Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Storm-0501, a financially motivated cybercrime group, has been active since 2021 and is known for conducting ransomware operations using various Ransomware-as-a-Service (RaaS) variants. They have recently expanded their tactics to target cloud environments, specifically Azure, by hijacking high-priv...
A multi-stage cyber attack targeted IIS servers, beginning with enumeration commands and escalating to credential extraction using Mimikatz. The attackers uploaded a steganographic webshell and executed a defense-impairment script (i.bat) that disabled logging and security services. Initial forensic...
Rapid7 disclosed an access control bypass vulnerability in Adobe ColdFusion, identified as CVE-2023-29298, which affects versions 2018u16, 2021u6, and 2023. The vulnerability allows attackers to access restricted administration endpoints by manipulating URL requests. This flaw undermines the securit...