Tag: SAP Vulnerability

Hackers Exploit SAP Vulnerability to Breach Linux Systems and Deploy Auto-Color Malware
News

Hackers Exploit SAP Vulnerability to Breach Linux Systems and Deploy Auto-Color Malware

In April 2025, threat actors were seen delivering the Auto-Color backdoor to a U.S.-based chemicals company by taking advantage of a now-patched significant SAP NetWeaver vulnerability. According to a report provided to The Hacker News by Darktrace, a threat actor got access to the customer's network over the course of three days, tried to download a number of dubious files, and interacted with malicious infrastructure connected to Auto-Color malware. Remote code execution (RCE) is made possible by the serious unauthenticated file upload flaw in SAP NetWeaver known as CVE-2025-31324. In April, SAP released a patch for it. Auto-Color works similarly to a remote access trojan, allowing remote access to vulnerable Linux computers. It was initially discovered by Palo Alto Networks Un...