logo

How Hacked Construction Apps Are Bringing Down Jobsite Security

ID: 90332769-6f90-5c17-a9ac-989f40fb657d

STIX ID: report--90332769-6f90-5c17-a9ac-989f40fb657d

Feed Name: Huntress Blog

Threat Score
65/100

Date Published: 2026-01-21

Date Updated: 2026-04-28

...
...

Huntress analysts observed multiple real-world intrusions exploiting a blind SQL injection (CVE-2025-51683) in the Mjobtime web application that enabled xp_cmdshell on MSSQL and allowed remote command execution (examples: net user, DNS exfiltration via ping, wget/curl downloads). Three separate customer incidents in 2025 were linked to the vulnerability; activity appeared limited to executing initial commands before detection and containment. Organizations running Mjobtime should contact the vendor and secure their IIS/MSSQL installations, monitor for the shown IIS POST pattern and xp_cmdshell enablement, and apply mitigations promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.