A suspected Chinese crew has been exploiting a now-patched remote code execution (RCE) flaw in Trimble Cityworks to break into US local government networks and target utility management systems, according to Cisco's Talos threat intelligence group. Cityworks is an asset and work management platform that integrates closely with Geographic Information Systems (GIS), and is primarily used by local governments, utilities, airports, and public works departments. Trimble disclosed and patched a deserialization vulnerability in Cityworks, tracked as CVE-2025-0994 and rated 8.6 under CVSS v4, in early February. At the time, the biz warned that an authenticated user could exploit it to achieve RCE on a customer's Microsoft Internet Information Services (IIS) server. Less than a week later, the US Cybersecurity and Infrastructure Security Agency (CISA) said the flaw was under active exploitation - apparently there are still enough IIS instances in the wild to make it worth exploiting, even though Microsoft hasn't released a major new version since 2018. But according to Talos, attackers found and abused the bug even before the vendor issued a patch. These intrusions began in January with a group Talos tracks, UAT-6382, breaking into US local governing bodies' networks to conduct reconnaissance, snoop around for files of interest, and deploy webshells and custom malware for long-term access. "Upon gaining access, UAT-6382 expressed a clear interest in pivoting to systems related to util...
Chinese snoops tried to break into US city utilities, says Talos
The Register
·Jessica Lyons
·Published May 22, 2025
·Updated
Affected Software
3 affected components
Trimble Cityworks
Microsoft Internet Information Services (IIS)
Trimble Cityworks