Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks

Microsoft is alerting users about a dangerous practice in which programmers are putting their apps in the path of attackers by integrating publicly available ASP.NET machine keys from publicly accessible sources.

In December 2024, the tech giant’s threat intelligence team reported limited activity in which an unidentified threat actor delivered the Godzilla post-exploitation framework and injected malicious code using a publicly available, static ASP.NET machine key.

Also, it reported that it has discovered more than 3,000 publicly available keys that may be exploited for what it refers to as ViewState code injection attacks read more about Microsoft Identifies 3000 Leaked ASP.NET Keys Enabling Code Injection Attacks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *