Patch it up: Old vulnerabilities are everyone’s problems
ID: 15a5a3e3-330f-53b2-923e-94beecece7a5
STIX ID: report--15a5a3e3-330f-53b2-923e-94beecece7a5
Feed Name: Cisco Talos
Threat Score
Cisco Talos reports an ongoing intrusion campaign (active since at least January 2025) targeting organizations in Japan that exploited CVE-2024-4577 (PHP-CGI RCE on Windows) to gain initial access and persist using registry changes, scheduled tasks, malicious services and Cobalt Strike "TaoWu" plugins; the newsletter also highlights widespread vulnerable instances for CVE-2025-22224, provides Snort SIDs, malware hashes, and mitigation/patching guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
