PHP Vulnerability Used For Malware And DDOS Attacks
ID: d68ad615-0aa6-55d5-a8eb-2c2118285a75
STIX ID: report--d68ad615-0aa6-55d5-a8eb-2c2118285a75
Feed Name: Security Boulevard
Threat Score
The report details the rapid in-the-wild exploitation of PHP vulnerability CVE-2024-4577 (CVSS 9.8), which allows attackers to escape the command line via Unicode conversion flaws. Exploits were observed within 24 hours of disclosure and have been used to deliver multiple malicious payloads—crypto miners (RedTail, XMRig), the Muhstik DDoS botnet, Gh0st RAT, and a .NET ransomware variant linked to Tell You The Pass—underscoring urgent patching and mitigation needs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
