Cryptojacking, backdoors abound as fiends abuse Aviatrix Controller bug
ID: bb6dd38e-4b11-5b26-a8db-0668383aab11
STIX ID: report--bb6dd38e-4b11-5b26-a8db-0668383aab11
Feed Name: The Register (Security)
A critical RCE in Aviatrix Controller (CVE-2024-50603) has been publicly disclosed and quickly weaponized: researchers observed exploitation between Jan 7–10 leading to deployment of Silver backdoors and XMRig cryptojacking. Default/high IAM privileges for many Aviatrix deployments create strong lateral-movement and privilege-escalation risk; ~681 controllers were publicly exposed per a Shodan scan. Patches and updated versions (7.2.4996 and CoPilot 4.16.1+) are available, and defenders are advised to patch and remove public access on port 443 where possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
