CVE-2022-22965
published 2022-04-01CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires…
PriorityP198critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-04-25
Exploited in the wild
EPSS
99.68%
99.9th percentile
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Affected
108 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cx_cloud_agent | < 2.1.0 | 2.1.0 |
| debian | libspring-java | — | — |
| gxsoftware | xperiencentral | <= 10.36.0 | — |
| oracle | commerce_platform | — | — |
| oracle | communications_cloud_native_core_automated_test_suite | — | — |
| oracle | communications_cloud_native_core_automated_test_suite | — | — |
| oracle | communications_cloud_native_core_binding_support_function | — | — |
| oracle | communications_cloud_native_core_console | — | — |
| oracle | communications_cloud_native_core_console | — | — |
| oracle | communications_cloud_native_core_network_exposure_function | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_repository_function | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | communications_cloud_native_core_unified_data_repository | — | — |
| oracle | communications_cloud_native_core_unified_data_repository | — | — |
| oracle | communications_policy_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
Snort SIDs: 30790-30793, 59388, and 59416
- →Exploitation is limited to applications packaged as WAR files served by Apache Tomcat, GlassFish, or Payara; scope detection to those web container environments ↗
- →Spring Boot executable JAR deployments are NOT vulnerable; focus detection resources on WAR-deployed Spring applications ↗
- →The vulnerability is triggered via data binding with particular parameter types in spring-webmvc or spring-webflux; inspect HTTP request parameters for class loader manipulation patterns (e.g., class.module.classLoader references) ↗
- →The vulnerability has been linked to Mirai botnet activity in addition to coinminer deployment; monitor for botnet C2 traffic from compromised Spring/Tomcat hosts ↗
- ·Only applications running on JDK 9 or higher are vulnerable; JDK 8 and below are not affected ↗
- ·The underlying bug is in spring-beans but is only currently triggerable via spring-webmvc or spring-webflux; applications not using these libraries are not exploitable by known methods ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_cisco9.8CRITICAL
vendor_debian9.8LOW
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Spring Framework vulnerability
vendor_ubuntu·2024-12-17
CVE-2022-22965 Spring Framework vulnerability
Title: Spring Framework vulnerability
Summary: Spring Framework could be made to run programs or expose sensitive
information if it received specially crafted network traffic.
It was discovered that the Spring Framework incorrectly handled web
requests via data binding. An attacker could possibly use this issue to
achieve remote code execution and obtain sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2010-1622 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) — CVE-2022-22965
vendor_oracle·2023-04-15·CVSS 9.8
CVE-2022-22965 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) — CVE-2022-22965
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) vulnerability
CVE: CVE-2022-22965
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Spring Framework) — CVE-2022-22965
vendor_oracle·2023-01-15·CVSS 9.8
CVE-2022-22965 [CRITICAL] Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Spring Framework) — CVE-2022-22965
Oracle Oracle Commerce Risk Matrix: Content Acquisition System (Spring Framework) vulnerability
CVE: CVE-2022-22965
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
CISA ICS
Hitachi Energy Lumada Asset Performance Management Prognostic Model Executor Service
cisa_ics·2022-10-13·CVSS 6.5
[MEDIUM] Hitachi Energy Lumada Asset Performance Management Prognostic Model Executor Service
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi Energy Lumada Asset Performance Management Prognostic Model Executor Service
Last RevisedOctober 13, 2022
Alert CodeICSA-22-286-05
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.5
- ATTENTION: Exploitable remotely/public exploits are available
- Vendor: Hitachi Energy
- Equipment: Lumada Asset Performance Manager (APM)
- Vulnerabilities: Allocation of Resources Without Limits or Throttling, Code injection
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could crash the Prognostic Model Executor and could allow remote code execution.
## 3. TECHNICAL DETA
Oracle
Oracle Oracle Commerce Risk Matrix: Endeca Integration (Spring Framework) — CVE-2022-22965
vendor_oracle·2022-07-15·CVSS 9.8
CVE-2022-22965 [CRITICAL] Oracle Oracle Commerce Risk Matrix: Endeca Integration (Spring Framework) — CVE-2022-22965
Oracle Oracle Commerce Risk Matrix: Endeca Integration (Spring Framework) vulnerability
CVE: CVE-2022-22965
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Automation Test Suite (Spring Framework) — CVE-2022-22965
vendor_oracle·2022-04-15·CVSS 9.8
CVE-2022-22965 [CRITICAL] Oracle Oracle Communications Risk Matrix: Automation Test Suite (Spring Framework) — CVE-2022-22965
Oracle Oracle Communications Risk Matrix: Automation Test Suite (Spring Framework) vulnerability
CVE: CVE-2022-22965
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
CISA
Spring Framework JDK 9+ Remote Code Execution Vulnerability
cisa·2022-04-04·CVSS 9.8
CVE-2022-22965 [CRITICAL] CWE-94 Spring Framework JDK 9+ Remote Code Execution Vulnerability
Vulnerability: Spring Framework JDK 9+ Remote Code Execution Vulnerability
Affected: VMware Spring Framework
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-22965
Remediation Due Date: 2022-04-25
VMware
VMware Response to Spring Framework Remote Code Execution Vulnerability (CVE-2022-22965)
vendor_vmware·2022-04-02·CVSS 9.8
CVE-2022-22965 [CRITICAL] VMware Response to Spring Framework Remote Code Execution Vulnerability (CVE-2022-22965)
VMSA-2022-0010: VMware Response to Spring Framework Remote Code Execution Vulnerability (CVE-2022-22965)
Description Multiple products impacted by remote code execution vulnerability (CVE-2022-22965).
CVEs: CVE-2022-22965
Affected products: VMware Tanzu
Cisco
Vulnerability in Spring Framework Affecting Cisco Products: March 2022
vendor_cisco·2022-04-01·CVSS 9.8
CVE-2022-22965 [CRITICAL] CWE-120 Vulnerability in Spring Framework Affecting Cisco Products: March 2022
Vulnerability in Spring Framework Affecting Cisco Products: March 2022
On March 31, 2022, the following critical vulnerability in the Spring Framework affecting Spring MVC and Spring WebFlux applications running on JDK 9+ was released:
CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+
For a description of this vulnerability, see VMware Spring Framework Security Vulnerability Report.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67
Palo Alto
Informational: Impact of Spring Vulnerabilities CVE-2022-22963 and CVE-2022-22965
vendor_paloalto·2022-03-31·CVSS 9.8
CVE-2022-22963 [CRITICAL] CWE-497 Informational: Impact of Spring Vulnerabilities CVE-2022-22963 and CVE-2022-22965
Informational: Impact of Spring Vulnerabilities CVE-2022-22963 and CVE-2022-22965
The Palo Alto Networks Product Security Assurance team has completed its evaluation of the Spring Cloud Function vulnerability CVE-2022-22963 and Spring Core vulnerability CVE-2022-22965 for all products and services. All Palo Alto Networks cloud services with possible impact have been mitigated and remediated.
The following products and services are not impacted by these Spring vulnerabilities: AutoFocus, Bridgecrew, Cortex Data Lake, Cortex XDR agent, Cortex Xpanse, Cortex XSOAR, Enterprise Data Loss Prevention, Exact Data Matching (EDM) CLI, Expanse, Expedition Migration Tool, GlobalProtect app, IoT Security, Okyo Garde, Palo Alto Networks App for Splunk, PAN-OS hardware and virtual firewalls and Panoram
Red Hat
spring-framework: RCE via Data Binding on JDK 9+
vendor_redhat·2022-03-30·CVSS 9.8
CVE-2022-22965 [CRITICAL] CWE-94 spring-framework: RCE via Data Binding on JDK 9+
spring-framework: RCE via Data Binding on JDK 9+
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
A flaw was found in Spring Framework, specifically within two modules called Spring MVC and Spring WebFlux, (transitively affected from Spring Beans), using parameter data binding. This flaw allows an attacker to pass specially-constructed malicious requests to certain parameters and possibly gain access to normally
Debian
CVE-2022-22965: libspring-java - A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable t...
vendor_debian·2022·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965: libspring-java - A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable t...
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Cisco
Vulnerability in Spring Framework Affecting Cisco Products: March 2022
vendor_cisco·CVSS 3.0
CVE-2022-22965 Vulnerability in Spring Framework Affecting Cisco Products: March 2022
CVE-2022-22965: Vulnerability in Spring Framework Affecting Cisco Products: March 2022
On March 31, 2022, the following critical vulnerability in the Spring Framework affecting Spring MVC and Spring WebFlux applications running on JDK 9+ was released: CVE-2022-22965: Spring Framework RCE via Data Binding on JDK 9+ For a description of this vulnerability, see VMware Spring Framework Security Vulnerability Report . This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67
CVSS: 3.0
CWE: CWE-120, CWE-120
Bug IDs: CSCvv65984, CSCwa79849, CSCwb43327, CSCvv65984, CSCwa79849
GHSA
GHSA-mw64-5p9w-rfgc: POST requests to /web/mvc in GX Software XperienCentral version 10
ghsa_unreviewed·2023-07-26·CVSS 9.8
CVE-2022-43712 [CRITICAL] CWE-862 GHSA-mw64-5p9w-rfgc: POST requests to /web/mvc in GX Software XperienCentral version 10
POST requests to /web/mvc in GX Software XperienCentral version 10.36.0 and earlier were not blocked for uses that are not logged in. If an unauthorized user is able to bypass other security filters they are able to post unauthorized data to the server because of CVE-2022-22965.
OSV
CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding
osv·2022-04-01·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
GHSA
Remote Code Execution in Spring Framework
ghsa·2022-03-31
CVE-2022-22965 [CRITICAL] CWE-74 Remote Code Execution in Spring Framework
Remote Code Execution in Spring Framework
Spring Framework prior to versions 5.2.20 and 5.3.18 contains a remote code execution vulnerability known as `Spring4Shell`.
## Impact
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
These are the prerequisites for the exploit:
- JDK 9 or higher
- Apache Tomcat as the Servlet container
- Packaged as WAR
- `spring-webmvc` or `spring-webflux` dependency
## Patches
- S
OSV
Remote Code Execution in Spring Framework
osv·2022-03-31
CVE-2022-22965 [CRITICAL] Remote Code Execution in Spring Framework
Remote Code Execution in Spring Framework
Spring Framework prior to versions 5.2.20 and 5.3.18 contains a remote code execution vulnerability known as `Spring4Shell`.
## Impact
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
These are the prerequisites for the exploit:
- JDK 9 or higher
- Apache Tomcat as the Servlet container
- Packaged as WAR
- `spring-webmvc` or `spring-webflux` dependency
## Patches
- S
VulnCheck
Spring Framework JDK 9+ Remote Code Execution Vulnerability
vulncheck·2022·CVSS 9.8
CVE-2022-22965 [CRITICAL] CWE-94 Spring Framework JDK 9+ Remote Code Execution Vulnerability
Spring Framework JDK 9+ Remote Code Execution Vulnerability
Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
Affected: VMware Spring Framework
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.trendmicro.com/en_us/research/22/d/cve-2022-22965-analyzing-the-exploitation-of-spring4shell-vulner.html; https://unit42.paloaltonetworks.com/recent-exploits-network-security-trends/; https://www.fortinet.com/blog/threat-research/zerobot-new-go-based-botnet-campaign-targets-multiple-vulnerabilities; https://blog.netlab.360.com/new-ddos-botnet-wszeor/; https:
Suricata
ET EXPLOIT SpringShell/Spring4Shell RCE Attempt (CVE-2022-22965)
suricata·2023-11-10·CVSS 9.8
CVE-2022-22965 [CRITICAL] ET EXPLOIT SpringShell/Spring4Shell RCE Attempt (CVE-2022-22965)
ET EXPLOIT SpringShell/Spring4Shell RCE Attempt (CVE-2022-22965)
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET EXPLOIT SpringShell/Spring4Shell RCE Attempt (CVE-2022-22965)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:".jsp?pwd=j&cmd=id"; endswith; fast_pattern; http.request_body; content:"class.module.classLoader.resources.context.parent.pipeline"; reference:url,unit42.paloaltonetworks.com/cve-2022-22965-springshell/; reference:cve,2022-22965; classtype:attempted-admin; sid:2049150; rev:1; metadata:affected_product Spring_Framework, attack_target Client_Endpoint, created_at 2023_11_10, cve CVE_2022_22965, deployment Perimeter, deployment SSLDecrypt, confidence High, signature_severity Major, tag CVE_2022_22965, tag CISA_KEV, tag Description_
Suricata
ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 1 Pattern Set Inbound (CVE-2022-22965)
suricata·2022-03-31·CVSS 9.8
CVE-2022-22965 [CRITICAL] ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 1 Pattern Set Inbound (CVE-2022-22965)
ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 1 Pattern Set Inbound (CVE-2022-22965)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 1 Pattern Set Inbound (CVE-2022-22965)"; flow:established,to_server; http.uri; content:"pipeline.first.pattern="; fast_pattern; classtype:attempted-admin; sid:2035674; rev:3; metadata:attack_target Server, created_at 2022_03_31, cve CVE_2022_22965, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible SpringCore RCE/Spring4Shell Inbound (CVE-2022-22965)
suricata·2022-03-31·CVSS 9.8
CVE-2022-22965 [CRITICAL] ET EXPLOIT Possible SpringCore RCE/Spring4Shell Inbound (CVE-2022-22965)
ET EXPLOIT Possible SpringCore RCE/Spring4Shell Inbound (CVE-2022-22965)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible SpringCore RCE/Spring4Shell Inbound (CVE-2022-22965)"; flow:established,to_server; http.request_body; content:"pipeline.first.pattern="; fast_pattern; content:"pipeline.first.suffix="; content:"pipeline.first.directory="; content:"pipeline.first.prefix="; classtype:attempted-admin; sid:2035678; rev:3; metadata:attack_target Server, created_at 2022_03_31, cve CVE_2022_22965, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_
Suricata
ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 3 Directory Set Inbound (CVE-2022-22965)
suricata·2022-03-31·CVSS 9.8
CVE-2022-22965 [CRITICAL] ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 3 Directory Set Inbound (CVE-2022-22965)
ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 3 Directory Set Inbound (CVE-2022-22965)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 3 Directory Set Inbound (CVE-2022-22965)"; flow:established,to_server; http.uri; content:"pipeline.first.directory="; fast_pattern; classtype:attempted-admin; sid:2035676; rev:3; metadata:attack_target Server, created_at 2022_03_31, cve CVE_2022_22965, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 2 Suffix Set Inbound (CVE-2022-22965)
suricata·2022-03-31·CVSS 9.8
CVE-2022-22965 [CRITICAL] ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 2 Suffix Set Inbound (CVE-2022-22965)
ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 2 Suffix Set Inbound (CVE-2022-22965)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 2 Suffix Set Inbound (CVE-2022-22965)"; flow:established,to_server; http.uri; content:"pipeline.first.suffix="; fast_pattern; classtype:attempted-admin; sid:2035675; rev:3; metadata:attack_target Server, created_at 2022_03_31, cve CVE_2022_22965, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Suricata
ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 4 Prefix Set Inbound (CVE-2022-22965)
suricata·2022-03-31·CVSS 9.8
CVE-2022-22965 [CRITICAL] ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 4 Prefix Set Inbound (CVE-2022-22965)
ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 4 Prefix Set Inbound (CVE-2022-22965)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT Possible SpringCore RCE/Spring4Shell Stage 4 Prefix Set Inbound (CVE-2022-22965)"; flow:established,to_server; http.uri; content:"pipeline.first.prefix="; fast_pattern; classtype:attempted-admin; sid:2035677; rev:3; metadata:attack_target Server, created_at 2022_03_31, cve CVE_2022_22965, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_technique_name Exploit_Public_Facing_Application;)
Nuclei
Spring - Remote Code Execution
nuclei·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring - Remote Code Execution
Spring - Remote Code Execution
Spring MVC and Spring WebFlux applications running on Java Development Kit 9+ are susceptible to remote code execution via data binding. It requires the application to run on Tomcat as a WAR deployment. An attacker can execute malware, obtain sensitive information, modify data, and/or gain full control over a compromised system without entering necessary credentials.
Template:
id: CVE-2022-22965
info:
name: Spring - Remote Code Execution
author: justmumu,arall,dhiyaneshDK,akincibor
severity: critical
description: |
Spring MVC and Spring WebFlux applications running on Java Development Kit 9+ are susceptible to remote code execution via data binding. It requires the application to run on Tomcat as a WAR deployment. An attacker can execute malware, obtain s
Metasploit
Spring Framework Class property RCE (Spring4Shell)
metasploit
Spring Framework Class property RCE (Spring4Shell)
Spring Framework Class property RCE (Spring4Shell)
Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and older versions when running on JDK 9 or above and specifically packaged as a traditional WAR and deployed in a standalone Tomcat instance are vulnerable to remote code execution due to an unsafe data binding used to populate an object from request parameters to set a Tomcat specific ClassLoader. By crafting a request to the application and referencing the org.apache.catalina.valves.AccessLogValve class through the classLoader with parameters such as the following: class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp, an unauthenticated attacker can gain remote code execution.
Nuclei
Spring Framework RCE via Data Binding on JDK 9+
nuclei·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring Framework RCE via Data Binding on JDK 9+
Spring Framework RCE via Data Binding on JDK 9+
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Template:
id: spring4shell-CVE-2022-22965
info:
name: Spring Framework RCE via Data Binding on JDK 9+
author: DhiyaneshDK,ritikchaddha
severity: critical
description: |
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploi
Unit42
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
blogs_unit42·2026-07-15
CVE-2022-1388 TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
## TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development
Chris Navarrete
Asher Davila
Doel Santos
Published: July 15, 2026
Malware
Threat Research
C2
DGA
Docker compose
Malware
TuxBot v3 Evolution
VirusTotal
XOR
## Executive Summary
We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution.
The malware authors leveraged an LLM to assist in their code development, yielding mixed results. While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed to remove before shipping.
Although the LLM clearly aided in constructing the botnet, several functions in the analyzed samples failed to work correctly. While a manual code review could hav
Wiz
What Is Arbitrary Code Execution? ACE Attacks Explained | Wiz
blogs_wiz·2025-11-30
What Is Arbitrary Code Execution? ACE Attacks Explained | Wiz
## What is arbitrary code execution?
Arbitrary code execution is when an attacker tricks your system into running their malicious code without permission. Think of it like someone breaking into your house and using your computer to do whatever they want.
When attackers achieve ACE, they can execute any commands they choose on your system. This lets attackers run code with the privileges of the compromised process—which could be a low-privilege web service account or a high-privilege system daemon. The actual control level depends on what permissions the exploited application already has. It's one of the worst types of security vulnerabilities because it hands over complete system access to the attacker.
Cloud environments change the blast radius calculus for ACE attacks. If network segm
Wiz
What Is Arbitrary Code Execution? ACE Attacks Explained | Wiz
blogs_wiz·2025-11-30
What Is Arbitrary Code Execution? ACE Attacks Explained | Wiz
## What is arbitrary code execution?
Arbitrary code execution is when an attacker tricks your system into running their malicious code without permission. Think of it like someone breaking into your house and using your computer to do whatever they want.
When attackers achieve ACE, they can execute any commands they choose on your system. This lets attackers run code with the privileges of the compromised process—which could be a low-privilege web service account or a high-privilege system daemon. The actual control level depends on what permissions the exploited application already has. It's one of the worst types of security vulnerabilities because it hands over complete system access to the attacker.
Cloud environments change the blast radius calculus for ACE attacks. If network segm
Zscaler
Zero Trust for Cloud Architects: Turning Spring4Shell Lessons into Resilient Workload Design | Zscaler
blogs_zscaler·2025-11-04·CVSS 9.8
[CRITICAL] Zero Trust for Cloud Architects: Turning Spring4Shell Lessons into Resilient Workload Design | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Qualys
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
blogs_qualys·2025-05-08
Inside LockBit: Defense Lessons from the Leaked LockBit Negotiations
## Table of Contents
Who is LockBit? How it Evolved and Operates
Monero: The Coin of the Realm
Patch or Mitigate Now: Critical CVEs Exploited by LockBit
Beyond Traditional Endpoints: Other Compromised Systems
Initial Access and Deployment
Conclusion
The LockBit ransomware gang recently suffered a significant data breach. Their dark web affiliate panels were defaced with the message “Don’t do crime CRIME IS BAD xoxo from Prague,” linking to a MySQL database dump. This archive contains a SQL file from LockBit’s affiliate panel database that includes twenty tables, notably including a ‘btc_addresses’ table with 59,975 unique bitcoin addresses and a ‘chats’ table containing over 4,400 victim negotiation messages from December 2024 to the end of April 2025.
This blog post will leverage
Wiz
What Is Application Security Testing? | Wiz
blogs_wiz·2025-02-28·CVSS 9.8
[CRITICAL] What Is Application Security Testing? | Wiz
Application security testing (AST) is a set of processes designed to detect and address security gaps during the early phases of the software development lifecycle (SDLC) . In other words, teams take steps in pre-production to identify and mitigate risks before applications are released into operational environments. By integrating application security testing into existing workflows, teams can catch issues early, avoid duplicating efforts, and reduce costly inefficiencies that come up when vulnerabilities surface after deployment.
That said, application security testing can feel like one more thing to keep track of. As the line between development and operations gets narrower, modern development teams often wear multiple hats: innovating, building features, using containerization, and wr
Wiz
What Is Application Security Testing? | Wiz
blogs_wiz·2025-02-28·CVSS 9.8
[CRITICAL] What Is Application Security Testing? | Wiz
Application security testing (AST) is a set of processes designed to detect and address security gaps during the early phases of the software development lifecycle (SDLC). In other words, teams take steps in pre-production to identify and mitigate risks before applications are released into operational environments. By integrating application security testing into existing workflows, teams can catch issues early, avoid duplicating efforts, and reduce costly inefficiencies that come up when vulnerabilities surface after deployment.
That said, application security testing can feel like one more thing to keep track of. As the line between development and operations gets narrower, modern development teams often wear multiple hats: innovating, building features, using containerization, and wri
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Qualys
Oracle Security Updates: Critical Patch April 2023 Advisory | Qualys
blogs_qualys·2023-04-19
Oracle Security Updates: Critical Patch April 2023 Advisory | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released the second quarterly edition of Critical Patch Update, which contains a group of patches for 433 security vulnerabilities. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q2 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 77, constituting 17% of the total patches released. The Oracle Financial Services Applications and Oracle Fusion Mi
Qualys
Oracle Patch Tuesday April 2023 Security Update Review
blogs_qualys·2023-04-19
Oracle Patch Tuesday April 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released the second quarterly edition of Critical Patch Update, which contains a group of patches for 433 security vulnerabilities. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q2 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 77, constituting 17% of the total patches released. The Oracle Financial Services Applications and Oracle Fusion Middlewar
Qualys
The January 2023 Oracle Critical Patch Update
blogs_qualys·2023-01-18
The January 2023 Oracle Critical Patch Update
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Conclusion
This Oracle Critical Patch Update contains a group of patches for multiple security vulnerabilities that address 327 new security patches. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and in third-party components included in Oracle products. We urge customers to apply these time-sensitive Oracle Critical Patch Updates.
During Q1 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 79, constituting 24% of the total patches released. The Oracle Fusion Middleware and Oracle Communications Applications product lines followed, with 50 and 39 patches, respe
Qualys
The January 2023 Oracle Critical Patch Update | Qualys
blogs_qualys·2023-01-18
The January 2023 Oracle Critical Patch Update | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Conclusion
This Oracle Critical Patch Update contains a group of patches for multiple security vulnerabilities that address 327 new security patches. Some of the vulnerabilities addressed this month impact various products. These patches address vulnerabilities in Oracle code and in third-party components included in Oracle products. We urge customers to apply these time-sensitive Oracle Critical Patch Updates.
During Q1 2023 Oracle Critical Patch Update, the Oracle Communications product suite recorded the highest number of patches at 79, constituting 24% of the total patches released. The Oracle Fusion Middleware and Oracle Communications Applications product lines followed, with 50 and 39 patches,
Qualys
Identify Server-Side Attacks Using Qualys Periscope | Qualys
blogs_qualys·2022-12-01·CVSS 8.8
[HIGH] Identify Server-Side Attacks Using Qualys Periscope | Qualys
#### Table of Contents
- Potential False Positives
- Potential False Negatives
Qualys previously announced the introduction of Qualys Periscope in 2020. This technology allows Qualys Web Application Scanning (WAS) to detect out-of-band vulnerabilities such as server-side request forgery (SSRF). Qualys Periscope provides confirmed detections for additional vulnerabilities, such as Log4j, where it enables rapid development and release of the QID. Occasionally, Qualys receives questions and support cases related to Qualys Periscope. This article will provide more detail on the common questions/situations seen with out-of-band detections.
As of publishing, the vulnerability detections that utilize Qualys Periscope are:
- QID 150055 – OS Command Injection
- QID 150179 – Blind XXE injection
Qualys
Identify Server-Side Attacks Using Qualys Periscope
blogs_qualys·2022-12-01·CVSS 8.8
[HIGH] Identify Server-Side Attacks Using Qualys Periscope
## Table of Contents
Potential False Positives
Potential False Negatives
Qualys previously announced the introduction of Qualys Periscope in 2020. This technology allows Qualys Web Application Scanning (WAS) to detect out-of-band vulnerabilities such as server-side request forgery (SSRF). Qualys Periscope provides confirmed detections for additional vulnerabilities, such as Log4j, where it enables rapid development and release of the QID. Occasionally, Qualys receives questions and support cases related to Qualys Periscope . This article will provide more detail on the common questions/situations seen with out-of-band detections.
As of publishing, the vulnerability detections that utilize Qualys Periscope are:
QID 150055 – OS Command Injection
QID 150179 – Blind XXE injection
QID 15
Elastic
Elastic's response to the Spring4Shell vulnerability (CVE-2022-22965) — Elastic Security Labs
blogs_elastic·2022-11-22·CVSS 9.8
CVE-2022-22965 [CRITICAL] Elastic's response to the Spring4Shell vulnerability (CVE-2022-22965) — Elastic Security Labs
22 November 2022•Devon Kerr
# Elastic's response to the Spring4Shell vulnerability (CVE-2022-22965)
Provide executive-level details about CVE-2022-22965, a recently-disclosed remote code execution (RCE) vulnerability also known as “Spring4Shell”.
2 min readDetection Engineering
On March 29, 2022 a vulnerability in the Spring framework was disclosed to the public by VMware. This vulnerability had several prerequisites affecting impact:
- Spring framework versions 5.3.0-5.3.17, 5.2.0-5.2.19, potentially software versions prior to 5.2.x
- An application running as a Spring MVX or WebFlux object
- Apache Tomcat as the container for that application
- The application packaged as a Web Application Resource (WAR)
Specifically, this vulnerability targets the ClassLoader() class, though simil
Elastic
Elastic's response to the Spring4Shell vulnerability (CVE-2022-22965) — Elastic Security Labs
blogs_elastic·2022-11-22·CVSS 9.8
CVE-2022-22965 [CRITICAL] Elastic's response to the Spring4Shell vulnerability (CVE-2022-22965) — Elastic Security Labs
## Elastic's response to the Spring4Shell vulnerability (CVE-2022-22965)
Provide executive-level details about CVE-2022-22965, a recently-disclosed remote code execution (RCE) vulnerability also known as “Spring4Shell”.
On March 29, 2022 a vulnerability in the Spring framework was disclosed to the public by VMware. This vulnerability had several prerequisites affecting impact:
Spring framework versions 5.3.0-5.3.17, 5.2.0-5.2.19, potentially software versions prior to 5.2.x
An application running as a Spring MVX or WebFlux object
Apache Tomcat as the container for that application
The application packaged as a Web Application Resource (WAR)
Specifically, this vulnerability targets the ClassLoader() class, though similar undiscovered vulnerabilities in other classes are likely. A URI
Qualys
Why Is Snapshot Scanning Not Enough? | Qualys
blogs_qualys·2022-11-01
Why Is Snapshot Scanning Not Enough? | Qualys
#### Table of Contents
- What Is Snapshot Scanning?
- Places Where Snapshot Scanning Makes Sense
- Limitations of Snapshot Scanning
- When Agents Should Be Used
- When API-Based Scanning Should Be Used
- When network scanning should be used
- What Users Want Multiple Scanner Options
- What Is Qualys FlexScan?
- The Advantage of FlexScan
- Recommendations on When To Use Each Scanning Method With FlexScan
- Additional Resources
As new scanning technologies are released, their supposed superiority is touted over the others. The problem is, however, that there is no best scanning technology, all of them have strengths and limitations. If recent claims from several vendors are believed, a “best” scanning method called snapshot scanning exists. But when we look closely, snapshot scanning has a
Qualys
Why Is Snapshot Scanning Not Enough?
blogs_qualys·2022-11-01
Why Is Snapshot Scanning Not Enough?
## Table of Contents
What Is Snapshot Scanning?
Places Where Snapshot Scanning Makes Sense
Limitations of Snapshot Scanning
When Agents Should Be Used
When API-Based Scanning Should Be Used
When network scanning should be used
What Users Want Multiple Scanner Options
What Is Qualys FlexScan?
The Advantage of FlexScan
Recommendations on When To Use Each Scanning Method With FlexScan
Additional Resources
As new scanning technologies are released, their supposed superiority is touted over the others. The problem is, however, that there is no best scanning technology, all of them have strengths and limitations. If recent claims from several vendors are believed, a “best” scanning method called snapshot scanning exists. But when we look closely, snapshot scanning has advantages for
Qualys
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
blogs_qualys·2022-08-23
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
## Table of Contents
Why Are Zero-Day Attacks/Exploits so Dangerous?
How Qualys Policy Compliance Helps Combat Zero-Day Threats
Benefit of Qualys Policy Compliance for Zero-Day Threats
Summary
Getting Started
Contributors
Zero-day vulnerability attacks have emerged as a major cybersecurity threat in the last few years. Organizations most often targeted include large enterprises and government/Federal agencies. However, any organization, regardless of its size, business, or industry, is a potential target for zero-day threats.
Most notably, already publicly disclosed. This means that one out of every four zero-day exploits detected could potentially have been avoided if a more thorough investigation and patching effort had been pursued. In 2021, around 58 zero-day vulnerabilities we
Unit42
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
blogs_unit42·2022-08-19·CVSS 8.8
CVE-2021-20166 [HIGH] Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
Threat Research Center
Trend Reports
Vulnerabilities
## Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
Yue Guan
Published: August 19, 2022
Trend Reports
Vulnerabilities
Attack analysis
CVE-2021-20166
CVE-2021-20167
CVE-2021-21881
CVE-2021-24762
CVE-2021-28169
CVE-2021-31589
CVE-2021-39226
CVE-2021-4045
CVE-2021-43711
CVE-2022-21371
CVE-2022-21662
CVE-2022-22536
CVE-2022-22947
CVE-2022-22954
CVE-2022-22963
CVE-2022-22965
CVE-2022-24112
CVE-2022-24260
CVE-2022-25060
CVE-2022-25075
CVE-2022-25134
CVE-2022-27226
CVE-2022-29464
Exploit in the wild
Network security trends
## Executive Summary
Recent observations of exploits used in the wild reveal that attackers have been making use
Unit42
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
blogs_unit42·2022-08-19
Network Security Trends: Recent Exploits Observed in the Wild Include Remote Code Execution, Cross-Site Scripting and More
## Executive Summary
Recent observations of exploits used in the wild reveal that attackers have been making use of newly published remote code execution vulnerabilities in VMware ONE Access and Identity Manager and Spring Cloud Function, Spring MVC and Spring Web Flux, among others. Attackers have also been taking advantage of a cross-site scripting vulnerability in WordPress core, and SQL injection vulnerabilities in VoIPmonitor GUI and other services. In our observations of network security trends, Unit 42 researchers select exploits of the latest published attacks that defenders should know based on the availability of proofs of concept (PoCs), the severity of the vulnerabilities the exploits are based on and the ease of exploitation.
Other insights that could assist defenders includ
Securelist
IT threat evolution in Q2 2022. Non-mobile statistics
blogs_securelist·2022-08-15
IT threat evolution in Q2 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
TOP 10 countries and territories that serve as sources of web-based attacks
Countries and territories where users faced the greatest risk of online infection
Local threat
Securelist
Non-mobile malware statistics, Q2 2022
blogs_securelist·2022-08-15
Non-mobile malware statistics, Q2 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q2 2022
- IT threat evolution in Q2 2022. Non-mobile statistics
- IT threat evolution in Q2 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q2 2022:
- Kaspersky solutions blocked 1,164,544,060 attacks from online resources across the globe.
- Web Anti-Virus recognized 273,033,368 unique URLs as malicious. Attempts to run malware fo
Securelist
IT threat evolution Q2 2022
blogs_securelist·2022-08-15
IT threat evolution Q2 2022
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
- IT threat evolution in Q2 2022
- IT threat evolution in Q2 2022. Non-mobile statistics
- IT threat evolution in Q2 2022. Mobile statistics
## Targeted attacks
### New technique for installing fileless malware
Earlier this year, we discovered a malicious campaign that employed a new technique for installing fileless malware on target machines by injecting a shellcode directly into Windows event logs. The attackers were using this to hide a last-stage Trojan in the file system.
The attack starts by driving targets to a legitimate website and tricking them into downloading a compressed RAR file that is booby-trapped with the network penetration testing tools Cobalt Strike and SilentBreak. The attackers use thes
Securelist
IT threat evolution Q2 2022
blogs_securelist·2022-08-15
IT threat evolution Q2 2022
Table of Contents
Targeted attacks
New technique for installing fileless malware
WinDealer’s man-on-the-side spyware
ToddyCat: previously unknown threat actor attacks high-profile organizations in Europe and Asia
SessionManager IIS backdoor
Other malware
Spring4Shell
Actively exploited vulnerability in Windows
Follina vulnerability in MSDT
BlackCat: a new ransomware gang
Yanluowang ransomware: how to recover encrypted files
Ransomware TTPs
Ransomware trends in 2022
Emotet’s return
Mobile subscription Trojans
The threat from stalkerware
Authors
David Emm
IT threat evolution in Q2 2022
IT threat evolution in Q2 2022. Non-mobile statistics
IT threat evolution in Q2 2022. Mobile statistics
## Targeted attacks
## New technique for installing fileless malware
Earlier this
Unit42
Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
blogs_unit42·2022-07-21·CVSS 9.8
CVE-2017-5638 [CRITICAL] Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
Threat Research Center
Trend Reports
Vulnerabilities
## Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
Unit 42
Published: July 21, 2022
Trend Reports
Vulnerabilities
Apache Log4j
CVE-2017-5638
CVE-2017-9841
CVE-2018-19986
CVE-2019-02320
CVE-2019-19597
CVE-2019-9082
CVE-2020-14882
CVE-2020-14883
CVE-2020-15505
CVE-2020-15506
CVE-2020-25078
CVE-2020-5902
CVE-2021-21315
CVE-2021-22986
CVE-2021-26855
CVE-2021-31805
CVE-2021-34473
CVE-2021-35464
CVE-2021-38647
CVE-2021-40438
CVE-2021-40539
CVE-2021-41773
CVE-2021-42013
CVE-2021-44228
CVE-2021-45046
CVE-2022-22963
CVE-2022-22965
Network security trends
Unit 42 Network Threat Trends Research Report
## Executive Summary
Tens of thousands of vulnerabilities are repo
Unit42
Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
blogs_unit42·2022-07-21·CVSS 9.8
[CRITICAL] Top CVEs to Patch: Insights from the 2022 Unit 42 Network Threat Trends Research Report
## Executive Summary
Tens of thousands of vulnerabilities are reported every year, but not all are used by threat actors in real-world attacks. There are many reasons for this: a proof of concept (PoC) may not be available for attackers to weaponize, it may be too difficult to exploit the vulnerability, there may be a lack of accessible vulnerable software on the internet, or attackers may simply deem a vulnerability not worth exploiting due to low impact. Real-world defenders need real-world data on which vulnerabilities attackers are choosing to exploit – and where to focus protections.
In the 2022 Unit 42 Network Threat Trends Research Report, we’ve used data captured by the Palo Alto Networks Advanced Threat Prevention security service on Next-Generation Firewall and Prisma SASE from
Tenable
Oracle July 2022 Critical Patch Update Addresses 188 CVEs
blogs_tenable·2022-07-20
Oracle July 2022 Critical Patch Update Addresses 188 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cybersecurity Snapshot: 6 Things That Matter Right Now
blogs_tenable·2022-06-17
Cybersecurity Snapshot: 6 Things That Matter Right Now
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
So Many CVEs, So Little Time: Zero In and ‘Zero Click’ into the Current Vulnerability Landscape
blogs_tenable·2022-06-08
So Many CVEs, So Little Time: Zero In and ‘Zero Click’ into the Current Vulnerability Landscape
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
blogs_trendmicro·2022-05-31·CVSS 9.8
CVE-2022-29464 [CRITICAL] Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
Ausnutzung von Schwachstellen
## Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
Users of WSO2 products are advised to update their respective products and platforms or to apply the temporary mitigation steps immediately.
By: Hitomi Kimura, Abraham Camba, Ryan Soliven May 31, 2022 Read time: ( words)
Save to Folio
We observed vulnerability CVE-2022-29464 being exploited in the wild since April, allowing unrestricted file uploads resulting to arbitrary remote code execution (RCE). Disclosed and patched in April, the security gap was ranked Critical at 9.8 and affects a number of WSO2 products. It requires no user interaction and administrative privileges for abuse, and can be used to infiltrate networks when left unpatched.
Th
Trendmicro
Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
blogs_trendmicro·2022-05-31·CVSS 9.8
CVE-2022-29464 [CRITICAL] Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
Exploits & Vulnerabilities
## Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
Users of WSO2 products are advised to update their respective products and platforms or to apply the temporary mitigation steps immediately.
By: Hitomi Kimura, Abraham Camba, Ryan Soliven May 31, 2022 Read time: ( words)
Save to Folio
We observed vulnerability CVE-2022-29464 being exploited in the wild since April, allowing unrestricted file uploads resulting to arbitrary remote code execution (RCE). Disclosed and patched in April, the security gap was ranked Critical at 9.8 and affects a number of WSO2 products. It requires no user interaction and administrative privileges for abuse, and can be used to infiltrate networks when left unpatched.
The v
Trendmicro
Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
blogs_trendmicro·2022-05-31·CVSS 9.8
CVE-2022-29464 [CRITICAL] Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
Exploits & Vulnerabilities
# Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
Users of WSO2 products are advised to update their respective products and platforms or to apply the temporary mitigation steps immediately.
By: Hitomi Kimura, Abraham Camba, Ryan Soliven
2022/05/31
Read time: ( words)
Save to Folio
We observed vulnerability CVE-2022-29464 being exploited in the wild since April, allowing unrestricted file uploads resulting to arbitrary remote code execution (RCE). Disclosed and patched in April, the security gap was ranked Critical at 9.8 and affects a number of WSO2 products. It requires no user interaction and administrative privileges for abuse, and can be used to infiltrate networks when left unpatched.
The vul
Trendmicro
Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
blogs_trendmicro·2022-05-31·CVSS 9.8
CVE-2022-29464 [CRITICAL] Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
Exploits y vulnerabilidades
## Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
Users of WSO2 products are advised to update their respective products and platforms or to apply the temporary mitigation steps immediately.
By: Hitomi Kimura, Abraham Camba, Ryan Soliven May 31, 2022 Read time: ( words)
Save to Folio
We observed vulnerability CVE-2022-29464 being exploited in the wild since April, allowing unrestricted file uploads resulting to arbitrary remote code execution (RCE). Disclosed and patched in April, the security gap was ranked Critical at 9.8 and affects a number of WSO2 products. It requires no user interaction and administrative privileges for abuse, and can be used to infiltrate networks when left unpatched.
The
Trendmicro
Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
blogs_trendmicro·2022-05-31·CVSS 9.8
CVE-2022-29464 [CRITICAL] Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
Exploits & Vulnerabilities
## Patch Your WSO2: CVE-2022-29464 Exploited to Install Linux-Compatible Cobalt Strike Beacons, Other Malware
Users of WSO2 products are advised to update their respective products and platforms or to apply the temporary mitigation steps immediately.
By: Hitomi Kimura, Abraham Camba, Ryan Soliven 2022/05/31 Read time: ( words)
Save to Folio
We observed vulnerability CVE-2022-29464 being exploited in the wild since April, allowing unrestricted file uploads resulting to arbitrary remote code execution (RCE). Disclosed and patched in April, the security gap was ranked Critical at 9.8 and affects a number of WSO2 products. It requires no user interaction and administrative privileges for abuse, and can be used to infiltrate networks when left unpatched.
The vul
Securelist
IT threat evolution in Q1 2022. Non-mobile statistics
blogs_securelist·2022-05-27
IT threat evolution in Q1 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Geography of financial malware attacks
TOP 10 banking malware families
Ransomware programs
Quarterly trends and highlights
Law enforcement successes
HermeticWiper, HermeticRansom and RUransom, etc.
Conti source-code leak
Attacks on NAS devices
Maze Decryptor
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarter highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat
Securelist
PC malware statistics, Q1 2022
blogs_securelist·2022-05-27
PC malware statistics, Q1 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q1 2022
- IT threat evolution in Q1 2022. Non-mobile statistics
- IT threat evolution in Q1 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q1 2022:
- Kaspersky solutions blocked 1,216,350,437 attacks from online resources across the globe.
- Web Anti-Virus recognized 313,164,030 unique URLs as malicious.
- Attempts to run malware
Checkpoint
16th May – Threat Intelligence Report
blogs_checkpoint·2022-05-16
CVE-2022-1388 16th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 16th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 16th May, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research revealed a yearlong campaign targeting German companies, focused on German car dealerships and manufacturers. Threat actors used a vast infrastructure designed to mimic existing German companies and leveraged phishing emails, with a combination of ISO\HTA payloads that, if opened, would infect victims with va
Trendmicro
Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
blogs_trendmicro·2022-04-20·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
Ausnutzung von Schwachstellen
## Analyzing Attempts to Exploit the Spring4Shell Vulnerability CVE-2022-22965 to Deploy Cryptocurrency Miners
Recently, we observed attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 — by malicious actors to deploy cryptocurrency miners.
By: Nitesh Surana, Ashish Verma Apr 20, 2022 Read time: ( words)
Save to Folio
To generate more profit, operators of cryptocurrency miners constantly look for ways to deploy their malware on vulnerable machines. These often involve the exploitation of in-the-wild vulnerabilities in different types of operating systems . Recently, we observed active attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 , that e
Trendmicro
Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
blogs_trendmicro·2022-04-20·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
Exploits y vulnerabilidades
## Analyzing Attempts to Exploit the Spring4Shell Vulnerability CVE-2022-22965 to Deploy Cryptocurrency Miners
Recently, we observed attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 — by malicious actors to deploy cryptocurrency miners.
By: Nitesh Surana, Ashish Verma Apr 20, 2022 Read time: ( words)
Save to Folio
To generate more profit, operators of cryptocurrency miners constantly look for ways to deploy their malware on vulnerable machines. These often involve the exploitation of in-the-wild vulnerabilities in different types of operating systems . Recently, we observed active attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 , that exi
Trendmicro
Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
blogs_trendmicro·2022-04-20·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
Sfruttamento vulnerabilità
## Analyzing Attempts to Exploit the Spring4Shell Vulnerability CVE-2022-22965 to Deploy Cryptocurrency Miners
Recently, we observed attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 — by malicious actors to deploy cryptocurrency miners.
By: Nitesh Surana, Ashish Verma Apr 20, 2022 Read time: ( words)
Save to Folio
To generate more profit, operators of cryptocurrency miners constantly look for ways to deploy their malware on vulnerable machines. These often involve the exploitation of in-the-wild vulnerabilities in different types of operating systems . Recently, we observed active attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 , that exis
Trendmicro
Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
blogs_trendmicro·2022-04-20·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
Exploits & Vulnerabilities
## Analyzing Attempts to Exploit the Spring4Shell Vulnerability CVE-2022-22965 to Deploy Cryptocurrency Miners
Recently, we observed attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 — by malicious actors to deploy cryptocurrency miners.
By: Nitesh Surana, Ashish Verma Apr 20, 2022 Read time: ( words)
Save to Folio
To generate more profit, operators of cryptocurrency miners constantly look for ways to deploy their malware on vulnerable machines. These often involve the exploitation of in-the-wild vulnerabilities in different types of operating systems . Recently, we observed active attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 , that exis
Trendmicro
Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
blogs_trendmicro·2022-04-20·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
Exploits & Vulnerabilities
# Analyzing Attempts to Exploit the Spring4Shell Vulnerability CVE-2022-22965 to Deploy Cryptocurrency Miners
Recently, we observed attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 — by malicious actors to deploy cryptocurrency miners.
By: Nitesh Surana, Ashish Verma
2022/04/20
Read time: ( words)
Save to Folio
To generate more profit, operators of cryptocurrency miners constantly look for ways to deploy their malware on vulnerable machines. These often involve the exploitation of in-the-wild vulnerabilities in different types of operating systems. Recently, we observed active attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965, that exists i
Trendmicro
Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
blogs_trendmicro·2022-04-20·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
Exploits & Vulnerabilities
# Analyzing Attempts to Exploit the Spring4Shell Vulnerability CVE-2022-22965 to Deploy Cryptocurrency Miners
Recently, we observed attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 — by malicious actors to deploy cryptocurrency miners.
By: Nitesh Surana, Ashish Verma
Apr 20, 2022
Read time: ( words)
Save to Folio
To generate more profit, operators of cryptocurrency miners constantly look for ways to deploy their malware on vulnerable machines. These often involve the exploitation of in-the-wild vulnerabilities in different types of operating systems. Recently, we observed active attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965, that exists
Trendmicro
Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
blogs_trendmicro·2022-04-20·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring4Shell Vulnerability CVE-2022-22965 Exploited to Deploy Cryptocurrency Miners
Exploits & Vulnerabilities
## Analyzing Attempts to Exploit the Spring4Shell Vulnerability CVE-2022-22965 to Deploy Cryptocurrency Miners
Recently, we observed attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 — by malicious actors to deploy cryptocurrency miners.
By: Nitesh Surana, Ashish Verma 2022/04/20 Read time: ( words)
Save to Folio
To generate more profit, operators of cryptocurrency miners constantly look for ways to deploy their malware on vulnerable machines. These often involve the exploitation of in-the-wild vulnerabilities in different types of operating systems . Recently, we observed active attempts to exploit the Spring4Shell vulnerability — a remote code execution bug, assigned as CVE-2022-22965 , that exists
Sentinelone
Spring4Shell Vulnerability (CVE-2022-22965): How to Protect Your Spring Based Applications
blogs_sentinelone·2022-04-15·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring4Shell Vulnerability (CVE-2022-22965): How to Protect Your Spring Based Applications
On the 30th of March, 2022 , a new zero-day CVE was discovered, named CVE-2022-22965, in applications that run on Tomcat as a WAR deployment having Spring MVC or Spring WebFlux running on JDK 9+. Such applications may be vulnerable to remote code execution (RCE) via data binding. The bug exists in the getCachedIntrospectionResults method, which can be used to gain unauthorized access to such objects by passing their class names via an HTTP request. It creates the risks of data leakage and remote code execution when special object classes are used. The vulnerability is remotely exploitable without authentication, i.e., it can be exploited over a network without a username and password.
## Below are the prerequisites to exploit this vulnerability:
JDK 9 or higher
Apache Tomcat as the Serv
Sentinelone
Spring4Shell Vulnerability (CVE-2022-22965): How to Protect Your Spring Based Applications
blogs_sentinelone·2022-04-15·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring4Shell Vulnerability (CVE-2022-22965): How to Protect Your Spring Based Applications
On the 30th of March, 2022, a new zero-day CVE was discovered, named CVE-2022-22965, in applications that run on Tomcat as a WAR deployment having Spring MVC or Spring WebFlux running on JDK 9+. Such applications may be vulnerable to remote code execution (RCE) via data binding. The bug exists in the getCachedIntrospectionResults method, which can be used to gain unauthorized access to such objects by passing their class names via an HTTP request. It creates the risks of data leakage and remote code execution when special object classes are used. The vulnerability is remotely exploitable without authentication, i.e., it can be exploited over a network without a username and password.
## Below are the prerequisites to exploit this vulnerability:
- JDK 9 or higher
- Apache Tomcat as the Se
Checkpoint
11th April – Threat Intelligence Report
blogs_checkpoint·2022-04-11
CVE-2022-22965 11th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 11th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 11th April, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research discovered six applications spreading banking malware on Google Play Store by masquerading as anti-virus solutions, with over 15,000 downloads. The malware, known as ‘Sharkbot’, steals credentials and banking information of Android users.
Check Point Harmony Mobile and Threat Emulation provide protection
Trendmicro
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
## CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Nitesh Surana, Ashish Verma Apr 08, 2022 Read time: ( words)
Save to Folio
Trend Micro Threat Research observed active exploitation of the Spring4Shell vulnerability assigned as CVE-2022-22965 , which allows malicious actors to weaponize and execute the Mirai botnet malware . The exploitation allows threat actors to download the Mirai sample to the “/tmp” folder and execute them after permission change using “chmod”.
We began seeing malicious activities at the start of Ap
Trendmicro
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
## CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Ashish Verma Apr 08, 2022 Read time: ( words)
Save to Folio
Trend Micro Threat Research observed active exploitation of the Spring4Shell vulnerability assigned as CVE-2022-22965 , which allows malicious actors to weaponize and execute the Mirai botnet malware . The exploitation allows threat actors to download the Mirai sample to the “/tmp” folder and execute them after permission change using “chmod”.
We began seeing malicious activities at the start of April 2022. We al
Trendmicro
Analyse der Angriffe über die Spring4Shell-Lücke
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] Analyse der Angriffe über die Spring4Shell-Lücke
## CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Ashish Verma Apr 08, 2022 Read time: ( words)
Save to Folio
Originalartikel von Deep Patel, Nitesh Surana, Ashish Verma, Threat Researcher
Das Trend Micro Threat Research konnte den aktiven Missbrauch der Spring4Shell-Schwachstelle beobachten. Die Lücke mit der Bezeichung CVE-2022-22965 ermöglicht es Angreifern, Mirai Botnet Malware herunterzuladen und auszuführen. Die ersten bösartigen Aktivitäten verzeichneten wir Anfang April 2022. Wir fanden auch den Malware-Dateiserv
Trendmicro
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
# CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Nitesh Surana, Ashish Verma
Apr 08, 2022
Read time: ( words)
Save to Folio
Trend Micro Threat Research observed active exploitation of the Spring4Shell vulnerability assigned as CVE-2022-22965, which allows malicious actors to weaponize and execute the Mirai botnet malware. The exploitation allows threat actors to download the Mirai sample to the “/tmp” folder and execute them after permission change using “chmod”.
We began seeing malicious activities at the start of Apri
Trendmicro
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
## CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Nitesh Surana, Ashish Verma 2022/04/08 Read time: ( words)
Save to Folio
Trend Micro Threat Research observed active exploitation of the Spring4Shell vulnerability assigned as CVE-2022-22965 , which allows malicious actors to weaponize and execute the Mirai botnet malware . The exploitation allows threat actors to download the Mirai sample to the “/tmp” folder and execute them after permission change using “chmod”.
We began seeing malicious activities at the start of Apri
Trendmicro
CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
blogs_trendmicro·2022-04-08·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965 Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
# CVE-2022-22965: Analyzing the Exploitation of Spring4Shell Vulnerability in Weaponizing and Executing the Mirai Botnet Malware
We discovered active exploitation of a vulnerability in the Spring Framework designated as CVE-2022-22965 that allows malicious actors to download the Mirai botnet malware.
By: Deep Patel, Nitesh Surana, Ashish Verma
2022/04/08
Read time: ( words)
Save to Folio
Trend Micro Threat Research observed active exploitation of the Spring4Shell vulnerability assigned as CVE-2022-22965, which allows malicious actors to weaponize and execute the Mirai botnet malware. The exploitation allows threat actors to download the Mirai sample to the “/tmp” folder and execute them after permission change using “chmod”.
We began seeing malicious activities at the start of April
Talos
Threat Source newsletter (April 7, 2022) — More money for cybersecurity still doesn't solve the skills gap problem
blogs_talos·2022-04-07
Threat Source newsletter (April 7, 2022) — More money for cybersecurity still doesn't solve the skills gap problem
## Threat Source newsletter (April 7, 2022) — More money for cybersecurity still doesn't solve the skills gap problem
Welcome to this week’s edition of the Threat Source newsletter.
U.S. President Joe Biden’s proposed budget would include an 11 percent increase in the federal government’s IT budget , including a total of $10.9 billion for cybersecurity. On the surface — this is all great (we can save a discussion about the national debt and spending gap for a later time).
There‘s still a way to go before any of that money becomes real — a president’s proposed budget rarely gets passed as-is after layers of negotiation and Congressional votes. But this is a promising sign that the administration is ready and willing to invest more in cybersecurity to address holes in federal networks tha
Talos
Threat Source newsletter (April 7, 2022) — More money for cybersecurity still doesn't solve the skills gap problem
blogs_talos·2022-04-07
Threat Source newsletter (April 7, 2022) — More money for cybersecurity still doesn't solve the skills gap problem
Welcome to this week’s edition of the Threat Source newsletter.
U.S. President Joe Biden’s proposed budget would include an 11 percent increase in the federal government’s IT budget, including a total of $10.9 billion for cybersecurity. On the surface — this is all great (we can save a discussion about the national debt and spending gap for a later time).
There‘s still a way to go before any of that money becomes real — a president’s proposed budget rarely gets passed as-is after layers of negotiation and Congressional votes. But this is a promising sign that the administration is ready and willing to invest more in cybersecurity to address holes in federal networks that are constantly being targeted. The FBI is already preparing to put that money to use to track down ransomware actors.
Securelist
Spring4Shell (CVE-2022-22965): details and mitigations
blogs_securelist·2022-04-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] Spring4Shell (CVE-2022-22965): details and mitigations
Table of Contents
- CVE-2022-22965 and CVE-2022-22963: technical details
- Mitigations for Spring vulnerabilities exploitation
- Indicators of Compromise
Authors
- AMR
Last week researchers found the critical vulnerability CVE-2022-22965 in Spring – the open source Java framework. Using the vulnerability, an attacker can execute arbitrary code on a remote web server, which makes CVE-2022-22965 a critical threat, given the Spring framework’s popularity. By analogy with the infamous Log4Shell threat, the vulnerability was named Spring4Shell.
## CVE-2022-22965 and CVE-2022-22963: technical details
CVE-2022-22965 (Spring4Shell, SpringShell) is a vulnerability in the Spring Framework that uses data binding functionality to bind data stored within an HTTP request to certain objects used b
Securelist
Spring4Shell (CVE-2022-22965): details and mitigations
blogs_securelist·2022-04-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] Spring4Shell (CVE-2022-22965): details and mitigations
Table of Contents
CVE-2022-22965 and CVE-2022-22963: technical details
Mitigations for Spring vulnerabilities exploitation
Indicators of Compromise
Authors
AMR
Last week researchers found the critical vulnerability CVE-2022-22965 in Spring – the open source Java framework. Using the vulnerability, an attacker can execute arbitrary code on a remote web server, which makes CVE-2022-22965 a critical threat, given the Spring framework’s popularity. By analogy with the infamous Log4Shell threat , the vulnerability was named Spring4Shell.
## CVE-2022-22965 and CVE-2022-22963: technical details
CVE-2022-22965 (Spring4Shell, SpringShell) is a vulnerability in the Spring Framework that uses data binding functionality to bind data stored within an HTTP request to certain objects used by an a
Checkpoint
4th April – Threat Intelligence Report
blogs_checkpoint·2022-04-04
CVE-2022-22965 4th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 4th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 4th April, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research (CPR) revealed a large spike in attacks committed by advanced persistent threat groups (APTs) around the world, using lures utilizing the war between Russia and Ukraine. Most of the attacks started with spear-phishing emails that contained documents with malicious macros dropping malware such as Loki.Rat ba
Wiz
Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
blogs_wiz·2022-04-01·CVSS 6.0
CVE-2022-22965 [MEDIUM] Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
Updated April 13th, 2022 to include the latest available information about CVE-2022-22965, further explanation of dependencies in Spring Framework, and data about the prevalence of this vulnerability in cloud environments.
Two critical Remote Code Execution (RCE) vulnerabilities were recently patched in popular Spring Java libraries, and both have generated quite a bit of buzz:
CVE-2022-22965 (Spring Framework RCE via Data Binding on JDK version 9 or higher) –
This vulnerability affects Java software dependent on Spring Framework versions earlier than 5.2.19, and versions 5.3.0 to 5.3.17. Developers must update their software’s dependencies to Spring Framework versions 5.3.18 or 5.2.20, or apply any of multiple workarounds suggested by Spring .
Dubbed “Spring4Shell” (in the same vein a
Wiz
Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
blogs_wiz·2022-04-01·CVSS 6.0
CVE-2022-22963 [MEDIUM] Addressing the Spring4Shell and CVE-2022-22963 RCE vulnerabilities in cloud environments | Wiz Blog
Updated April 13th, 2022 to include the latest available information about CVE-2022-22965, further explanation of dependencies in Spring Framework, and data about the prevalence of this vulnerability in cloud environments.
Two critical Remote Code Execution (RCE) vulnerabilities were recently patched in popular Spring Java libraries, and both have generated quite a bit of buzz:
CVE-2022-22965 (Spring Framework RCE via Data Binding on JDK version 9 or higher) –
- This vulnerability affects Java software dependent on Spring Framework versions earlier than 5.2.19, and versions 5.3.0 to 5.3.17. Developers must update their software’s dependencies to Spring Framework versions 5.3.18 or 5.2.20, or apply any of multiple workarounds suggested by Spring.
- Dubbed “Spring4Shell” (in the same vein
Sentinelone
Spring Cloud Function RCE Vulnerability (CVE-2022-22963)
blogs_sentinelone·2022-04-01·CVSS 9.8
CVE-2022-22963 [CRITICAL] Spring Cloud Function RCE Vulnerability (CVE-2022-22963)
On the 30th of March, 2022, a new Zero-day CVE in Spring Cloud Functions was discovered, named CVE-2022-22963. Spring Cloud Function promotes the implementation of business logic via functions. The vulnerability is remotely exploitable without authentication, i.e., it can be exploited over a network without a username and password.
## What is a Spring Cloud function?
Spring Cloud is an open-source microservice framework. Spring Cloud is a collection of functions useful in building distributed enterprise applications.
Due to the severity of this vulnerability, Sentinelone strongly recommends that customers apply the updates and upgrade the Spring cloud function to the recommended patch Spring Cloud Function 3.2.3 or 3.1.7.
## What is the impact of Spring Cloud vulnerability?
The spring
Talos
Threat Advisory: Spring4Shell
blogs_talos·2022-03-31·CVSS 6.0
CVE-2022-22965 [MEDIUM] Threat Advisory: Spring4Shell
## UPDATE, APRIL 4, 2022:
The Kenna Risk Score for CVE-2022-22965 is currently at maximum 100. This is an exceptionally rare score, of which only 415 out of 184,000 CVEs (or 0.22 percent) have achieved, reflecting the severity and potential effects of this vulnerability. To get a risk score this high means it is a widely deployed technology with a public exploit available, and we have seen proof of an ongoing active internet breach using the vulnerability.
Kenna Risk Scores are continually reevaluated and may shift over time. An outline of the current risk score is below:
Cisco Talos is releasing coverage to protect users against the exploitation of two remote code execution vulnerabilities in Spring Framework. CVE-2022-22963 is a medium-severity bug that affects Spring Cloud and CVE-20
Unit42
CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
blogs_unit42·2022-03-31·CVSS 6.0
CVE-2022-22965 [MEDIUM] CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
## Executive Summary
Recently, two vulnerabilities were announced within the Spring Framework, an open-source framework for building enterprise Java applications. On March 29, 2022, the Spring Cloud Expression Resource Access Vulnerability tracked in CVE-2022-22963 was patched with the release of Spring Cloud Function 3.1.7 and 3.2.3. Two days later on March 31, 2022, Spring released version 5.3.18 and 5.2.20 of Spring Framework to patch another more severe vulnerability tracked in CVE-2022-22965. The CVE-2022-22965 vulnerability allows an attacker unauthenticated remote code execution (RCE), which Unit 42 has observed being exploited in the wild. The exploitation of this vulnerability could result in a webshell being installed onto the compromised server that allows further command execu
Qualys
Spring Framework Zero-Day Remote Code Execution (Spring4Shell) Vulnerability
blogs_qualys·2022-03-31
Spring Framework Zero-Day Remote Code Execution (Spring4Shell) Vulnerability
## Table of Contents
What is Spring Framework?
Which versions are vulnerable?
How can this be exploited?
What are the prerequisites to exploit this vulnerability?
Is there a patch available for Spring4Shell?
Qualys Coverage
Discover Your Attack Surface with up-to-date CyberSecurity Asset Management
Detect the Vulnerability with Qualys WAS
Detect Spring4Shell Vulnerability Using Qualys VMDR
Track Spring4Shell Progress with Unified Dashboard
Detect Spring4Shell Vulnerabilities in Running Containers & Images
Remediate Spring4Shell Using Qualys Patch Management
FAQ:
Updates
A new zero-day Remote Code Execution (RCE) vulnerability, “Spring4Shell” or “SpringShell” was disclosed in the Spring framework. An unauthorized attacker can exploit this vulnerability to remotely execute arb
Talos
Threat Advisory: Spring4Shell
blogs_talos·2022-03-31·CVSS 6.0
CVE-2022-22965 [MEDIUM] Threat Advisory: Spring4Shell
## Threat Advisory: Spring4Shell
## UPDATE, APRIL 4, 2022:
The Kenna Risk Score for CVE-2022-22965 is currently at maximum 100. This is an exceptionally rare score, of which only 415 out of 184,000 CVEs (or 0.22 percent) have achieved, reflecting the severity and potential effects of this vulnerability. To get a risk score this high means it is a widely deployed technology with a public exploit available, and we have seen proof of an ongoing active internet breach using the vulnerability.
Kenna Risk Scores are continually reevaluated and may shift over time. An outline of the current risk score is below:
Cisco Talos is releasing coverage to protect users against the exploitation of two remote code execution vulnerabilities in Spring Framework. CVE-2022-22963 is a medium-severity bug th
Unit42
CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
blogs_unit42·2022-03-31·CVSS 9.8
CVE-2022-22965 [CRITICAL] CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
Threat Research Center
High Profile Threats
Vulnerabilities
## CVE-2022-22965: Spring Core Remote Code Execution Vulnerability Exploited In the Wild (SpringShell) (Updated)
Haozhe Zhang
Ken Hsu
Tao Yan
Qi Deng
Robert Falcone
Published: March 31, 2022
High Profile Threats
Vulnerabilities
CVE-2022-22963
CVE-2022-22965
Exploit in the wild
Remote Code Execution
SpringShell
## Executive Summary
Recently, two vulnerabilities were announced within the Spring Framework, an open-source framework for building enterprise Java applications. On March 29, 2022, the Spring Cloud Expression Resource Access Vulnerability tracked in CVE-2022-22963 was patched with the release of Spring Cloud Function 3.1.7 and 3.2.3. Two days later on March 31, 2022, Spring released version 5.3.18 and
Zscaler
Spring Cloud Framework Vulnerabilities | Zscaler Blog
blogs_zscaler·2022-03-31
Spring Cloud Framework Vulnerabilities | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Qualys
Spring Framework Zero-Day Remote Code Execution (Spring4Shell) Vulnerability | Qualys
blogs_qualys·2022-03-31
Spring Framework Zero-Day Remote Code Execution (Spring4Shell) Vulnerability | Qualys
#### Table of Contents
- What is Spring Framework?
- Which versions are vulnerable?
- How can this be exploited?
- What are the prerequisites to exploit this vulnerability?
- Is there a patch available for Spring4Shell?
- Qualys Coverage
- Discover Your Attack Surface with up-to-date CyberSecurity Asset Management
- Detect the Vulnerability with Qualys WAS
- Detect Spring4Shell Vulnerability Using Qualys VMDR
- Track Spring4Shell Progress with Unified Dashboard
- Detect Spring4Shell Vulnerabilities in Running Containers & Images
- Remediate Spring4Shell Using Qualys Patch Management
- FAQ:
- Updates
A new zero-day Remote Code Execution (RCE) vulnerability, “Spring4Shell” or “SpringShell” was disclosed in the Spring framework. An unauthorized attacker can exploit this vulnerability to rem
Tenable
Spring4Shell (CVE-2022-22965) FAQ: Spring Framework Remote Code Execution Vulnerability
blogs_tenable·2022-03-30·CVSS 9.8
[CRITICAL] Spring4Shell (CVE-2022-22965) FAQ: Spring Framework Remote Code Execution Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Elastic
Detection Engineering — Elastic Security Labs
blogs_elastic
Detection Engineering — Elastic Security Labs
## Topic
## Detection Engineering
## 24 February 2026
## Beyond Behaviors: AI-Augmented Detection Engineering with ES|QL COMPLETION
Learn how Elastic's ES|QL COMPLETION command brings LLM reasoning directly into detection rules, enabling detection engineers to build intelligent alert triage without external orchestration.
## The Engineer's Guide to Elastic Detections as Code
This post details the latest evolution of Elastic Security's Detections as Code (DaC) framework, including its development timeline, current feature highlights, and tailored implementation examples.
## Investigating a Mysteriously Malformed Authenticode Signature
An in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented kernel routines.
## Taking SHELLTE
Zscaler
ThreatLabz April 2022 Report: Conti attacks, BlackGuard sells, Spring springs a leak, and FFDroider gets social | CXO Revolutionaries
blogs_zscaler
ThreatLabz April 2022 Report: Conti attacks, BlackGuard sells, Spring springs a leak, and FFDroider gets social | CXO Revolutionaries
## ThreatLabz April 2022 Report: Conti attacks, BlackGuard sells, Spring springs a leak, and FFDroider gets social
Deepen Desai
Contributor
Zscaler
## Apr 26, 2022
Keep up with the resurrection of Conti ransomware attacks, BlackGuard, vulnerabilities in the Spring Cloud Framework, and the distribution of malware targeting social-media account credentials.
In the past month, the Zscaler ThreatLabZ security research team has documented a resurrection of Conti ransomware attacks , the arrival of a new info-stealer dubbed BlackGuard , the appearance of vulnerabilities in the Spring Cloud Framework , and the distribution of malware targeting social-media account credentials .
## Despite leak of its source code, Conti ransomware group continues attacks
In late February, a hacker released
Elastic
Detection Engineering — Elastic Security Labs
blogs_elastic
Detection Engineering — Elastic Security Labs
#### Topic
# Detection Engineering
Subscribe
#### 24 February 2026
## Beyond Behaviors: AI-Augmented Detection Engineering with ES|QL COMPLETION
Learn how Elastic's ES|QL COMPLETION command brings LLM reasoning directly into detection rules, enabling detection engineers to build intelligent alert triage without external orchestration.
4 February 2026The Engineer's Guide to Elastic Detections as CodeThis post details the latest evolution of Elastic Security's Detections as Code (DaC) framework, including its development timeline, current feature highlights, and tailored implementation examples.4 September 2025Investigating a Mysteriously Malformed Authenticode SignatureAn in-depth investigation tracing a Windows Authenticode validation failure from vague error codes to undocumented ke
Huntress
Spring4Shell (CVE-2022-22965) Vulnerability: Analysis, Impact, Mitigation | Huntress
blogs_huntress·CVSS 9.8
CVE-2022-22965 [CRITICAL] Spring4Shell (CVE-2022-22965) Vulnerability: Analysis, Impact, Mitigation | Huntress
## Spring4Shell (CVE-2022-22965) Vulnerability
Published: 10/07/2025
Written by: Monica Burgess
CVE-2022-22965, widely known as "Spring4Shell," is a critical remote code execution (RCE) vulnerability found in the popular Java Spring Framework. Think of it as an unlocked back door in certain web applications. This flaw allows an unauthenticated attacker to remotely execute malicious code on a target server, potentially giving them full control. Because the Spring Framework is so common in enterprise Java applications, this vulnerability sent shockwaves through the cybersecurity community, drawing comparisons to the infamous Log4Shell.
## When was it Discovered?
The Spring4Shell vulnerability first came to light in late March 2022. It was initially disclosed to VMware by a security rese
arXiv
Cybersecurity AI Benchmark (CAIBench): A Meta-Benchmark for Evaluating Cybersecurity AI Agents
arxiv_fulltext·2025-10-28
Cybersecurity AI Benchmark (CAIBench): A Meta-Benchmark for Evaluating Cybersecurity AI Agents
-1em
## Abstract
Cybersecurity spans multiple interconnected domains, complicating the development of meaningful, labor-relevant benchmarks. Existing benchmarks assess isolated skills rather than integrated performance. We find that pre-trained knowledge of cybersecurity in LLMs does not imply attack and defense abilities, revealing a gap between knowledge and capability. To address this limitation, we present the Cybersecurity AI Benchmark (CAIBench), a modular meta-benchmark framework that allows evaluating LLM models and agents across offensive and defensive cybersecurity domains, taking a step towards meaningfully measuring their labor-relevance. CAIBench integrates five evaluation categories, covering over 10,000 instances: Jeopardy-style CTFs, Attack and Defense CTFs, Cyber Range e
arXiv
xOffense: An AI-driven autonomous penetration testing framework with offensive knowledge-enhanced LLMs and multi agent systems
arxiv_fulltext·2025-09-16
xOffense: An AI-driven autonomous penetration testing framework with offensive knowledge-enhanced LLMs and multi agent systems
1
.001
xOffense: An AI-driven autonomous penetration testing framework with offensive knowledge-enhanced LLMs and multi agent systems
[1]organization=Information Security Lab, University of Information Technology,
city=Ho Chi Minh City,
country=Vietnam
[2]organization=Vietnam National University Ho Chi Minh City,
city=Ho Chi Minh City,
country=Vietnam
[1,2]Phung Duc Luong 0009-0004-6057-5313
[email protected]
[1,2]Le Tran Gia Bao 0009-0000-8911-5741
[email protected]
[1,2]Nguyen Vu Khai Tam
0009-0008-1715-4213
[email protected]
[1,2]Dong Huu Nguyen Khoa 0009-0005-9526-140X
[email protected]
[1,2]Nguyen Huu Quyen 0000-0002-0065-9919
[email protected]
[1,2]Van-Hau Pham 0000-0003-3147-3356
[email protected]
[1,2]Phan The Duy 0000-0002-5945-3712cor1
[email protected]
arXiv
Identifying Key Expert Actors in Cybercrime Forums Based on their Technical Expertise
arxiv_fulltext·2025-06-03
Identifying Key Expert Actors in Cybercrime Forums Based on their Technical Expertise
Identifying Key Expert Actors in Cybercrime Forums Based on their Technical ExpertiseStudy published in the 2024 APWG Symposium on Electronic Crime Research (eCrime) available at: www.doi.org/10.1109/eCrime66200.2024.00019
Estelle Ruellan
Université de Montréal
Flare
Canada
François Labrèche
Secureworks
Canada
Masarah Paquet-Clouston
Université de Montréal
Complexity Science Hub
Canada
Study published in the 2024 APWG Symposium on Electronic Crime Research (eCrime) available at: www.doi.org/10.1109/eCrime66200.2024.00019. © 2025 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective wor
arXiv
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
arxiv_fulltext·2025-02-16
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
VulRG: Multi-Level Explainable Vulnerability Patch Ranking for Complex Systems Using Graphs
Yuning Jiang
[email protected]
0000-0003-4791-8452
National University of Singapore
Singapore
Nay Oo
[email protected]
NCS Cyber Special Ops R&D
Singapore
Qiaoran Meng
[email protected]
National University of Singapore
Singapore
Hoon Wei Lim
[email protected]
NCS Cyber Special Ops R&D
Singapore
Biplab Sikdar
[email protected]
National University of Singapore
Singapore
Jiang et al.
## Abstract
As interconnected systems proliferate, safeguarding complex infrastructures against an escalating array of cyber threats has become an urgent challenge. The growing number of vulnerabilities, coupled with resource constraints, makes addressing every vulnerability impractical, thereby rende
CTF
Inject / README
ctf_writeups
Inject / README
# Inject
> Write-up author: jon-brandy
## STEPS:
> PORT SCANNING
```
┌──(brandy㉿bread-yolk)-[~]
└─$ nmap -p- -sVC 10.10.11.204 --min-rate 1000
Starting Nmap 7.93 ( https://nmap.org ) at 2023-09-26 04:39 PDT
Nmap scan report for inject.htb (10.10.11.204)
Host is up (0.065s latency).
Not shown: 65533 closed tcp ports (conn-refused)
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.2p1 Ubuntu 4ubuntu0.5 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 3072 caf10c515a596277f0a80c5c7c8ddaf8 (RSA)
| 256 d51c81c97b076b1cc1b429254b52219f (ECDSA)
|_ 256 db1d8ceb9472b0d3ed44b96c93a7f91d (ED25519)
8080/tcp open nagios-nsca Nagios NSCA
|_http-title: Home
Service Info: OS: Linux; CPE: cpe:/o:linux:linux_kernel
Service detection performed. Please report any incorrect results at https://nmap.org/subm
http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.htmlhttp://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdfhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005https://tanzu.vmware.com/security/cve-2022-22965https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttp://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.htmlhttp://packetstormsecurity.com/files/167011/Spring4Shell-Spring-Framework-Class-Property-Remote-Code-Execution.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-254054.pdfhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2022-0005https://tanzu.vmware.com/security/cve-2022-22965https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-java-spring-rce-Zx9GUc67https://www.kb.cert.org/vuls/id/970766https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-22965
2022-04-01
Published
2022-04-04
Added to CISA KEV
Exploited in the wild