Government Servers Breached by Hackers Exploiting Adobe ColdFusion Vulnerability

1 min read
Source: The Hacker News
Government Servers Breached by Hackers Exploiting Adobe ColdFusion Vulnerability
Photo: The Hacker News
TL;DR Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about the active exploitation of a high-severity Adobe ColdFusion vulnerability by unidentified threat actors to gain initial access to government servers. The vulnerability, CVE-2023-26360, allows for arbitrary code execution and affects outdated versions of ColdFusion 2018 and ColdFusion 2021. At least two public-facing servers were compromised, and the attackers were able to drop malware and perform reconnaissance activities. No data exfiltration has been observed, but the threat actors attempted to decrypt passwords using the seed values found in the ColdFusion seed.properties file.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

80%

48294 words

Want the full story? Read the original article

Read on The Hacker News