logo

Laravel Livewire Applications Compromised to Steal Credentials Exploiting RCE Vulnerability

ID: 0a8bf8ed-40db-591e-9e07-c3df82a4f546

STIX ID: report--0a8bf8ed-40db-591e-9e07-c3df82a4f546

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: Abinaya

...
...

A widespread campaign exploited a critical deserialization-based RCE in Laravel Livewire (v3 ≤ 3.6.3, CVE-2025-54068) to run remote commands and deploy a credential-stealing Bash script named “shoc.enz.” Researchers observed mass scanning and exploitation leading to exfiltration of secrets from 6,167 applications (including 14,000+ database passwords, AWS credentials, and payment keys) via FTP, Telegram, and GoFile; the activity is linked to an Indonesian-origin actor. Organizations are advised to upgrade to Livewire 3.6.4+, restrict outbound connections, monitor abnormal API traffic, and rotate compromised credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.