CVE-2025-24893 is a vulnerability tracked across 11 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed October 29, 2025; most recent activity March 9, 2026.
The RondoDox botnet is exploiting the unpatched XWiki remote code execution vulnerability CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, many servers remain vulnerable,…
Hackers are increasingly targeting newly disclosed vulnerabilities in third-party software to access cloud environments, with the time frame for such attacks decreasing significantly. Google reports a notable decline in…
The RondoDox botnet has been exploiting the React2Shell flaw (CVE-2025-55182) to infect vulnerable .js servers with malware and cryptominers. First documented by Fortinet in July 2025, the botnet targets multiple n-day…
The RondoDox botnet is exploiting the unpatched XWiki remote code execution (RCE) flaw CVE-2025-24893, which has a CVSS score of 9.8. Despite patches released in February 2025, the botnet continues to infect servers,…
A vulnerability in XWiki software is being actively exploited by various threat actors, including botnets and coin-miners. VulnCheck reported on November 14, 2025, that these actors are using a range of tools to target…
Hackers are actively exploiting a critical vulnerability in XWiki, tracked as CVE-2025-24893, to hire servers for botnet operations. This exploitation has escalated from isolated incidents to widespread attacks…
A vulnerability in XWiki software is being actively exploited by various threat actors, including botnets and coin-miners. VulnCheck reported on November 14, 2025, that these actors are utilizing a range of tools, from…
Hackers are actively exploiting a critical vulnerability in XWiki, tracked as CVE-2025-24893, to hire servers for botnet operations. This exploitation has transitioned from isolated incidents to widespread attacks…
VulnCheck has launched Canary Intelligence, a tool that provides verified evidence of active exploitation from live, intentionally vulnerable systems. This product aims to assist security teams in confirming which…
Hackers have exploited a critical vulnerability in XWiki, identified as CVE-2025-24893, to hijack corporate servers for cryptocurrency mining. Active attacks have been confirmed by VulnCheck researchers, with exploits…