logo

Open Directory Stages NGINX Rift and Ghost CMS Exploits Against Government and Finance Across Eleven Countries

ID: 1f3aecf5-49ef-5be5-98d5-3e08274cf9ed

STIX ID: report--1f3aecf5-49ef-5be5-98d5-3e08274cf9ed

Feed Name: Hunt.io Blog

Threat Score
72/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

...
...

This report describes an exposed, actively assembled exploit server that hosted public and custom exploit code for multiple recent critical vulnerabilities (NGINX Rift, Ghost CMS SQLi, Splunk, Samba, WebLogic, PaperCut, D-Link NAS), included post-exploitation tooling (AdaptixC2, Supershell), and targeted high-value sectors across 11 countries using out-of-band DNS callback verification; IOCs and operator tradecraft are provided, but no confirmed successful compromises were recovered.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.