CVE-2023-32315
Known exploited · CISA KEV
CVSS 8.6 HIGH: openfire is an XMPP server licensed under the Open Source Apache License. EPSS 100% (100th percentile).
CISA federal remediation date Sep 14 · date passed
Vulnerabilities & Exploits · Web App Attack
The break is no longer a single product flaw. StrikeShark now looks like a broad access campaign that reuses public web-app exploits to get in, then hands the foothold to SharkLoader so Cobalt Strike can stay on the network and move beyond the first compromised host.
Kaspersky ties the activity to a custom loader that deploys Cobalt Strike Beacon and to opportunistic abuse of many internet-facing vulnerabilities across Microsoft Exchange, Openfire, GeoServer, Fortinet FortiOS, F5 BIG-IP, Cisco IOS XE, Zimbra, Apache Shiro, and Hikvision. The set includes older flaws such as CVE-2021-26855, CVE-2023-32315, and CVE-2024-36401, and the campaign uses publicly available proof-of-concept exploits rather than bespoke zero-days.
The practical change is the blast radius. Any exposed admin or app service can become the same intrusion path, so patching one named CVE does not remove the campaign pattern once a reachable service is left open.
3 sources · Jun 27
Known exploited · CISA KEV
CVSS 8.6 HIGH: openfire is an XMPP server licensed under the Open Source Apache License. EPSS 100% (100th percentile).
CISA federal remediation date Sep 14 · date passed
Known exploited · CISA KEV
CVSS 9.1 CRITICAL: microsoft Exchange Server Remote Code Execution Vulnerability Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date May 3 · date passed
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: geoServer is an open source server that allows users to share and edit geospatial data. EPSS 100% (100th percentile).
CISA federal remediation date Aug 5 · date passed
The Hacker News
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
Kaspersky details StrikeShark, a likely Chinese-speaking campaign using SharkLoader, public CVE exploits, and droppers to deploy Cobalt Strike.
originalHelp Net Security
Mystery hackers use novel SharkLoader dropper against governments, software devs - Help Net Security
A global attack operation researchers dubbed StrikeShark relies on attackers' delivering the novel SharkLoader dropper.
originalKaspersky Securelist
StrikeShark: a new campaign involving a custom SharkLoader and Cobalt Strike Beacon
Kaspersky researchers analyze a new global campaign dubbed StrikeShark that delivers Cobalt Strike Beacon via custom SharkLoader malware.
originalPart of the PlainSec briefing for 2026-06-26
Every edition of this story: Public Exploits Now Feed a Custom Cobalt Strike Loader