CVE-2023-46747
published 2023-10-26CVE-2023-46747: Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2023-11-21
Exploited in the wild
EPSS
96.52%
99.9th percentile
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected
125 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| f5 | big-ip | >= 13.1.0 < * | * |
| f5 | big-ip | >= 14.1.0 < * | * |
| f5 | big-ip | >= 15.1.0 < * | * |
| f5 | big-ip | >= 16.1.0 < * | * |
| f5 | big-ip | >= 17.1.0 < * | * |
| f5 | big-ip_aam | — | — |
| f5 | big-ip_access_policy_manager | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_access_policy_manager | 14.1.0 – 14.1.5 | — |
| f5 | big-ip_access_policy_manager | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_access_policy_manager | 16.1.0 – 16.1.4 | — |
| f5 | big-ip_access_policy_manager | 17.1.0 – 17.1.1 | — |
| f5 | big-ip_advanced_firewall_manager | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_advanced_firewall_manager | 14.1.0 – 14.1.5 | — |
| f5 | big-ip_advanced_firewall_manager | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_advanced_firewall_manager | 16.1.0 – 16.1.4 | — |
| f5 | big-ip_advanced_firewall_manager | 17.1.0 – 17.1.1 | — |
| f5 | big-ip_advanced_waf | — | — |
| f5 | big-ip_advanced_web_application_firewall | 13.1.0 – 13.1.5 | — |
| f5 | big-ip_advanced_web_application_firewall | 14.1.0 – 14.1.5 | — |
| f5 | big-ip_advanced_web_application_firewall | 15.1.0 – 15.1.10 | — |
| f5 | big-ip_advanced_web_application_firewall | 16.1.0 – 16.1.4 | — |
| f5 | big-ip_advanced_web_application_firewall | 17.1.0 – 17.1.1 | — |
| f5 | big-ip_afm | — | — |
| f5 | big-ip_analytics | — | — |
| f5 | big-ip_analytics | 13.1.0 – 13.1.5 | — |
Detection & IOCsextracted from sources · hover to see the quote
otherjava.sql.SQLException: Column not found: 0. {...) sh: no job control in this shell sh-4.2$ sh-4.2$ exit↗
- →CVE-2023-46747 is an authentication bypass in the BIG-IP Configuration utility (TMUI) exploitable via the management port and/or self IP addresses without authentication; attackers chained it with CVE-2023-46748 (SQL injection) to execute arbitrary system commands. ↗
- →F5 observed threat actors using CVE-2023-46747 and CVE-2023-46748 in combination; applying the mitigation for CVE-2023-46747 is sufficient to stop most chained attacks. ↗
- →Attackers actively erase forensic traces on compromised BIG-IP devices; absence of IOCs does not confirm a clean system — treat unpatched devices as compromised. ↗
- →CVE-2023-46747 post-exploitation has been associated with the Supershell C2 framework (reverse SSH shell over web services); look for outbound SSH-over-HTTP/HTTPS connections from BIG-IP management interfaces. ↗
- →Monitor BIG-IP logs for SQL injection artefacts in /var/log/tomcat/catalina.out indicating chained exploitation: look for 'Column not found: 0' followed by shell spawn strings 'sh: no job control in this shell'. ↗
- ·CVE-2023-46747 is exploitable via the management port AND/OR self IP addresses; restricting access to the Configuration utility from both vectors is required to reduce attack surface. ↗
- ·Not all exploited BIG-IP systems will display the same IOCs; a skilled attacker may remove all traces, so absence of evidence is not evidence of absence of compromise. ↗
- ·Software versions that have reached End of Technical Support (EoTS) are not evaluated for CVE-2023-46747; organizations on EoTS versions have no vendor-provided fix path. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
cisa·2023-10-31·CVSS 9.8
CVE-2023-46747 [CRITICAL] CWE-288 F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
Vulnerability: F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
Affected: F5 BIG-IP Configuration Utility
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://my.f5.com/manage/s/article/K000137353; https://nvd.nist.gov/vuln/detail/CVE-2023-46747
Remediation Due Date: 2023-11-21
CISA
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
cisa·2023-10-31·CVSS 9.8
CVE-2023-46748 [CRITICAL] CWE-89 F5 BIG-IP Configuration Utility SQL Injection Vulnerability
Vulnerability: F5 BIG-IP Configuration Utility SQL Injection Vulnerability
Affected: F5 BIG-IP Configuration Utility
F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://my.f5.com/manage/s/article/K000137365 ; https://nvd.nist.gov/vuln/detail/CVE-2023-46748
Remediation Due Date: 2023-11-21
F5
CVE-2023-46747: Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the...
vendor_f5·2023-10-26·CVSS 9.8
CVE-2023-46747 [CRITICAL] CWE-288 CVE-2023-46747: Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the...
CVE-2023-46747: Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the...
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Affected Products: BIG-IP AAM, BIG-IP AFM, BIG-IP APM, BIG-IP ASM, BIG-IP AVR, BIG-IP Advanced WAF, BIG-IP Analytics, BIG-IP CGNAT, BIG-IP DHD, BIG-IP DNS, BIG-IP GTM, BIG-IP LTM, BIG-IP Link Controller, BIG-IP PEM, BIG-IP SSLO, BIG-IP WebAccelerator, BIG-IP WebSafe, Big-Ip Automation Toolchain, Big-Ip Container Ingress Services, Big-Ip Fraud
GHSA
GHSA-pq6p-fc96-wc5w: Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the manage
ghsa_unreviewed·2023-10-26
CVE-2023-46747 [CRITICAL] CWE-288 GHSA-pq6p-fc96-wc5w: Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the manage
Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
VulnCheck
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-46748 [CRITICAL] CWE-89 F5 BIG-IP Configuration Utility SQL Injection Vulnerability
F5 BIG-IP Configuration Utility SQL Injection Vulnerability
F5 BIG-IP Configuration utility contains an SQL injection vulnerability that may allow an authenticated attacker with network access through the BIG-IP management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46747.
Affected: F5 BIG-IP Configuration Utility
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://my.f5.com/manage/s/article/K000137353; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://cyble.com/blog/active-exploitation-of-big-ip-and-citrix-vulnerabilities-observed-by-cyble-global-sensor-intelligence
VulnCheck
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
vulncheck·2023·CVSS 9.8
CVE-2023-46747 [CRITICAL] CWE-288 F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
F5 BIG-IP Configuration Utility Authentication Bypass Vulnerability
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute system commands. This vulnerability can be used in conjunction with CVE-2023-46748.
Affected: F5 BIG-IP Configuration Utility
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://cyble.com/blog/active-exploita
Suricata
ET EXPLOIT F5 BIG-IP - Successful Password Reset Attempt - Observed Post CVE-2023-46747 Activity
suricata·2023-11-20·CVSS 9.8
CVE-2023-46747 [CRITICAL] ET EXPLOIT F5 BIG-IP - Successful Password Reset Attempt - Observed Post CVE-2023-46747 Activity
ET EXPLOIT F5 BIG-IP - Successful Password Reset Attempt - Observed Post CVE-2023-46747 Activity
Rule: alert http $HOME_NET any -> any any (msg:"ET EXPLOIT F5 BIG-IP - Successful Password Reset Attempt - Observed Post CVE-2023-46747 Activity"; flow:established,to_client; flowbits:isset,ET.CVE-2023-46747.pw.request; http.stat_code; content:"200"; http.response_body; content:"/mgmt/tm/auth/user/"; content:"|22|description|22|"; content:"|22|encryptedPassword|22|"; content:"|22|role|22|"; reference:url,packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.html; classtype:successful-admin; sid:2049258; rev:3; metadata:attack_target Networking_Equipment, created_at 2023_11_20, deployment Perimeter, deployment SSLDecrypt, performance_impact Low, confidence H
Suricata
ET EXPLOIT F5 BIG-IP - Password Reset Attempt - Observed Post CVE-2023-46747 Activity
suricata·2023-11-20·CVSS 9.8
CVE-2023-46747 [CRITICAL] ET EXPLOIT F5 BIG-IP - Password Reset Attempt - Observed Post CVE-2023-46747 Activity
ET EXPLOIT F5 BIG-IP - Password Reset Attempt - Observed Post CVE-2023-46747 Activity
Rule: alert http any any -> $HOME_NET any (msg:"ET EXPLOIT F5 BIG-IP - Password Reset Attempt - Observed Post CVE-2023-46747 Activity"; flow:established,to_server; flowbits:set,ET.CVE-2023-46747.pw.request; http.method; content:"PATCH"; http.uri; content:"/mgmt/tm/auth/user/"; startswith; fast_pattern; http.request_body; content:"|22|password|22|"; reference:url,packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.html; classtype:attempted-admin; sid:2049257; rev:3; metadata:affected_product F5, attack_target Networking_Equipment, created_at 2023_11_20, deployment Perimeter, deployment SSLDecrypt, former_category INFO, performance_impact Low, confidence High, signatu
Suricata
ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request - User Creation (CVE-2023-46747)
suricata·2023-11-03·CVSS 9.8
CVE-2023-46747 [CRITICAL] ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request - User Creation (CVE-2023-46747)
ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request - User Creation (CVE-2023-46747)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request - User Creation (CVE-2023-46747)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/tmui/"; startswith; http.request_body; content:"|00 08|HTTP"; isdataat:!518,relative; content:"|00 12|/tmui/Control/form|00|"; nocase; distance:0; content:"form|5f|page|3d 25|2Ftmui|25|2Fsystem|25|2Fuser|25|2Fcreate|2e|jsp"; fast_pattern; distance:0; nocase; reference:url,my.f5.com/manage/s/article/K000137353; reference:url,www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/; reference:cve,2023-46747; class
Suricata
ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request (CVE-2023-46747)
suricata·2023-11-03·CVSS 9.8
CVE-2023-46747 [CRITICAL] ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request (CVE-2023-46747)
ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request (CVE-2023-46747)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request (CVE-2023-46747)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/tmui/"; startswith; fast_pattern; http.request_body; content:"|00 08|HTTP"; isdataat:!518,relative; content:"/tmui/"; nocase; distance:0; reference:url,my.f5.com/manage/s/article/K000137353; reference:url,www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/; reference:cve,2023-46747; classtype:attempted-admin; sid:2049057; rev:5; metadata:attack_target Networking_Equipment, created_at 2023_11_03, cve CVE_2023_46747, deployment Perimeter, d
Suricata
ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request - User Deletion (CVE-2023-46747)
suricata·2023-11-03·CVSS 9.8
CVE-2023-46747 [CRITICAL] ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request - User Deletion (CVE-2023-46747)
ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request - User Deletion (CVE-2023-46747)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET EXPLOIT F5 BIG-IP - Unauthenticated RCE via AJP Smuggling Request - User Deletion (CVE-2023-46747)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/tmui/"; startswith; http.request_body; content:"|00 08|HTTP"; isdataat:!514,relative; content:"|00 12|/tmui/Control/form|00|"; nocase; distance:0; content:"form|5f|page|3d 25|2Ftmui|25|2Fsystem|25|2Fuser|25|2Flist|2e|jsp"; fast_pattern; nocase; distance:0; content:"delete|5f|confirm|3d|Delete"; nocase; distance:0; reference:url,my.f5.com/manage/s/article/K000137353; reference:url,www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-s
Suricata
ET WEB_SPECIFIC_APPS Possible F5 BIG-IP AJP Request Smuggling Attempt (CVE-2023-46747)
suricata·2023-10-27·CVSS 9.8
CVE-2023-46747 [CRITICAL] ET WEB_SPECIFIC_APPS Possible F5 BIG-IP AJP Request Smuggling Attempt (CVE-2023-46747)
ET WEB_SPECIFIC_APPS Possible F5 BIG-IP AJP Request Smuggling Attempt (CVE-2023-46747)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Possible F5 BIG-IP AJP Request Smuggling Attempt (CVE-2023-46747)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/tmui"; http.request_header; header_lowercase; content:"transfer-encoding|3a 20|chunked|2c 20|chunked"; fast_pattern; startswith; reference:url,www.praetorian.com/blog/refresh-compromising-f5-big-ip-with-request-smuggling-cve-2023-46747/; reference:cve,2023-46747; classtype:web-application-attack; sid:2048925; rev:2; metadata:affected_product F5, attack_target Networking_Equipment, created_at 2023_10_27, cve CVE_2023_46747, deployment Perimeter, deployment Internal, deployment SSLDecrypt, perfo
Metasploit
F5 BIG-IP TMUI AJP Smuggling RCE
metasploit
F5 BIG-IP TMUI AJP Smuggling RCE
F5 BIG-IP TMUI AJP Smuggling RCE
This module exploits a flaw in F5's BIG-IP Traffic Management User Interface (TMUI) that enables an external, unauthenticated attacker to create an administrative user. Once the user is created, the module uses the new account to execute a command payload. Both the exploit and check methods automatically delete any temporary accounts that are created.
Nuclei
F5 BIG-IP - Unauthenticated RCE via AJP Smuggling
nuclei·CVSS 9.8
CVE-2023-46747 [CRITICAL] F5 BIG-IP - Unauthenticated RCE via AJP Smuggling
F5 BIG-IP - Unauthenticated RCE via AJP Smuggling
CVE-2023-46747 is a critical severity authentication bypass vulnerability in F5 BIG-IP that could allow an unauthenticated attacker to achieve remote code execution (RCE). The vulnerability impacts the BIG-IP Configuration utility, also known as the TMUI, wherein arbitrary requests can bypass authentication. The vulnerability received a CVSSv3 score of 9.8.
Template:
id: CVE-2023-46747
info:
name: F5 BIG-IP - Unauthenticated RCE via AJP Smuggling
author: iamnoooob,rootxharsh,pdresearch
severity: critical
description: |
CVE-2023-46747 is a critical severity authentication bypass vulnerability in F5 BIG-IP that could allow an unauthenticated attacker to achieve remote code execution (RCE). The vulnerability impacts the BIG-IP Configuratio
Recorded Future
June 2026 CVE Landscape
blogs_recorded_future·2026-07-10·CVSS 9.1
CVE-2026-35616 [CRITICAL] June 2026 CVE Landscape
## June 2026 CVE Landscape
In June 2026, Insikt Group® identified 60 high-impact vulnerabilities that should be prioritized for remediation , 30 of which had a Very Critical Recorded Future Risk Score. This represents a 49% increase from last month. 23 of the 60 vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 34 were reported by vendors, and three were primarily surfaced through honeypot data.
The 60 vulnerabilities in this report affected products from 36 vendors, with Microsoft accounting for approximately 18% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform
Hackernews
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
blogs_hackernews·2026-06-26·CVSS 9.8
CVE-2021-26855 [CRITICAL] New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts.
Kaspersky, which is tracking the activity under the moniker StrikeShark , said the campaign has targeted a diplomatic organization in Indonesia, government organizations in Taiwan, software development companies across multiple countries, and entities associated with other sectors located in Hong Kong, Lebanon, Syria, Colombia, North Macedonia, Ne
Securelist
StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
blogs_securelist·2026-06-24
CVE-2021-26855 StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
Fareed Radzi
Table of Contents
Introduction
Initial infection
Exploitation of public-facing applications
Dropper-based distribution
SharkLoader installation
SharkLoader DLL – Main implant
“PerfectDLL Hijacking” technique
Decryption and loading of >DscCoreR.mui
DscCoreR.mui and SyncRes.dat DLLs
Decryption and loading of SyncRes.dat
SyncRes.dat decrypted DLL: Multiple API hooks
VEH registration and access violation handling
Thread creation for Cobalt Strike Beacon execution
MinHook DLL, API hooking, and Cobalt Strike beacon
Persistence mechanism
Post-compromise activity
Victimology
Attribution
Conclusion
Indicators of compromise
Authors
Fareed Radzi
## Introduction
During our research of activity affecting a diplomatic organization in Indonesia, we uncovered a previo
Unit42
Exploitation of Critical Vulnerability in React Server Components (Updated December 12)
blogs_unit42·2025-12-12·CVSS 10.0
CVE-2025-55182 [CRITICAL] Exploitation of Critical Vulnerability in React Server Components (Updated December 12)
Threat Research Center
High Profile Threats
Vulnerabilities
## Exploitation of Critical Vulnerability in React Server Components (Updated December 12)
Justin Moore
Published: December 12, 2025
High Profile Threats
Vulnerabilities
Cobalt Strike
CVE-2025-55182
CVE-2025-66478
Remote Code Execution
Web shells
## Executive Summary
Unit 42 stopped monitoring this threat and updating the brief on Jan. 30, 2025. Please refer to Vercel's website for the latest information.
## Update Dec. 12, 2025
Unit 42 uncovered the previously unseen KSwapDoor. This Linux backdoor was initially mistaken for BPFDoor.
Key features include:
P2P mesh network: Enables multi-hop routing for robust C2 communications
Strong encryption: Uses AES-256-CFB with Diffie-Hellman key exchange
Stealth an
Unit42
Exploitation of Critical Vulnerability in React Server Components (Updated December 12)
blogs_unit42·2025-12-12·CVSS 10.0
CVE-2025-55182 [CRITICAL] Exploitation of Critical Vulnerability in React Server Components (Updated December 12)
## Executive Summary
Unit 42 stopped monitoring this threat and updating the brief on Jan. 30, 2025. Please refer to Vercel's website for the latest information.
### Update Dec. 12, 2025
Unit 42 uncovered the previously unseen KSwapDoor. This Linux backdoor was initially mistaken for BPFDoor.
Key features include:
- P2P mesh network: Enables multi-hop routing for robust C2 communications
- Strong encryption: Uses AES-256-CFB with Diffie-Hellman key exchange
- Stealth and persistence: Mimics a legitimate Linux kernel swap daemon
- Full remote access: Offers an interactive shell, command execution, file operations and lateral movement scanning
### Update Dec. 9, 2025
Unit 42 has identified activity that reportedly shares overlap with North Korean (DPRK) Contagious Interview tooling, t
Wiz
Gogs Zero-Day RCE (CVE-2025-8110) Actively Exploited | Wiz Blog
blogs_wiz·2025-12-10·CVSS 8.7
CVE-2025-8110 [HIGH] Gogs Zero-Day RCE (CVE-2025-8110) Actively Exploited | Wiz Blog
# Executive Summary
- While investigating a malware infection on a customer workload, Wiz Research discovered an active zero-day vulnerability in Gogs, a popular self-hosted Git service.
- A symlink bypass (CVE-2025-8110) of a previously patched RCE (CVE-2024-55947) allows authenticated users to overwrite files outside the repository, leading to Remote Code Execution (RCE).
- We identified over 700 compromised instances public-facing on the internet.
- Update: As of January 23, 2026, a fix has been issued in version v0.13.4.
# Introduction
On July 10th, the Wiz Threat Research team observed malware findings on public-facing instances of Gogs, a popular self-hosted Git service. What began as a routine investigation into an infected machine turned into the accidental discovery of a live z
Wiz
Gogs Zero-Day RCE (CVE-2025-8110) Actively Exploited | Wiz Blog
blogs_wiz·2025-12-10·CVSS 8.7
CVE-2025-8110 [HIGH] Gogs Zero-Day RCE (CVE-2025-8110) Actively Exploited | Wiz Blog
## Executive Summary
While investigating a malware infection on a customer workload, Wiz Research discovered an active zero-day vulnerability in Gogs, a popular self-hosted Git service.
A symlink bypass (CVE-2025-8110) of a previously patched RCE (CVE-2024-55947) allows authenticated users to overwrite files outside the repository, leading to Remote Code Execution (RCE).
We identified over 700 compromised instances public-facing on the internet.
Update: As of January 23, 2026, a fix has been issued in version v0.13.4.
## Introduction
On July 10th, the Wiz Threat Research team observed malware findings on public-facing instances of Gogs, a popular self-hosted Git service. What began as a routine investigation into an infected machine turned into the accidental discovery of a live zero
Bleepingcomputer
CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
blogs_bleepingcomputer·2025-10-30·CVSS 7.8
CVE-2025-41244 [HIGH] CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
## CISA orders feds to patch VMware Tools flaw exploited by Chinese hackers
## Sergiu Gatlan
On Thursday, CISA warned U.S. government agencies to secure their systems against attacks exploiting a high-severity vulnerability in Broadcom's VMware Aria Operations and VMware Tools software.
Tracked as CVE-2025-41244 and patched one month ago , this vulnerability allows local attackers with non-administrative privileges to a virtual machine (VM) with VMware Tools and managed by Aria Operations with SDMP enabled to escalate privileges to root on the same VM.
CISA added the flaw to its Known Exploited Vulnerabilities catalog , which lists security bugs the cybersecurity agency has flagged as exploited in the wild. Federal Civilian Executive Branch (FCEB) agencies now have three weeks, until N
Unit42
Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
blogs_unit42·2025-10-16·CVSS 8.5
CVE-2025-53868 [HIGH] Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
Justin Moore
Published: October 16, 2025
High Profile Threats
Vulnerabilities
CVE-2025-53868
CVE-2025-57780
CVE-2025-61955
Exfiltration
## Executive Summary
On Oct. 15, 2025, F5 — a U.S. technology company — disclosed that a nation-state threat actor conducted a significant long-term compromise of their corporate networks. In this incident, attackers stole source code from their BIG-IP suite of products and information about undisclosed vulnerabilities. F5’s BIG-IP suite is commonly used by large organizations, primarily in the U.S. but also globally, for availability, access control and security. Organizations including gove
Unit42
Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
blogs_unit42·2025-10-16·CVSS 8.5
[HIGH] Threat Brief: Nation-State Actor Steals F5 Source Code and Undisclosed Vulnerabilities
## Executive Summary
On Oct. 15, 2025, F5 — a U.S. technology company — disclosed that a nation-state threat actor conducted a significant long-term compromise of their corporate networks. In this incident, attackers stole source code from their BIG-IP suite of products and information about undisclosed vulnerabilities. F5’s BIG-IP suite is commonly used by large organizations, primarily in the U.S. but also globally, for availability, access control and security. Organizations including government agencies and Fortune 500 companies rely on BIG-IP.
Cortex Xpanse currently identifies over 600,000 unique hosts behind a Big-IP instance exposed to the internet.
F5’s investigation revealed that the attackers maintained long-term access to the company’s product development environment and eng
Bleepingcomputer
Chinese hackers exploiting VMware zero-day since October 2024
blogs_bleepingcomputer·2025-09-30·CVSS 9.8
CVE-2025-41244 [CRITICAL] Chinese hackers exploiting VMware zero-day since October 2024
## Chinese hackers exploiting VMware zero-day since October 2024
## Sergiu Gatlan
Broadcom has patched a high-severity privilege escalation vulnerability in its VMware Aria Operations and VMware Tools software, which has been exploited in zero-day attacks since October 2024.
While the American technology giant didn't tag this security bug ( CVE-2025-41244 ) as exploited in the wild, it thanked NVISO threat researcher Maxime Thiebaut for reporting the bug in May.
However, yesterday, the European cybersecurity company disclosed that this vulnerability was first exploited in the wild beginning mid-October 2024 and linked the attacks to the UNC5174 Chinese state-sponsored threat actor.
"To abuse this vulnerability, an unprivileged local attacker can stage a malicious binary within any of
Sentinelone
Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets
blogs_sentinelone·2025-06-09
Follow the Smoke | China-nexus Threat Actors Hammer At the Doors of Top Tier Targets
## Executive Summary
- In October 2024, SentinelLABS observed and countered a reconnaissance operation targeting SentinelOne, which we track as part of a broader activity cluster named PurpleHaze.
- At the beginning of 2025, we also identified and helped disrupt an intrusion linked to a wider ShadowPad operation. The affected organization was responsible for managing hardware logistics for SentinelOne employees at the time.
- A thorough investigation of SentinelOne’s infrastructure, software, and hardware assets confirmed that the attackers were unsuccessful and SentinelOne was not compromised by any of these activities.
- The PurpleHaze and ShadowPad activity clusters span multiple partially related intrusions into different targets occurring between July 2024 and March 2025. The victimo
Sentinelone
RansomHub
blogs_sentinelone·2025-01-08
RansomHub
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Tenable
Cybersecurity Snapshot: RansomHub Group Triggers CISA Warning, While FBI Says North Korean Hackers Are Targeting Crypto Orgs
blogs_tenable·2024-09-06
Cybersecurity Snapshot: RansomHub Group Triggers CISA Warning, While FBI Says North Korean Hackers Are Targeting Crypto Orgs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2024-21793, CVE-2024-26026: Proof of Concept Available for F5 BIG-IP Next Central Manager Vulnerabilities
blogs_tenable·2024-05-09·CVSS 7.5
[HIGH] CVE-2024-21793, CVE-2024-26026: Proof of Concept Available for F5 BIG-IP Next Central Manager Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
New BIG-IP Next Central Manager bugs allow device takeover
blogs_bleepingcomputer·2024-05-08·CVSS 7.5
CVE-2024-26026 [HIGH] New BIG-IP Next Central Manager bugs allow device takeover
## New BIG-IP Next Central Manager bugs allow device takeover
## Sergiu Gatlan
F5 has fixed two high-severity BIG-IP Next Central Manager vulnerabilities, which can be exploited to gain admin control and create hidden rogue accounts on any managed assets.
Next Central Manager allows administrators to control on-premises or cloud BIG-IP Next instances and services via a unified management user interface.
The flaws are an SQL injection vulnerability ( CVE-2024-26026 ) and an OData injection vulnerability ( CVE-2024-21793 ) found in the BIG-IP Next Central Manager API that would allow unauthenticated attackers to execute malicious SQL statements on unpatched devices remotely.
SQL injection attacks involve injecting malicious SQL queries into input fields or parameters in database queries
Bleepingcomputer
Hackers exploit recent F5 BIG-IP flaws in stealthy attacks
blogs_bleepingcomputer·2023-11-01·CVSS 9.8
[CRITICAL] Hackers exploit recent F5 BIG-IP flaws in stealthy attacks
## Hackers exploit recent F5 BIG-IP flaws in stealthy attacks
## Bill Toulas
F5 is warning BIG-IP admins that devices are being breached by "skilled" hackers exploiting two recently disclosed vulnerabilities to erase signs of their access and achieve stealthy code execution.
F5 BIG-IP is a suite of products and services offering load balancing, security, and performance management for networked applications. The platform has been widely adopted by large enterprises and government organizations, making any flaws in the product a significant concern.
Last week, F5 urged admins to apply available security updates for two newly discovered vulnerabilities:
CVE-2023-46747 – Critical (CVSS v3.1 score: 9.8) authentication bypass flaw allowing an attacker to access the Configuration utility an
Checkpoint
30th October – Threat Intelligence Report
blogs_checkpoint·2023-10-30
CVE-2023-32434 30th October – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 30th October – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 30th October, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Stanford University has been a victim of cyber-attack that affected the systems of its Department of Public Safety (SUDPS). Akira ransomware gang claimed responsibility for the attack, which allegedly resulted in the exposure of 430GB of university’s data.
Check Point Harmony End Point and Threat Emulation provides prote
Tenable
CVE-2023-46747: Critical Authentication Bypass Vulnerability in F5 BIG-IP
blogs_tenable·2023-10-27·CVSS 9.8
[CRITICAL] CVE-2023-46747: Critical Authentication Bypass Vulnerability in F5 BIG-IP
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
F5 fixes BIG-IP auth bypass allowing remote code execution attacks
blogs_bleepingcomputer·2023-10-27·CVSS 9.8
CVE-2023-46747 [CRITICAL] F5 fixes BIG-IP auth bypass allowing remote code execution attacks
## F5 fixes BIG-IP auth bypass allowing remote code execution attacks
## Bill Toulas
A critical vulnerability in the F5 BIG-IP configuration utility, tracked as CVE-2023-46747, allows an attacker with remote access to the configuration utility to perform unauthenticated remote code execution.
The flaw has received a CVSS v3.1 score of 9.8, rating it "critical," as it can be exploited without authentication in low-complexity attacks.
"This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands," reads F5's security bulletin .
Threat actors can only exploit devices that have the Traffic Management User Interface (TMUI) exposed to the internet and do not affect
Sentinelone
RansomHub
blogs_sentinelone
RansomHub
## RansomHub Ransomware: In-Depth Analysis, Detection, and Mitigation
## What Is RansomHub Ransomware?
RansomHub operations were first observed in February of 2024. Since then, the group has drawn heavily upon its ability to recruit and attract operators from other, sometimes imploding, extortion operations. Upon the collapse of ALPHV, for example, multiple affiliates migrated to RansomHub, hoping to monetize their stolen data through them. RansomHub has been associated with the re-extortion of ransomware victims, including high-value healthcare organizations. Primary operators behind RansomHub have openly recruited affiliates from other ransomware operations via their various communication channels, including DLS sites, forum posts, and Telegram.
Operating primarily as a Ransomware-as-
Crowdstrike
Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Unveiling WARP PANDA: A New Sophisticated China-Nexus Adversary
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
http://packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.htmlhttps://my.f5.com/manage/s/article/K000137353https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/http://packetstormsecurity.com/files/175673/F5-BIG-IP-TMUI-AJP-Smuggling-Remote-Command-Execution.htmlhttps://my.f5.com/manage/s/article/K000137353https://www.secpod.com/blog/f5-issues-warning-big-ip-vulnerability-used-in-active-exploit-chain/https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46747
2023-10-26
Published
2023-10-31
Added to CISA KEV
Exploited in the wild