logo

Hackers Exploiting PHP Vulnerability To Launch DDoS Attacks

ID: 22dfb9d7-5f47-5ab1-a1ac-e6486a1dad48

STIX ID: report--22dfb9d7-5f47-5ab1-a1ac-e6486a1dad48

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2024-07-11

Date Updated: 2026-04-19

Author: Kaaviya

...
...

A critical PHP CGI vulnerability (CVE-2024-4577) affecting PHP 8.1–8.3 allows RCE via a Unicode soft-hyphen parsing bypass; attackers exploited it within 24 hours to deliver Gh0st RAT, RedTail cryptominer and other malware through crafted POST requests to php-cgi endpoints, with observed C2 infrastructure and download scripts used in multiple campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.