A severe remote code execution vulnerability (CVE-2024-36401) in OSGeo GeoServer GeoTools is being exploited to deploy cryptocurrency miners, botnet malware, and the SideWalk backdoor. Targeted attacks have been observed against IT, government, and telecom sectors across multiple regions. The flaw, added to CISA's KEV catalog, is leveraged by sophisticated actors, including APT41, to compromise and control affected servers.
https://thehackernews.com/2024/09/geoserver-vulnerability-targeted-by.html
crack-vault.de
#crackvault