As cited
Copy frozen at (site build).
vulnerabilities
Rondo Meets Geoserver
Geoserver instances are being targeted with CVE-2024-36401, an X-Path expression evaluation flaw, to deploy the Rondo botnet. The exploit chain attempts to download and execute a shell script from a remote server, though evidence suggests the malware may have been subsequently removed from affected hosts. This represents a continuation of Rondo's documented interest in Geoserver as an attack vector.
Why it matters: Organizations running Geoserver, particularly those exposed on the internet, should immediately patch CVE-2024-36401 and monitor logs for similar malicious GetPropertyValue requests, as this active in-the-wild exploitation can lead to botnet infection and full system compromise.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Rondo Meets Geoserver
Geoserver instances are being targeted with CVE-2024-36401, an X-Path expression evaluation flaw, to deploy the Rondo botnet. The exploit chain attempts to download and execute a shell script from a remote server, though evidence suggests the malware may have been subsequently removed from affected hosts. This represents a continuation of Rondo's documented interest in Geoserver as an attack vector.
Why it matters: Organizations running Geoserver, particularly those exposed on the internet, should immediately patch CVE-2024-36401 and monitor logs for similar malicious GetPropertyValue requests, as this active in-the-wild exploitation can lead to botnet infection and full system compromise.
- Source published
- First seen by Cybersecurity Tracker