Two distinct Mirai botnet variants are being dropped by threat actors using a now-patched serious security vulnerability in the Wazur Server to launch distributed denial-of-service (DDoS) assaults.
The malicious campaign targets CVE-2025-24016 (CVSS score: 9.9), an unsafe deserialization vulnerability that permits remote code execution on Wazuh servers, according to Akamai, which initially learned about the exploitation activities in late March 2025.
In February 2025, 4.9.1 was released to fix the security flaw that impacts all server software versions, including and beyond 4.4.0. Concurrent with the fixes’ release, a proof-of-concept (PoC) exploit was made public.
“as_wazuh_object” in the framework/wazuh/core/cluster/common.py code is used to deserialize arguments that are serialized as JSON in the DistributedAPI read more about Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
