Tag: ASP.NET

Hackers exploited Sitecore zero-day flaw to deploy backdoors
News

Hackers exploited Sitecore zero-day flaw to deploy backdoors

Threat actors have been using WeepSteel reconnaissance malware by taking advantage of a zero-day vulnerability in older Sitecore implementations. The inclusion of a sample ASP.NET machine key in pre-2017 Sitecore documentation led to the ViewState deserialization vulnerability, which is tracked under CVE-2025-53690. By reusing this key in production, some customers made it possible for attackers who knew the key to create legitimate but malicious '_VIEWSTATE' payloads that deceived the server into deserializing and running them, resulting in remote code execution (RCE). The problem is a misconfiguration vulnerability brought about by reusing publicly documented keys that were never intended for production, not an ASP.NET fault read more about Hackers exploited Sitecore zero-day f...
Gold Melody IAB Exploits Exposed ASP.NET Machine Keys for Unauthorized Access to Targets
News

Gold Melody IAB Exploits Exposed ASP.NET Machine Keys for Unauthorized Access to Targets

A campaign that uses stolen ASP.NET machine keys to gain unauthorized access to companies and sell that access to other threat actors has been linked to the Initial Access Broker (IAB) known as Gold Melody. Under the designation TGR-CRI-0045—where "TGR" stands for "temporary group" and "CRI" for "criminal motivation"—Palo Alto Networks Unit 42 is monitoring the activities. Prophet Spider and UNC961 are other names for the hacker outfit, while ToyMaker, an initial access broker, also uses one of its tools. According to academics Tom Marsden and Chema Garcia, the group appears to use an opportunistic strategy, but it has targeted companies in the financial services, manufacturing, wholesale and retail, high technology, transportation, and logistics sectors in both Europe and the Unite...
Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks
News

Microsoft Identifies 3,000 Leaked ASP.NET Keys Enabling Code Injection Attacks

Microsoft is alerting users about a dangerous practice in which programmers are putting their apps in the path of attackers by integrating publicly available ASP.NET machine keys from publicly accessible sources. In December 2024, the tech giant's threat intelligence team reported limited activity in which an unidentified threat actor delivered the Godzilla post-exploitation framework and injected malicious code using a publicly available, static ASP.NET machine key. Also, it reported that it has discovered more than 3,000 publicly available keys that may be exploited for what it refers to as ViewState code injection attacks read more about Microsoft Identifies 3000 Leaked ASP.NET Keys Enabling Code Injection Attacks. Get up to date on the latest cybersecurity news and enhance yo...