Mirai Botnets Exploit Flaw in Wazuh Security Platform
ID: f6731d17-4745-5715-915f-2eb644db4a05
STIX ID: report--f6731d17-4745-5715-915f-2eb644db4a05
Feed Name: Dark Reading
Akamai researchers observed two Mirai botnet campaigns (LZRD and Resbot) exploiting CVE-2025-24016, a critical (9.9) remote code execution in Wazuh (affecting 4.4.0–4.9.1) soon after a public PoC appeared; exploitation began in March with a second wave in May. The campaigns use Mirai variants targeting multiple IoT architectures and different Wazuh endpoints, prompting CISA to add the CVE to its KEV catalog, while Wazuh contends exploitation requires valid admin API credentials and reports no customer impact; Akamai recommends upgrading to Wazuh 4.9.1 or later.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
