logo

Attackers snooping around Sitecore, dropping malware via public sample keys

ID: 2397bc88-e5b2-5625-bbee-481ff641cb0e

STIX ID: report--2397bc88-e5b2-5625-bbee-481ff641cb0e

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-09-04

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Multiple Sitecore products are potentially impacted by CVE-2025-53690 — a ViewState deserialization/configuration issue where publicly documented machine keys enabled remote code execution. Attackers exploited exposed instances to deploy WEEPSTEEL (information-gathering malware), archive web application files (likely to obtain web.config), escalate privileges, and attempt lateral movement; Mandiant disrupted the attack and CISA added the CVE to its Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.