SecurityWeek· Ionut Arghire·· 4 小时前AI 评分74
Huntress称AhsayCBS两个未修补漏洞已遭在野利用
Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
AI 导读
Huntress称,攻击者正在链式利用AhsayCBS两个未修补漏洞,以获取未认证的远程代码执行权限并植入WebShell。截至10月8日,至少五个组织遭到攻击,所有10.3.2及以下版本以及最新版10.3.4均受影响。Huntres建议在补丁发布前仅允许可信IP或通过VPN访问管理界面,并调查系统是否已遭入侵。
来源:SecurityWeek · securityweek.com