Cloud Attackers Exploit Max-Critical Aviatrix RCE Flaw
ID: 9d82eaf8-c38c-5be9-8268-433ecb590d50
STIX ID: report--9d82eaf8-c38c-5be9-8268-433ecb590d50
Feed Name: Dark Reading
Threat Score
Multiple threat actors are actively exploiting CVE-2024-50603, a maximum-severity (CVSS 10) unauthenticated RCE in Aviatrix Controller, to deploy XMRig cryptomining malware and the Sliver backdoor; proof-of-concept code and automated scanners have driven opportunistic attacks across cloud environments, and Aviatrix has released patches and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
