logo

Bug affecting PHP scripts demands ‘immediate action from defenders globally’

ID: 89aebe23-0c61-5ee9-93ed-cbc9b0941043

STIX ID: report--89aebe23-0c61-5ee9-93ed-cbc9b0941043

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2025-03-07

Date Updated: 2026-05-01

...
...

Researchers report mass exploitation of CVE-2024-4577, a critical PHP-CGI remote code execution vulnerability: initially observed targeting Japanese organizations, activity has expanded globally (notable spikes in the U.S., Singapore, and Japan). Cisco Talos observed attackers deploying a C2 infrastructure and tools to steal credentials and maintain persistence, GreyNoise documented widespread scanning/exploitation patterns, and Symantec reported earlier exploitation against a Taiwanese university; a patch exists but exploitation continues, prompting urgent defensive action.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.