The US cybersecurity agency CISA on Tuesday published an alert to warn organizations about the exploitation of an Adobe ColdFusion vulnerability.
In August, cybersecurity firm Rapid7 said it had seen multiple attacks leveraging the ColdFusion vulnerability, suggesting that broad exploitation had been underway.
In a new cybersecurity advisory, CISA revealed that CVE-2023-26360 was exploited in June as part of attacks aimed at servers belonging to a federal civilian executive branch agency.
One incident occurred in early June and the second in late June and CISA said it was unclear if the same hacker group was behind both intrusions.
The attackers targeted internet-exposed web servers located in the victim's pre-production environment, with both servers running outdated software versions affected by multiple vulnerabilities.
CISA's advisory on the exploitation of CVE-2023-26360 provides information on tactics, techniques, and procedures, indicators of compromise, as well as recommendations for protecting systems against such attacks.
This Cyber News was published on www.securityweek.com. Publication date: Wed, 06 Dec 2023 13:13:04 +0000