logo

Hackers target Apache RocketMQ servers vulnerable to RCE attacks

ID: 9468be79-f3aa-5d0c-87d0-0c94262c7ed6

STIX ID: report--9468be79-f3aa-5d0c-87d0-0c94262c7ed6

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-01-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Security researchers and monitoring organizations report active scanning and exploitation of critical Apache RocketMQ NameServer vulnerabilities (CVE-2023-33246 and CVE-2023-37582) that were not fully fixed in earlier patches; threat actors including the DreamBus botnet have leveraged these flaws to deploy XMRig miners, ShadowServer observes hundreds of scanning hosts, and CISA and Apache recommend upgrading NameServer to fixed versions (5.1.2 / 4.9.7+) to mitigate ongoing attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.