Cryptojacking campaign exploiting Apache Struts 2 flaw kills off the competition

It has only been two weeks since a critical vulnerability in Apache Struts 2 was revealed to the public, but this hasn’t stopped cybercriminals from rapidly adding proof-of-concept (PoC) attack code to their arsenal. More security news ​Troll-killing internet software Trollteq arrives Telegram starts to play nice with security agencies over user data, but not in Russia Defense Distributed now sells 3D gun blueprints online, ‘pay what you want’ Meet the malware which hijacks your browser and redirects you to fake pages The security flaw, patched by the Apache Software Foundation, is tracked as CVE-2018-11776 was caused due to insufficient validation of untrusted user data in the core Struts framework.

Read full news article on ZDNet

 


Date:

Categorie(s):