Emby shuts down some user media servers after hacker attack

Emby shuts down some user media servers after hacker attack

Software company Emby has remotely shut down some user-based media server instances after a threat actor exploited a known vulnerability to hijack systems.

“You encounter the following message in the Emby Server log: We have detected a malicious plugin on your system which has probably been installed without your knowledge. For your safety we have shutdown your Emby Server as a precautionary measure Note: Your server was never directly accessed by us. We used our standard update mechanism,” the company said in an advisory.

Emby further explained that the attacks have been going on since mid-May 2023, with the attacker breaching internet-facing user-hosted Emby servers with an insecure configuration for administrative user accounts. The attacker used a recently fixed flaw described as the “Proxy Header Vulnerability” to install a malicious plugin designed to steal login credentials.

The Emby team developed a firmware update to scan for the malicious plugin and shut down systems where it was found.

“As the given situation requires direct action and assessment by the administrator, we determined that shutting down the server and preventing further startup up is the most suitable action as it disables the plug-in, possibly prevents the situation from getting worse and at the same time draws the attention of the administrator onto the subject,” the company said.

Back to the list

Latest Posts

Cyber Security Week in Review: May 9, 2025

Cyber Security Week in Review: May 9, 2025

In brief: SAP zero-day exploited by Chinese hackers, SonicWall patches bugs in its SMA appliances, and more.
9 May 2025
Russia-linked Coldriver hackers deploy new espionage malware in targeted attacks

Russia-linked Coldriver hackers deploy new espionage malware in targeted attacks

LOSTKEYS is designed to steal sensitive files, harvest system information, and exfiltrate details about running processes.
8 May 2025
Russia-aligned operation manipulates audio and images to impersonate experts

Russia-aligned operation manipulates audio and images to impersonate experts

The operation primarily focused on undermining NATO support for Ukraine and spreading false narratives to disrupt domestic politics in EU member states.
7 May 2025