logo

Oracle WebLogic Server OS Command Injection Flaw Under Active Attack

ID: f441f3b7-07bc-56c9-955a-c0069135f3f9

STIX ID: report--f441f3b7-07bc-56c9-955a-c0069135f3f9

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-04

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

CISA added Oracle WebLogic Server CVE-2017-3506 (OS command injection, CVSS 7.4) to the Known Exploited Vulnerabilities catalog after observing active exploitation; the China-based 8220 Gang (Water Sigbin) has been leveraging this flaw to deploy fileless, in-memory cryptocurrency miners via obfuscated shell and PowerShell scripts. Federal agencies are advised to apply the latest patches by June 24, 2024 to mitigate takeover and cryptomining activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.