Laravel Livewire Applications Compromised to Steal Credentials Exploiting RCE Vulnerability
ID: 0a8bf8ed-40db-591e-9e07-c3df82a4f546
STIX ID: report--0a8bf8ed-40db-591e-9e07-c3df82a4f546
Feed Name: cybersecurityNews.com
A widespread campaign exploited a critical deserialization-based RCE in Laravel Livewire (v3 ≤ 3.6.3, CVE-2025-54068) to run remote commands and deploy a credential-stealing Bash script named “shoc.enz.” Researchers observed mass scanning and exploitation leading to exfiltration of secrets from 6,167 applications (including 14,000+ database passwords, AWS credentials, and payment keys) via FTP, Telegram, and GoFile; the activity is linked to an Indonesian-origin actor. Organizations are advised to upgrade to Livewire 3.6.4+, restrict outbound connections, monitor abnormal API traffic, and rotate compromised credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
