile on the host, and what that changes
Huntress offers one possible advantage: building the miner on the target lets an actor tailor it to the environment, for example to the endpoint's processor. It names the cost too. The build ran the .NET Framework utilities csc.exe and cvtres.exe, then a set of C compilers and related tools (donut.exe, tcc.exe, and the cc1.exe and gcc.exe parts of MinGW64), all as child processes of an unsigned parent, Silent XMR Miner Builder.exe, which ran from the new user's Documents folder. Huntress says the builder likely stemmed from the open-source SilentXMRMiner project, and that the result was a spike in activity that was "quite noisy" for endpoint detection and response (EDR) telemetry.
That makes the novelty narrower than the word "novel" suggests. The tooling is commodity and open source. What Huntress calls unique is where it was run, on the victim's own endpoint, and its evidence is its own telemetry. The practical point is the order of events. Repeated remote access tool downloads, a new administrator, Defender switched off and compilers on a signage server all came before the miner ran. Huntress's three prevention points are to patch internet-facing MagicINFO promptly, to treat repeated remote access tool downloads as a sign of compromise, and to monitor for unusual compiler activity, not just known miner binaries.
Stated and not stated
This table is limited to what Huntress's own write-up says. The right-hand column is the one to keep in mind before repeating the story.
What Huntress's write-up of 24 September 2026 states, and what it leaves out
- Topic
- Victim
- Stated
- One managed endpoint with a Samsung MagicINFO Premium installation, alerted in early September 2026
- Not stated
- Sector, size, country, host count, the exact date
- Topic
- The flaw
- Stated
- Activity "reportedly associated with" CVE-2025-4632, fixed in May 2025; customer told how to remediate
- Not stated
- MagicINFO version, internet exposure, how the flaw was confirmed, what the advice was
- Topic
- Second report
- Stated
- Eight days later the endpoint was reported again, tied to the same access vector
- Not stated
- Whether remediation was done, which report held which step
- Topic
- AnyDesk
- Stated
- Three download attempts; the first two removed by Defender; the third worked; a password was set
- Not stated
- Why the third was not stopped; what the AnyDesk session did
- Topic
- Account and Defender
- Stated
- A new local account named oldadministrator; Defender disabled via SystemSettingsAdminFlows.exe
- Not stated
- Whether tamper protection was on; any movement to other hosts
- Topic
- Miner
- Stated
- A Silent XMR Miner Builder run compiled a Monero miner, which connected to C3Pool as explorer.exe
- Not stated
- Hash rate, run time or earnings; the actor; links to earlier MagicINFO attacks
- Topic
- Novelty
- Stated
- "Unique" and "one such outlier" in Huntress's own casework
- Not stated
- That the method is new elsewhere, or spreading
| Topic | Stated | Not stated |
|---|---|---|
| Victim | One managed endpoint with a Samsung MagicINFO Premium installation, alerted in early September 2026 | Sector, size, country, host count, the exact date |
| The flaw | Activity "reportedly associated with" CVE-2025-4632, fixed in May 2025; customer told how to remediate | MagicINFO version, internet exposure, how the flaw was confirmed, what the advice was |
| Second report | Eight days later the endpoint was reported again, tied to the same access vector | Whether remediation was done, which report held which step |
| AnyDesk | Three download attempts; the first two removed by Defender; the third worked; a password was set | Why the third was not stopped; what the AnyDesk session did |
| Account and Defender | A new local account named oldadministrator; Defender disabled via SystemSettingsAdminFlows.exe | Whether tamper protection was on; any movement to other hosts |
| Miner | A Silent XMR Miner Builder run compiled a Monero miner, which connected to C3Pool as explorer.exe | Hash rate, run time or earnings; the actor; links to earlier MagicINFO attacks |
| Novelty | "Unique" and "one such outlier" in Huntress's own casework | That the method is new elsewhere, or spreading |
What the public record says about the flaw
Samsung, CVE.org, NVD and CISA's Known Exploited Vulnerabilities (KEV) catalogue each hold part of the record. The states below were read on 5 October 2026 at about 16:43 BST (15:43 UTC).
The public record for CVE-2025-4632, read 5 October 2026
- Source
- Samsung bulletin SVP-MAY-2025
- What it says
- SVE-2025-50001: improper limitation of a pathname lets attackers write an arbitrary file as system authority; the patch modifies verification logic of the input. No version number and no day on the page.
- State when read
- Page lists bulletins by month only
- Source
- CVE.org
- What it says
- Published 13 May 2025 by its CVE Numbering Authority (CNA), Samsung. MagicINFO 9 Server before 21.1052. CWE-22. CVSS 3.1 base score 9.8, vector AV:N/AC:L/PR:N/UI:N, assigned by Samsung.
- State when read
- PUBLISHED; last updated 26 February 2026
- Source
- NVD
- What it says
- NVD's own CVSS 3.1 score is also 9.8. CISA-ADP (source 134c704f-9b21-4f2e-91b3-4a467353bcc0) adds Stakeholder-Specific Vulnerability Categorization (SSVC) decision points: exploitation active, automatable yes, technical impact total.
- State when read
- Analyzed; last modified 17 June 2026; SSVC dated 20 August 2025
- Source
- CISA KEV catalogue
- What it says
- Listed 22 May 2025, due 12 June 2025, 21 days later. Known ransomware campaign use: Unknown.
- State when read
- Catalogue version 2026.10.04, released 4 October 2026 at 18:52 UTC
| Source | What it says | State when read |
|---|---|---|
| Samsung bulletin SVP-MAY-2025 | SVE-2025-50001: improper limitation of a pathname lets attackers write an arbitrary file as system authority; the patch modifies verification logic of the input. No version number and no day on the page. | Page lists bulletins by month only |
| CVE.org | Published 13 May 2025 by its CVE Numbering Authority (CNA), Samsung. MagicINFO 9 Server before 21.1052. CWE-22. CVSS 3.1 base score 9.8, vector AV:N/AC:L/PR:N/UI:N, assigned by Samsung. | PUBLISHED; last updated 26 February 2026 |
| NVD | NVD's own CVSS 3.1 score is also 9.8. CISA-ADP (source 134c704f-9b21-4f2e-91b3-4a467353bcc0) adds Stakeholder-Specific Vulnerability Categorization (SSVC) decision points: exploitation active, automatable yes, technical impact total. | Analyzed; last modified 17 June 2026; SSVC dated 20 August 2025 |
| CISA KEV catalogue | Listed 22 May 2025, due 12 June 2025, 21 days later. Known ransomware campaign use: Unknown. | Catalogue version 2026.10.04, released 4 October 2026 at 18:52 UTC |
Two things stand out. The 9.8 is Samsung's own score as the CNA, and NVD's agrees; CISA-ADP supplies exploitation context rather than a competing score. And the fixed version is on the CVE and NVD records, not on Samsung's bulletin page, which names the weakness and the month. Help Net Security reported at the time that Samsung released the 21.1052 hotfix on 7 May 2025 and that its release notes named CVE-2024-7399 rather than CVE-2025-4632 (secondary reporting). Huntress's own account is that the 2025 fix followed an incomplete fix for CVE-2024-7399.
A flaw with a history, and ten more behind it
CVE-2025-4632 is the second attempt at one weakness. Samsung's August 2024 bulletin (SVP-AUG-2024) fixed CVE-2024-7399, described in the same words. On 30 April 2025 a proof of concept for a flaw in version 21.1050 was published. Huntress said it saw exploitation of the latest version, and its follow-up gives 4 May 2025 as the earliest date in its indicator table. Arctic Wolf reported exploitation at the start of May, and the SANS Internet Storm Center reported Mirai-style botnet attempts on 5 May. The CVE record for the fix, CVE-2025-4632, appeared on 13 May, nine days after that earliest Huntress date; exploitation was being reported before the identifier existed. CISA listed it on 22 May.
Exposure is on record for May 2025 only. On 30 May 2025 Censys counted 1,101 internet-exposed MagicINFO servers. It could read a version for 116 of them, and 58 of those, half, were still on affected versions. Counts differ by method: Arctic Wolf told Help Net Security on 6 May 2025 that Shodan showed nearly 5,000 publicly accessible MagicINFO servers across several countries (secondary reporting). Huntress's counts from the same week show the other side: more than 75 machines with MagicINFO installed across its customers, three incidents, and its guess that firewalls explain why there were not more. We found no 2026 count of exposed servers, and none for the United Kingdom.
The May 2025 fix was not the last. Samsung's bulletin page and the NVD records list three further bulletins for MagicINFO 9 Server:
Further MagicINFO 9 Server bulletins after SVP-MAY-2025, from Samsung's page and NVD
- Bulletin
- SVP-JUL-2025
- What it lists
- Six CVEs, published 23 July 2025: path traversal, authentication bypass, unrestricted upload, XML entity handling, code injection and hard-coded credentials. Two are scored 9.8 by Samsung.
- Fixed in
- 21.1080.0
- Bulletin
- SVP-NOV-2025
- What it lists
- Three CVEs, published 2 February 2026: unauthenticated file upload leading to code execution (CVE-2026-25201, 8.8), hard-coded database credentials (CVE-2026-25202, 9.8) and HTML upload leading to stored XSS (CVE-2026-25200, 9.8).
- Fixed in
- 21.1090.1
- Bulletin
- SVP-DEC-2025
- What it lists
- One CVE, published 10 April 2026: incorrect default permissions allowing local privilege escalation (CVE-2026-25203, 7.8). NVD status when read: Awaiting Analysis.
- Fixed in
- 21.1091.1
| Bulletin | What it lists | Fixed in |
|---|---|---|
| SVP-JUL-2025 | Six CVEs, published 23 July 2025: path traversal, authentication bypass, unrestricted upload, XML entity handling, code injection and hard-coded credentials. Two are scored 9.8 by Samsung. | 21.1080.0 |
| SVP-NOV-2025 | Three CVEs, published 2 February 2026: unauthenticated file upload leading to code execution (CVE-2026-25201, 8.8), hard-coded database credentials (CVE-2026-25202, 9.8) and HTML upload leading to stored XSS (CVE-2026-25200, 9.8). | 21.1090.1 |
| SVP-DEC-2025 | One CVE, published 10 April 2026: incorrect default permissions allowing local privilege escalation (CVE-2026-25203, 7.8). NVD status when read: Awaiting Analysis. | 21.1091.1 |
A server that took the May 2025 fix and nothing since is behind three further fix releases and ten further CVE identifiers, four of them scored 9.8 by Samsung. None of the ten is in the KEV catalogue as read at 15:43 UTC on 5 October 2026; only CVE-2025-4632 and CVE-2024-7399 are. CVE-2024-7399 was added on 24 April 2026, 337 days after the other, with a due date of 8 May 2026. Huntress does not say which version its victim ran, so we cannot say whether any of the later flaws mattered here. That is a gap in the record, and it is why "patched in May 2025" is not the end of the question.
There is a second question, which is who can get the update. Samsung's download page for MagicINFO is titled "Display Solutions Download Centre for Partners". Tenable's disclosure timeline for its own MagicINFO advisory (TRA-2026-16, cited but not linked because the page carries proof of concept commands) records that on 2 February 2026 Samsung told it that new versions would only be available to partners, and that Tenable could no longer see one fixed version on the public site. That is Tenable's account of what Samsung said; we have not seen a Samsung statement on it. For an organisation whose signage was installed by an integrator, who holds the partner access is part of the patching process.
Two friendly names in one incident
The first is the product's own reputation. Samsung's product page says MagicINFO "provides the highest level of security in the digital signage industry" and notes ISO 27001 and ISO 27701 certification (the Ireland page; the UK address redirected to a general displays page when we read it on 5 October 2026). Samsung also publishes bulletins and CVE records for its flaws, which is what a vendor should do, and is why this briefing can count them: twelve distinct CVE identifiers for MagicINFO 9 Server across five bulletins since August 2024, by our count of Samsung's page. A management system certificate describes how an organisation runs its security processes within a stated scope. It is not a statement that any version of a product is free of flaws, and Samsung's page does not say what the scope covers. That reading is ours. Arctic Wolf made the practical point in May 2025: because these servers manage signage in corporate and public environments, a compromised one that is not segmented from internal networks could be a way to pivot deeper (via Help Net Security, secondary).
The second is AnyDesk. It is a legitimate product, which is what makes it useful to an intruder: the name is familiar to IT teams, and Huntress shows the actor setting an access password on the instance. The AnyDesk guidance we read does not cover this case. Its Abuse management page (updated 14 August 2025) is about scams in which a person is talked into granting access, and says users who break its terms are banned "upon identification". Its Security tips page (published 30 July 2025, updated 7 August 2025) describes controls the licence holder sets on its own clients: an access control list, exclusive unattended access, two-factor authentication and an on-premises option. Neither describes what a defender can do when someone else installs an instance on a server they have already compromised. That control sits on your side.
CISA, NSA and MS-ISAC said as much in their joint advisory on malicious use of remote monitoring and management (RMM) software (AA23-025A, revised 26 January 2023): use application controls, including allowlisting RMM programs. The earlier briefing on a signed MSP360 installer that installed ScreenConnect made the same point about a different tool: signed is not the same as approved.
What this means for UK signage and AV estates
Huntress names no sector and no country, so this section is about exposure, not victims. Samsung's UK business site lists Education, Retail, Corporate, Hospitality, Healthcare and Airport among the industries it sells displays into (menu read 5 October 2026). Shop floors, concourses, lobbies, waiting rooms and campuses are where such screens run. Our judgement, not a finding, is that the server behind them often belongs in practice to whoever bought the screens, which can be marketing, estates or facilities rather than IT. We found no figure for UK MagicINFO installations.
The NCSC has no page on signage servers that we could find, but its general guidance applies directly. Its blog on protecting management interfaces (22 March 2017) says to expose them to a dedicated management network where you can, and at the least to limit authorised inbound addresses. Its advisory of 27 August 2026 on internet-exposed systems, written about operational technology with a section for other organisations, asks for an accurate inventory of internet-facing systems, prompt vendor updates, and monitoring for unexpected configuration changes or outbound connections, and tells every organisation to register for its free Early Warning service. Its Connected Places principle on reducing exposure (reviewed 14 November 2024) says software should not run with administrator rights. MagicINFO's flaw wrote files with system authority, which is the opposite of least privilege. The guidance is general rather than signage-specific, so the gap is whether anyone applies it to a box nobody calls a server.
Cyber Essentials v3.3 (April 2026) requires software on in-scope devices, servers included, to be updated within 14 days of release where the fix is for a vulnerability the vendor calls critical or high, or one scored 7 or above on CVSS v3. If Help Net Security's date of 7 May 2025 for the 21.1052 hotfix is right, that window closed on 21 May 2025, which is 468 days before 1 September 2026. Whether a given signage server sits inside a certified boundary is a scoping decision, and an intruder does not respect scoping. The Early Warning service takes your public IP addresses and domains and sends alerts about malware and vulnerabilities affecting them. The NCSC says it should complement, not replace, your other controls.
What to do, in the order worth doing it
Take this with you
Eight checks for signage and AV servers
- Find every signage and AV management server, including those bought and run by marketing, estates, facilities or an integrator. Record the owner, the version, where it sits on the network and whether it can be reached from outside.
- Compare each MagicINFO 9 Server version with the fixed versions on the record: 21.1052 for CVE-2025-4632, then 21.1080.0, 21.1090.1 and 21.1091.1. Find out how you obtain updates: Samsung's download centre is labelled for partners, so ask whoever supplied the system, in writing.
- Take the server off the internet. If it must be reachable, put it on a management network or behind a jump host and allow only known addresses, as the NCSC advises for management interfaces. Check from outside rather than trusting the firewall diagram, and register for the NCSC's free Early Warning service.
- Patch to a current fixed version, or isolate the server if you cannot. If it was reachable and unpatched at any point since May 2025, treat it as possibly compromised: look for unexpected local accounts, new services, remote access tools and a changed Defender state before trusting the patch, and rebuild rather than clean if anything turns up.
- Allow-list the remote access tools you approve, and alert on any other being downloaded or installed, and on repeated attempts. In this incident Defender flagged the first two attempts.
- Alert on compilers and build tools running on servers and endpoints that have no reason to have them, such as .NET compiler utilities and C compilers started by an unsigned parent. Baseline developer machines first so the alert stays quiet where it should.
- Alert on new local administrator accounts and on endpoint protection being switched off. If you use Defender, check that tamper protection is on for signage servers specifically; Microsoft says it helps protect important security settings from being disabled.
- After any alert on one of these servers, verify that the way in is closed, not just that the alert has stopped. Huntress's customer was reported again eight days after being told how to remediate.
Items 1, 4, 6 and 8 are our judgement. The others follow the sources named above: Huntress and Samsung's records for 2, the NCSC for 3, CISA AA23-025A and Huntress for 5, and Microsoft's documentation for 7.
Method and interest
Huntress sells managed detection and response, and its write-up closes with an invitation to book a demo. The account is one incident seen through its own telemetry, and the lessons it draws, patch, watch for remote tools, watch for compilers, are ones its service is built to notice. That is not a reason to doubt the observations, which carry process names others can check, but the reader should know whose telemetry it is. Samsung markets MagicINFO on its security and also publishes its flaws; both facts are in the record. The Hacker News's bulletin quotes Huntress's key takeaways, inserts the CVE number in square brackets, and calls the attack "novel", where Huntress's wording is "unique". Nothing here is an accusation. The method is to separate what the vendors say, what the record says and what we infer.
The question that exposes the gap
Every step before the miner left a trace, and the earliest trace Huntress describes in detail was a remote access tool being downloaded to a server that many organisations do not think of as a server. If the server behind your screens began downloading a remote access tool tonight, who would be told, and by when?
Key facts
Sources
- PrimaryThe Not So Silent Miner: Threat Actor Compiles Cryptominer on the Endpoint, 24 September 2026, read in full including the indicator table (whose password is deliberately not reproduced); the source of the incident chain, the three AnyDesk attempts, the eight days and the novelty wordingHuntressaccessed 2026-10-05
- PrimarySecurity Updates for Smart TVs, Smart Monitors and Audio Products, the bulletin page listing SVP-MAY-2025 (CVE-2025-4632) and the other MagicINFO 9 Server bulletins; used for the weakness text, the patch description and the bulletin list, which carries months but no daysSamsung Electronicsaccessed 2026-10-05
- PrimaryCVE.org record for CVE-2025-4632: published 13 May 2025, CNA Samsung, affected before 21.1052, CWE-22, CVSS 3.1 base score 9.8, CISA-ADP containerCVE Program (CVE Services API)accessed 2026-10-05
- PrimaryNVD record for CVE-2025-4632 read through the API at 15:43 UTC on 5 October 2026: status Analyzed, both CVSS scores, the CISA-ADP SSVC entry (source 134c704f-9b21-4f2e-91b3-4a467353bcc0) and the KEV fieldsNIST National Vulnerability Databaseaccessed 2026-10-05
- PrimaryNVD record for CVE-2024-7399, the earlier flaw: published 12 August 2024, affected before 21.1050, Samsung 8.8 and NVD 9.8, KEV fields; the other later MagicINFO CVEs named in the article (CVE-2025-54438, 54439, 54445, 54451, 54452, 54454, CVE-2026-25200, 25201, 25202, 25203) were read through the same APINIST National Vulnerability Databaseaccessed 2026-10-05
- PrimaryKnown Exploited Vulnerabilities catalogue JSON, catalogue version 2026.10.04 released 4 October 2026 at 18:52 UTC, read 5 October 2026 at 15:43 UTC: entries for CVE-2025-4632 and CVE-2024-7399, and absence of the ten later MagicINFO CVEsCISAaccessed 2026-10-05
- PrimaryRapid Response: Samsung MagicINFO 9 Server Flaw, 7 May 2025; used for the proof of concept date, the finding that 21.1050.0 was still vulnerable and Huntress's observation of exploitationHuntressaccessed 2026-10-05
- PrimaryPost-Exploitation Activities Observed from the Samsung MagicINFO 9 Server Flaw, 9 May 2025; used for the first-observed date of 4 May 2025, the count of more than 75 machines and three incidents, and the firewall observationHuntressaccessed 2026-10-05
- PrimaryFollow-Up: Samsung MagicINFO 9 Remains Vulnerable to Ongoing Exploitation, 8 May 2025; used for its observation of exploitation at the start of May 2025 and its advice not to expose the serverArctic Wolfaccessed 2026-10-05
- PrimaryMirai Now Exploits Samsung MagicINFO CMS (CVE-2024-7399), 5 May 2025; used for the report of botnet-style exploit attemptsSANS Internet Storm Centeraccessed 2026-10-05
- PrimaryMay 30 Advisory: Samsung MagicInfo9 Path Traversal Vulnerability Added to CISA KEV, used for its count of 1,101 exposed servers and the version table for 116 of themCensysaccessed 2026-10-05
- PrimaryMagicINFO 9 product page (Ireland), read 5 October 2026; used for the Server, Author and Player description and the security and ISO certification claimsSamsung Electronicsaccessed 2026-10-05
- PrimarySamsung Display Solutions Download Centre for Partners, read 5 October 2026; used for the page titleSamsung Electronicsaccessed 2026-10-05
- PrimarySamsung UK business site, read 5 October 2026; used for the industries listed in its menuSamsung Electronicsaccessed 2026-10-05
- PrimaryAnyDesk Help Center, Abuse management, updated 14 August 2025; used for what its abuse guidance coversAnyDesk Softwareaccessed 2026-10-05
- PrimaryAnyDesk Help Center, Security tips and offboarding, published 30 July 2025 and updated 7 August 2025; used for the client security controls it listsAnyDesk Softwareaccessed 2026-10-05
- PrimaryProtecting Against Malicious Use of Remote Monitoring and Management Software, AA23-025A, last revised 26 January 2023; used for the application control and allowlisting recommendationCISA, NSA and MS-ISACaccessed 2026-10-05
- PrimaryProtect your management interfaces, 22 March 2017; used for management network, jump server and logging adviceNCSCaccessed 2026-10-05
- PrimaryDisruptive cyber activity highlights risk from internet-exposed systems and edge devices, 27 August 2026; used for the inventory, updates, monitoring and Early Warning adviceNCSCaccessed 2026-10-05
- PrimaryConnected Places Cyber Security Principles, principle 7, reviewed 14 November 2024; used for the administrator rights point. The NCSC has no signage-specific page that we foundNCSCaccessed 2026-10-05
- PrimaryCyber Essentials: Requirements for IT Infrastructure v3.3, April 2026; used for the 14-day update rule and the allow listing optionNCSCaccessed 2026-10-05
- PrimaryEarly Warning service page, read 5 October 2026; used for eligibility, cost and what it alerts onNCSCaccessed 2026-10-05
- PrimaryTamper protection overview, Microsoft Learn, read 5 October 2026; used for what tamper protection doesMicrosoftaccessed 2026-10-05
- Reported bySamsung patches MagicINFO 9 Server vulnerability exploited by attackers, 15 May 2025; secondary reporting used only for the 7 May 2025 release date of the 21.1052 hotfix and the mismatch in its release notesHelp Net Securityaccessed 2026-10-05
- Reported byExploited: Vulnerability in software for managing Samsung digital displays (CVE-2024-7399), 6 May 2025 with updates; secondary reporting used for Arctic Wolf's statements on the Shodan count of nearly 5,000 and on segmentationHelp Net Securityaccessed 2026-10-05
- Reported byThreatsDay bulletin, 1 October 2026; secondary pointer to the Huntress write-up, which quotes Huntress's key takeaways and uses the word novelThe Hacker Newsaccessed 2026-10-05
- Reported bySamsung Patches CVE-2025-4632 Used to Deploy Mirai Botnet via MagicINFO 9 Exploit, 14 May 2025; secondary reporting used for Huntress's confirmation that 21.1052.0 mitigates the issue and the upgrade path from version 8The Hacker Newsaccessed 2026-10-05


