Tag: botnet malware

New ShadowV2 botnet malware used AWS outage as a test opportunity
News

New ShadowV2 botnet malware used AWS outage as a test opportunity

With exploits for known vulnerabilities, a new Mirai-based botnet virus known as "ShadowV2" has been seen to attack IoT devices from D-Link, TP-Link, and other companies. Researchers at Fortinet's FortiGuard Labs saw the activity during the significant October AWS outage. The botnet was only active during the outage, which may suggest that it was a test run even though the two instances are unrelated. ShadowV2 propagated via taking use of at least eight flaws in various Internet of Things products: DD-WRT (CVE-2009-2765) D-Link (CVE-2020-25506, CVE-2022-37055, CVE-2024-10914, CVE-2024-10915) DigiEver (CVE-2023-52163) TBK (CVE-2024-3721) TP-Link (CVE-2024-53375) Among these vulnerabilities, the vendor declared that it would not address CVE-2024-10914, a known-to-b...
RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet
News

RondoDox Exploits Unpatched XWiki Servers to Pull More Devices Into Its Botnet

RondoDox, a botnet malware, has been seen to target unpatched XWiki instances in order to exploit a serious security vulnerability that might enable attackers to execute arbitrary code. CVE-2025-24893 (CVSS score: 9.8) is the vulnerability in question. It is an eval injection problem that might enable any guest user to execute arbitrary remote code by sending a request to the ".bin/get/Main/SolrSearch" endpoint. In late February 2025, the maintainers fixed it in XWiki 15.10.11, 16.4.1, and 16.5.0RC1. It wasn't until late October that VulnCheck said it had seen new attempts to weaponize the issue as part of a two-stage attack chain to deploy a bitcoin miner, despite indications that the vulnerability had been exploited in the wild since at least March. The vulnerability was then a...