Hackers hide post-exploitation toolkit inside Oracle database after SQL injection attack
The attackers gained access through a vulnerable autocomplete search feature in a public-facing Java application hosted on Apache Tomcat.
2 min read
Cybersecurity Help is a global vulnerability intelligence provider. We monitor vulnerabilities in software from 60,000+ vendors and help customers prevent potential data breaches by addressing them proactively.
Request DemoThe attackers gained access through a vulnerable autocomplete search feature in a public-facing Java application hosted on Apache Tomcat.
2 min readThe attack, called ChainDrop, began after hackers infected the keyv and cacheable packages.
2 min readResearchers started with a lower-level employee's compromised email account and used the AI assistant to gather information and plan an attack.
2 min readResearchers said INC Ransomware was not the first group to abuse the flaws, but it has been the most aggressive in combining both vulnerabilities into a full attack chain.
2 min readThe campaign uses multiple malware components, including VBScript droppers, batch scripts, .NET executables, and phishing HTML pages.
2 min read