Attackers snooping around Sitecore, dropping malware via public sample keys
ID: 2397bc88-e5b2-5625-bbee-481ff641cb0e
STIX ID: report--2397bc88-e5b2-5625-bbee-481ff641cb0e
Feed Name: The Register (Security)
Multiple Sitecore products are potentially impacted by CVE-2025-53690 — a ViewState deserialization/configuration issue where publicly documented machine keys enabled remote code execution. Attackers exploited exposed instances to deploy WEEPSTEEL (information-gathering malware), archive web application files (likely to obtain web.config), escalate privileges, and attempt lateral movement; Mandiant disrupted the attack and CISA added the CVE to its Known Exploited Vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
