Thursday, March 19, 2026
Law And Order News
  • Home
  • Law and Legal
  • Military and Defense
  • International Conflict
  • Crimes
  • Constitution
  • Cyber Crimes
No Result
View All Result
  • Home
  • Law and Legal
  • Military and Defense
  • International Conflict
  • Crimes
  • Constitution
  • Cyber Crimes
No Result
View All Result
Law And Order News
No Result
View All Result
Home Cyber Crimes

Hackers exploiting bug in popular Trimble Cityworks tool used by local gov’ts

Hackers exploiting bug in popular Trimble Cityworks tool used by local gov’ts



Federal civilian businesses have been ordered to patch a vulnerability impacting Trimble Cityworks — a preferred instrument utilized by many governments to handle public infrastructure. 

The Cybersecurity and Infrastructure Safety Company (CISA) launched a warning alongside Trimble on Thursday about CVE-2025-0994 after confirming it’s being exploited by hackers. Federal civilian businesses have till February 28 to patch the bug. 

Trimble Cityworks is an asset administration system utilized by many native and federal authorities businesses to handle infrastructure belongings for airports, utilities, municipalities and counties.

CISA stated the vulnerability permits malicious actors to “probably conduct distant code execution (RCE) in opposition to a buyer’s Microsoft Web Data Providers (IIS) internet server.”

In a letter to prospects, the corporate stated the discover adopted “investigations of studies of unauthorized makes an attempt to realize entry to particular prospects’ Cityworks deployments.” 

A patch was launched on January 29 and the corporate listed a number of different actions prospects have to take to cut back the publicity of information. Clients ought to restrict permissions linked to Cityworks and the system “shouldn’t be run with native or area degree administrative privileges on any website.”

The corporate additionally offered indicators of compromise alongside the letter. CISA stated Trimble reported the vulnerability to them and Symantec’s Risk Hunter crew contributed to the advisory they launched in regards to the bug. 

The bug carries a CVSS v4 severity rating of 8.4 out of 10. All Cityworks variations prior to fifteen.8.9 are impacted by the vulnerability. 

Trimble didn’t reply to requests for remark about what actions the hackers took after exploiting CVE-2025-0994 or the place the hackers could also be based mostly. 

Trimble is a big Colorado-based expertise supplier, with greater than 11,000 staff throughout about 40 nations. The corporate reported a income of $875.8 million within the final fiscal quarter. 

The Cityworks instrument permits prospects to handle important infrastructure belongings from one platform and set up inspections, work orders, permits, operations and extra.

A couple of yr in the past, agricultural tools producer AGCO acquired an 85% stake in Trimble’s agribusiness for $2 billion in money. AGCO suffered a ransomware assault in 2022 that impacted its enterprise operations.

Get extra insights with the

Recorded Future

Intelligence Cloud.

Study extra.



Source link

Tags: bugCityworksexploitinggovtsHackerslocalpopularToolTrimble
Previous Post

Government of India Act 1935

Next Post

The Best AI Time Tracking Tools for Lawyers

Related Posts

Bank software vendor Marquis says more than 670,000 impacted by August breach
Cyber Crimes

Bank software vendor Marquis says more than 670,000 impacted by August breach

March 18, 2026
CISO DEMO: Cybersecurity Vendors Pitch Chief Information Security Officers On YouTube
Cyber Crimes

CISO DEMO: Cybersecurity Vendors Pitch Chief Information Security Officers On YouTube

March 17, 2026
Ransomware incident responder gave info to BlackCat cybercriminals during negotiations, DOJ alleges
Cyber Crimes

Ransomware incident responder gave info to BlackCat cybercriminals during negotiations, DOJ alleges

March 15, 2026
How AI And LLMs Are Redefining Cloud Security and Cyber Defense
Cyber Crimes

How AI And LLMs Are Redefining Cloud Security and Cyber Defense

March 14, 2026
Stryker tells SEC that timeline for recovery from cyberattack unknown
Cyber Crimes

Stryker tells SEC that timeline for recovery from cyberattack unknown

March 12, 2026
The Hacking Games Is Recruiting GenZ Talent To Create A Generation Of Cyber Fighters
Cyber Crimes

The Hacking Games Is Recruiting GenZ Talent To Create A Generation Of Cyber Fighters

March 11, 2026
Next Post
The Best AI Time Tracking Tools for Lawyers

The Best AI Time Tracking Tools for Lawyers

Reagan Judge Still Respects The Rule Of Law – See Also – Above the Law

Reagan Judge Still Respects The Rule Of Law - See Also - Above the Law

  • Trending
  • Comments
  • Latest
Praxis des Internationalen Privat- und Verfahrensrechts (IPRax) 6/2024: Abstracts

Praxis des Internationalen Privat- und Verfahrensrechts (IPRax) 6/2024: Abstracts

October 31, 2024
Announcements: CfP Ljubljana Sanctions Conference; Secondary Sanctions and the International Legal Order Discussion; The Law of International Society Lecture; CfS Cyber Law Toolkit; ICCT Live Webinar

Announcements: CfP Ljubljana Sanctions Conference; Secondary Sanctions and the International Legal Order Discussion; The Law of International Society Lecture; CfS Cyber Law Toolkit; ICCT Live Webinar

September 29, 2024
Mitigating Impacts to Your Business in a Changing Trade Environment | Customs & International Trade Law Blog

Mitigating Impacts to Your Business in a Changing Trade Environment | Customs & International Trade Law Blog

April 28, 2025
Lean Into Our Community as Our Fight Continues | ACS

Lean Into Our Community as Our Fight Continues | ACS

August 24, 2025
Two Weeks in Review, 21 April – 4 May 2025

Two Weeks in Review, 21 April – 4 May 2025

May 4, 2025
June 2025 – Conflict of Laws

June 2025 – Conflict of Laws

July 5, 2025
From Silk Road to Valid8: Former US Marshals Asset Forfeiture Expert Joins as VP of Public Sector – Legal Reader

From Silk Road to Valid8: Former US Marshals Asset Forfeiture Expert Joins as VP of Public Sector – Legal Reader

March 18, 2026
Bank software vendor Marquis says more than 670,000 impacted by August breach

Bank software vendor Marquis says more than 670,000 impacted by August breach

March 18, 2026
Lokesh Machines Clinches ₹9.5 Cr ASMI SMG Deal With Sashastra Seema Bal, Boosting Indigenous Border Defence

Lokesh Machines Clinches ₹9.5 Cr ASMI SMG Deal With Sashastra Seema Bal, Boosting Indigenous Border Defence

March 18, 2026
Does the Supreme Court have a strong “unitary” judicial power?

Does the Supreme Court have a strong “unitary” judicial power?

March 19, 2026
Caught between Locus Standi and CFSP Exceptionalism

Caught between Locus Standi and CFSP Exceptionalism

March 19, 2026
Armed men rob woman at gunpoint as she drops off daughter at daycare on Near North Side – CWB Chicago

Armed men rob woman at gunpoint as she drops off daughter at daycare on Near North Side – CWB Chicago

March 18, 2026
Law And Order News

Stay informed with Law and Order News, your go-to source for the latest updates and in-depth analysis on legal, law enforcement, and criminal justice topics. Join our engaged community of professionals and enthusiasts.

  • About Founder
  • About Us
  • Advertise With Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2024 Law And Order News.
Law And Order News is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Law and Legal
  • Military and Defense
  • International Conflict
  • Crimes
  • Constitution
  • Cyber Crimes

Copyright © 2024 Law And Order News.
Law And Order News is not responsible for the content of external sites.