Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

The US Spends More On ‘Defense’ Than The Next 8 Countries Combined

May 3, 2026

Bitcoin mining stocks climb in 2026 as BTC lags behind

May 3, 2026

Alex Lab hack reportedly hits SPD Bank clients after earlier $8.3M exploit

May 3, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Adobe ColdFusion Critical Vulnerabilities Exploited Despite Patches
Adobe ColdFusion Critical Vulnerabilities Exploited Despite Patches
Security

Adobe ColdFusion Critical Vulnerabilities Exploited Despite Patches

September 24, 2023No Comments2 Mins Read

Fortinet has observed significant threat exploitation targeting Adobe ColdFusion, a web development computing platform.

This is despite a series of security updates (APSB23-40, APSB23-41, and APSB23-47) released by Adobe in July following reports of several critical vulnerabilities in its platform.

Since those updates, however, Fortinet’s FortiGuard Labs IPS telemetry data has continued to detect numerous efforts to exploit one of these vulnerabilities, the deserialization of untrusted data by the Web Distributed Data eXchange (WDDX) data that forms part of some requests to ColdFusion.

This vulnerability is critical because it poses a significant risk of arbitrary code execution.

The observed attacks include probing, using an interactsh tool that can generate specific domain names to help researchers test whether an exploit is successful but can also be used by attackers, and establishing reverse shells, often called remote shells or connect-back shells, to attempt to exploit vulnerabilities within a target system by initiating a shell session, thereby enabling access to the victim’s computer.

In the report, FortiGuard Labs has identified four malware variants used by attackers trying to exploit ColdFusion’s deserialization vulnerability:

  • XMRig Miner, which leverages computer processing cycles to mine for the Monero cryptocurrency
  • Satan DDoS/Lucifer, a hybrid bot that combines cryptojacking and distributed denial of service (DDoS) functionalities
  • RudeMiner/SpreadMiner, with similar functionalities as Lucifer
  • BillGates/Setag, a backdoor known for hijacking systems, communicating with command and control servers and initiating attacks

“Although the patches for these vulnerabilities have already been released, public attacks are still occurring. We strongly urge users to upgrade affected systems immediately and apply FortiGuard protection to avoid threat probing,” FortiGuard Labs warned.

See also  US Targets Crypto Firms Aiding Russia Sanctions Evasion

Source link

Adobe ColdFusion critical Exploited Patches vulnerabilities

Related Posts

Alex Lab hack reportedly hits SPD Bank clients after earlier $8.3M exploit

May 3, 2026

How North Korean spies spent months in-person to drain $285 million from Drift

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026
Top Posts

Underwater Connectors Market size to hit $3.15 Billion by 2035 | Top companies include TE Connectivity, Amphenol Corporation, Fischer Connectors, MacArtney Group, SEACON (TE Connectivity)

March 12, 2026

BoE And Fed Decision Out Of The Way – What’s Next For GBP And USD?

September 29, 2023

South Korea regulators blame Coupang data breach on internal security weaknesses

February 11, 2026

Type above and press Enter to search. Press Esc to cancel.