logo

Hackers exploit Aiohttp bug to find vulnerable networks

ID: 652c6adf-0d87-5faf-94d2-c77fb8bf942e

STIX ID: report--652c6adf-0d87-5faf-94d2-c77fb8bf942e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-03-16

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report describes ShadowSyndicate scanning for and attempting to exploit CVE-2024-23334, a high-severity aiohttp path traversal fixed in aiohttp 3.9.2; a public PoC and exploitation instructions were released in late February/early March, analysts observed scanning from IPs linked to the actor, and roughly 44,170 internet-exposed aiohttp instances exist worldwide—though vulnerable versions and confirmed breaches are not yet established.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.