Thousands of Qlik Sense Servers Open to Cactus Ransomware
ID: aef27d7a-f54e-53e9-b55d-cb844d85bd36
STIX ID: report--aef27d7a-f54e-53e9-b55d-cb844d85bd36
Feed Name: Dark Reading
Threat Score
Nearly five months after Qlik disclosed CVE-2023-41266, CVE-2023-41265 and the subsequent bypass CVE-2023-48365, security teams observed the Cactus ransomware group exploiting these flaws to gain remote code execution in Qlik Sense; scans identified 5,205 internet-accessible Qlik Sense servers with 3,143 still vulnerable and at least 122 likely compromised, prompting Fox-IT, DIVD, ShadowServer and others to notify affected organizations and warn of a high likelihood of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
