logo

Hackers exploit ProjectSend flaw to backdoor exposed servers

ID: bf88428c-a497-5d76-96bf-d3da86333304

STIX ID: report--bf88428c-a497-5d76-96bf-d3da86333304

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-11-27

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

Threat actors are actively exploiting a critical authentication bypass in ProjectSend (CVE-2024-11680) to alter configuration, enable registrations, and deploy webshells on compromised servers; public exploits (Metasploit, Nuclei) and scanning data indicate thousands of vulnerable instances (~4,000 public-facing) with evidence of in-the-wild deployment and persistent webshells—upgrading to r1750 is strongly recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.