Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » The PHP vulnerability is used to spread malware and launch DDoS attacks
Global Security

The PHP vulnerability is used to spread malware and launch DDoS attacks

AdminBy AdminJuly 11, 2024No Comments3 Mins Read
PHP Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


July 11, 2024Information hallCyber ​​Attack / Vulnerability

PHP vulnerability

Several threat actors have been observed exploiting a newly disclosed security flaw in PHP to deliver remote access Trojans, cryptocurrency miners, and distributed denial-of-service (DDoS) botnets.

The vulnerability in question CVE-2024-4577 (CVSS Score: 9.8), which allows an attacker to remotely execute malicious commands on Windows systems using Chinese and Japanese locales. It was publicly announced in early June 2024.

“CVE-2024-4577 is a flaw that allows an attacker to escape the command line and pass arguments that will be interpreted directly by PHP,” Akamai researchers Kyle Lefton, Allen West, and Sam Tinklenberg said in the analysis on Wednesday. “The vulnerability itself lies in how Unicode characters are converted to ASCII.”

Cyber ​​security

The web infrastructure company said it began seeing exploit attempts against its honeypot servers targeting the PHP flaw within 24 hours of it becoming public.

This included exploits designed to deliver a named remote access trojan Gh0st RATlike cryptocurrency miners Red tail and XMRig, as well as a DDoS botnet called Mukhstik.

“The attacker sent a request similar to other visible previous RedTail operations, abusing a soft hyphen flaw with ‘%ADd’ to execute a wget request for a shell script,” the researchers explained. “This script makes an additional network request to the same Russian IP address to retrieve the x86 version of the RedTail crypto-mining malware.”

Last month, Imperva also revealed that CVE-2024-4577 was being used by the TellYouThePass ransomware to distribute a .NET variant of the file encryption malware.

Users and organizations using PHP are advised to update their installations to the latest version to protect against active threats.

“The ever-decreasing amount of time defenders have to defend themselves after a new vulnerability is disclosed is another critical security risk,” the researchers said. “This is particularly true for this PHP vulnerability due to its high exploitability and rapid adoption by threats.”

Cyber ​​security

The disclosure comes after Cloudflare said it saw a 20% year-over-year increase in DDoS attacks in the second quarter of 2024, and that it mitigated 8.5 million DDoS attacks in the first six months. For comparison, the company blocked 14 million DDoS attacks in all of 2023.

“Overall, DDoS attacks in the second quarter were down 11% quarter-over-quarter, but up 20% year-over-year,” researchers Omer Joachimik and Jorge Pacheco said in the Q2 2024 DDoS Threat Report.

The most attacked country during this period was China, followed by Turkey, Singapore, Hong Kong, Russia, Brazil, Thailand, Canada, Taiwan and Kyrgyzstan. Information technology and services, telecommunications, consumer goods, education, construction and food have become the main sectors affected by DDoS attacks.

“Argentina was identified as the largest source of DDoS attacks in the second quarter of 2024,” the researchers said. “Indonesia is a close second, followed by the Netherlands in third.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025

Popular Chrome Extensions API leaks, user data via HTTP and Hard Codes

June 5, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025

Why are more security leaders choose AEV

June 6, 2025

New data Wiper Pathwiper Data Wiper violates Ukrainian critical infrastructure in 2025 attack

June 6, 2025

Popular Chrome Extensions API leaks, user data via HTTP and Hard Codes

June 5, 2025

Researchers in detail in detail decisively developing tactics as it expands its geographical volume

June 5, 2025

Iran related

June 5, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

New company Atomic MacOS Campation Exploaits Clickfix to focus on Apple users

June 6, 2025

Microsoft helps CBI disassemble the Indian Centers for Japanese Technical Support

June 6, 2025

Expand users’ capabilities and protect against Genai data loss

June 6, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.