Over 2.5 Million Malicious Requests Target Adobe ColdFusion Servers
ID: 13ed8a68-17bb-5d1f-a714-5f5c8ed2c0f1
STIX ID: report--13ed8a68-17bb-5d1f-a714-5f5c8ed2c0f1
Feed Name: Cyber Press
A coordinated exploitation campaign over the Christmas 2025 holiday targeted Adobe ColdFusion servers using JNDI/LDAP WDDX deserialization and a com.sun.rowset.JdbcRowSetImpl gadget chain to trigger RCE; two primary IPs (134.122.136.119 and 134.122.136.96) launched thousands of requests and used Interactsh callbacks to confirm successful exploitation across 20 countries, while the broader operation generated ~2.5 million requests against 767 CVEs and likely serves as an initial access brokerage effort—organisations should patch listed CVEs, monitor/block Interactsh domains, and block identified IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
