logo

PHP Under Attack

ID: 47124c0f-bc54-588d-b240-ffe0ba61accb

STIX ID: report--47124c0f-bc54-588d-b240-ffe0ba61accb

Feed Name: Canary Trap

Threat Score
85/100

Date Published: 2025-03-24

Date Updated: 2026-05-13

Author: Canary Trap

...
...

A critical PHP remote code execution vulnerability (CVE-2024-4577) affecting Windows-based PHP installations has been actively exploited worldwide since June 2024; GreyNoise telemetry shows large-scale automated scanning and attack spikes in Jan–Feb 2025 (1,089 unique attacking IPs in January, with >40% from Germany and China), while Cisco Talos links the flaw to targeted intrusions against Japanese telecom, technology, and education sectors using Cobalt Strike TaoWu plug-ins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.