logo

Scans Targeting Hospitality Applications, (Wed, Sep 16th)

ID: 15ceb258-7624-575d-b2f8-3910e64d3c80

STIX ID: report--15ceb258-7624-575d-b2f8-3910e64d3c80

Feed Name: SANS ISC Diary

Threat Score
50/100

Date Published: 2026-09-16

Date Updated: 2026-09-17

...
...

An abandoned PBX-in-a-Flash hospitality management application (PIAF-HMS) is being actively scanned from a single host (94.102.49.125) using requests that include an unusual User-Agent (Farez-Sorter/1.0) and probes for admin and hotel-related paths. The codebase reportedly contains an SQL injection vulnerability and lacks input validation and authentication, making it an attractive target for attackers seeking to compromise hotel PBX systems for data theft or MitM activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.