Chinese hackers behind attacks targeting SAP NetWeaver servers
ID: 877ffaba-ac5d-59a8-939d-cb9c79c2db36
STIX ID: report--877ffaba-ac5d-59a8-939d-cb9c79c2db36
Feed Name: Bleeping Computer
Forescout and other security firms observed active exploitation of a critical SAP NetWeaver Visual Composer zero-day (CVE-2025-31324) that permits unauthenticated file uploads; attackers have been uploading JSP web shells and post-exploitation tools, compromising hundreds of exposed instances. The activity—dated from at least January–March 2025—has been linked to a Chinese threat actor tracked as Chaya_004, prompting emergency patches and CISA inclusion of the CVE in its Known Exploited Vulnerabilities Catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
