While investigating a malicious crypto-mining case, I discovered that attackers implanted the payload exploiting a recently patched RCE vulnerability (CVE-2022-29464) affecting multiple WSO2 products, including API Manager. The vulnerability was discovered by Orange Tsai and responsibly disclosed to WSO2.
Intelligence View
WSO2 RCE exploited in the wild, (Tue, Apr 26th)
While investigating a malicious crypto-mining case, I discovered that attackers implanted the payload exploiting a recently patched RCE vulnerability…
Cyber Threat Intelligence & Forensik
Compliance, SLA & Vendor Adherence
Hersteller-Sicherheitsmeldungen & Patch-Status
Wird aktiv im Feld ausgenutzt! Kein verifiziertes Hersteller-Update gemeldet. Sofortige Quarantäne oder WAF-Virtual-Patching zwingend.
-
Web Referencewww.openwall.com
-
Upstream-Referenz (Code-Hosting, kein Advisory)github.com
-
Web Referencesecurity.docs.wso2.com