Critical Wazuh bug exploited in growing Mirai botnet infection
ID: 40a9190d-0d9c-5b98-bc4d-16316aba3507
STIX ID: report--40a9190d-0d9c-5b98-bc4d-16316aba3507
Feed Name: The Register (Security)
Threat Score
Researchers observed active exploitation of a critical Wazuh RCE (CVE-2025-24016, 9.9) being used to deploy Mirai variants and the Resbot botnet; attackers leveraged publicly shared PoC code and targeted IoT devices and legacy router vulnerabilities. The campaigns have been observed in the wild by Akamai and Kaspersky, and Wazuh released a patch in October 2024 (4.9.1) — upgrading to patched versions will mitigate the attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
