logo

Silent Intrusion: “Metro4Shell” Exploited in the Wild Since December

ID: da1655cf-06eb-5255-8bb6-37ca6cd0413f

STIX ID: report--da1655cf-06eb-5255-8bb6-37ca6cd0413f

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

VulnCheck reports that CVE-2025-11953 (“Metro4Shell”) was being actively weaponized in the wild as early as late December 2025, with honeypot telemetry showing consistent delivery of advanced Windows and Linux payloads from multiple IP addresses; the report warns that publicly reachable development infrastructure functions as practical initial access and urges immediate patching rather than waiting for KEV guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.