Hackers hide post-exploitation toolkit inside Oracle database after SQL injection attack
The attackers gained access through a vulnerable autocomplete search feature in a public-facing Java application hosted on Apache Tomcat.
In brief: a critical N-able flaw exploited in the wild; Russian hackers target hotel Wi-Fi systems; and more.
The attackers gained access through a vulnerable autocomplete search feature in a public-facing Java application hosted on Apache Tomcat.
The attack, called ChainDrop, began after hackers infected the keyv and cacheable packages.
Researchers started with a lower-level employee's compromised email account and used the AI assistant to gather information and plan an attack.
Researchers said INC Ransomware was not the first group to abuse the flaws, but it has been the most aggressive in combining both vulnerabilities into a full attack chain.
The campaign uses multiple malware components, including VBScript droppers, batch scripts, .NET executables, and phishing HTML pages.
Censys noted possible links between DarkSword and Coruna and the UNC6353 threat actor, which has been linked to attacks on Ukraine.