Vulnerabilità ed exploit · Cryptojacking

Attaccanti Sfruttano Bug RCE per Compromettere Cloud

Google segnala che attori malintenzionati sfruttano bug RCE di terze parti per ottenere accesso a risorse cloud e installare cryptominer entro 48 ore dalla divulgazione.

4 fonti · 13 mar

CVE-2025-24893

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 9.8 CRITICAL: xWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. EPSS 100% (100º percentile).

Data di correzione federale CISA 20 nov · data superata

CVE-2025-55182

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 10 CRITICAL: a pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0… Impiego noto in campagne ransomware. EPSS 100% (100º percentile).

Data di correzione federale CISA 12 dic · data superata

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-23

Every edition of this story: Attaccanti Sfruttano Bug RCE per Compromettere Cloud

Altro da oggi