Silent Intrusion: “Metro4Shell” Exploited in the Wild Since December
ID: da1655cf-06eb-5255-8bb6-37ca6cd0413f
STIX ID: report--da1655cf-06eb-5255-8bb6-37ca6cd0413f
Feed Name: securityonline.info
Threat Score
VulnCheck reports that CVE-2025-11953 (“Metro4Shell”) was being actively weaponized in the wild as early as late December 2025, with honeypot telemetry showing consistent delivery of advanced Windows and Linux payloads from multiple IP addresses; the report warns that publicly reachable development infrastructure functions as practical initial access and urges immediate patching rather than waiting for KEV guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
