What happened
CISA added CVE-2025-67038, a code injection vulnerability scoring 9.8 out of 10 on the CVSS scale, to its Known Exploited Vulnerabilities catalog after confirming active attacks against Lantronix EDS5000 Series serial-to-Ethernet devices. Federal civilian agencies have been directed to apply available patches no later than June 26, 2026. Separately, two members of the Scattered Spider cybercrime group entered guilty pleas on the opening day of what had been scheduled as a six-week criminal trial in the United Kingdom. The pair were charged in connection with a major August 2024 attack that severely disrupted Transport for London's public transit operations.
Why it matters for your business
Lantronix EDS5000 devices are widely deployed in industrial and operational technology environments to bridge legacy serial hardware to modern IP networks, meaning the attack surface extends well beyond traditional IT infrastructure. A successful exploit of CVE-2025-67038 could give an attacker arbitrary code execution on network-connected equipment, potentially pivoting deeper into critical systems. Organizations using these devices should treat patching as urgent regardless of whether they fall under CISA's federal mandate. The Scattered Spider guilty pleas, meanwhile, reinforce that social-engineering-driven threat groups remain highly effective against large enterprises and should factor into tabletop exercises and identity-security reviews.
What to watch next
Security teams should monitor Lantronix's advisory channel for additional patch guidance and verify that EDS5000 units are not directly exposed to the internet. In the Scattered Spider case, sentencing dates and any cooperation agreements with prosecutors could yield new intelligence about the group's tactics, techniques, and remaining active members. Broader law enforcement momentum against English-speaking cybercrime crews may accelerate indictments on both sides of the Atlantic in the months ahead.
