Hackers Exploiting PHP Vulnerability To Launch DDoS Attacks
ID: 22dfb9d7-5f47-5ab1-a1ac-e6486a1dad48
STIX ID: report--22dfb9d7-5f47-5ab1-a1ac-e6486a1dad48
Feed Name: Cyber Press
Threat Score
A critical PHP CGI vulnerability (CVE-2024-4577) affecting PHP 8.1–8.3 allows RCE via a Unicode soft-hyphen parsing bypass; attackers exploited it within 24 hours to deliver Gh0st RAT, RedTail cryptominer and other malware through crafted POST requests to php-cgi endpoints, with observed C2 infrastructure and download scripts used in multiple campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
