Hackers target Apache RocketMQ servers vulnerable to RCE attacks
ID: 9468be79-f3aa-5d0c-87d0-0c94262c7ed6
STIX ID: report--9468be79-f3aa-5d0c-87d0-0c94262c7ed6
Feed Name: Bleeping Computer
Security researchers and monitoring organizations report active scanning and exploitation of critical Apache RocketMQ NameServer vulnerabilities (CVE-2023-33246 and CVE-2023-37582) that were not fully fixed in earlier patches; threat actors including the DreamBus botnet have leveraged these flaws to deploy XMRig miners, ShadowServer observes hundreds of scanning hosts, and CISA and Apache recommend upgrading NameServer to fixed versions (5.1.2 / 4.9.7+) to mitigate ongoing attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
