CrushFTP warns users to patch exploited zero-day “immediately”
ID: 66a9020d-44c1-5b35-8c95-71492e251b02
STIX ID: report--66a9020d-44c1-5b35-8c95-71492e251b02
Feed Name: Bleeping Computer
Threat Score
CrushFTP disclosed a zero-day VFS sandbox escape (now tracked as CVE-2024-4040) that allows unauthenticated attackers to retrieve system files outside a user's VFS; the flaw is being actively exploited in targeted, likely politically motivated intelligence-gathering attacks against U.S. organizations, CrowdStrike confirmed observations, and vendor patches (10.7.1 and 11.1.0) and urgent patching guidance were issued while Shodan shows thousands of exposed instances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
