• News/
  • https://www.theregister.com/2025/05/22/chinese_crew_us_city_utilities/

Chinese snoops tried to break into US city utilities, says Talos

The Register
·
Jessica Lyons
·
Published May 22, 2025
·
Updated

A suspected Chinese crew has been exploiting a now-patched remote code execution (RCE) flaw in Trimble Cityworks to break into US local government networks and target utility management systems, according to Cisco's Talos threat intelligence group. Cityworks is an asset and work management platform that integrates closely with Geographic Information Systems (GIS), and is primarily used by local governments, utilities, airports, and public works departments. Trimble disclosed and patched a deserialization vulnerability in Cityworks, tracked as CVE-2025-0994 and rated 8.6 under CVSS v4, in early February. At the time, the biz warned that an authenticated user could exploit it to achieve RCE on a customer's Microsoft Internet Information Services (IIS) server. Less than a week later, the US Cybersecurity and Infrastructure Security Agency (CISA) said the flaw was under active exploitation - apparently there are still enough IIS instances in the wild to make it worth exploiting, even though Microsoft hasn't released a major new version since 2018. But according to Talos, attackers found and abused the bug even before the vendor issued a patch. These intrusions began in January with a group Talos tracks, UAT-6382, breaking into US local governing bodies' networks to conduct reconnaissance, snoop around for files of interest, and deploy webshells and custom malware for long-term access. "Upon gaining access, UAT-6382 expressed a clear interest in pivoting to systems related to util...

Read full article

Affected Software

3 affected components
Trimble Cityworks
Microsoft Internet Information Services (IIS)
Trimble Cityworks
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203