PHP Vulnerability Exploited to Spread Malware and Launch DDoS Attacks
ID: 506bd2ce-7a28-56c1-8da7-443591b00a00
STIX ID: report--506bd2ce-7a28-56c1-8da7-443591b00a00
Feed Name: The Hacker News
Multiple threat actors rapidly began exploiting CVE-2024-4577 (CVSS 9.8) in PHP to escape the command line via Unicode conversion issues and deliver remote access trojans (Gh0st RAT), cryptocurrency miners (RedTail, XMRig), and the Muhstik DDoS botnet; Imperva observed TellYouThePass actors using the flaw to distribute a .NET ransomware variant. Akamai saw exploitation attempts within 24 hours of disclosure, underscoring high exploitability and rapid adoption, while Cloudflare reported increased DDoS activity in Q2 2024; organizations are advised to update PHP immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
