Attaccanti Sfruttano Bug RCE per Compromettere Cloud
Google segnala che attori malintenzionati sfruttano bug RCE di terze parti per ottenere accesso a risorse cloud e installare cryptominer entro 48 ore dalla divulgazione.
CVSS 9.8 CRITICAL: xWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. EPSS 100% (100º percentile).
Data di correzione federale CISA 20 nov · data superata
Hackers are increasingly exploiting newly disclosed vulnerabilities in third-party software to gain initial access to cloud environments, with the window for attacks shrinking from weeks to just days.