Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries
ID: 1f3aecf5-49ef-5be5-98d5-3e08274cf9ed
STIX ID: report--1f3aecf5-49ef-5be5-98d5-3e08274cf9ed
Feed Name: Hunt.io Blog
Threat Score
This report describes an exposed, actively assembled exploit server that hosted public and custom exploit code for multiple recent critical vulnerabilities (NGINX Rift, Ghost CMS SQLi, Splunk, Samba, WebLogic, PaperCut, D-Link NAS), included post-exploitation tooling (AdaptixC2, Supershell), and targeted high-value sectors across 11 countries using out-of-band DNS callback verification; IOCs and operator tradecraft are provided, but no confirmed successful compromises were recovered.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
