Skip to Content
  • Home
  • Past Shows
  • Books by Ken
  • Our Partners
  • Technology Store

Tech Today w/ Ken May

Tag: post-published

Critical vulnerability under “massive” attack imperils high-impact sites [Updated]

Enlarge / One of two publicly available exploits for a critical Apache Struts vulnerability. (credit: Kevin Beaumont ) In a string of attacks that have escalated over the past 48 hours, hackers are actively exploiting a critical vulnerability that allows them to take almost complete control of Web servers used by banks, government agencies, and large Internet companies. The code-execution bug resides in the Apache Struts 2 Web application framework and is trivial to exploit. Although maintainers of the open source project patched the vulnerability on Monday , it remains under attack by hackers who are exploiting it to inject commands of their choice into Struts servers that have yet to install the update, researchers are warning. Making matters worse, at least two working exploits are publicly available. “If you run it against a vulnerable application, the result will be the remote execution of commands with the user running the server,” Vicente Motos wrote of one of the exploits in a post published late Wednesday afternoon on the Hack Players website. “We have dedicated hours to reporting to companies, governments, manufacturers, and even individuals to patch and correct the vulnerability as soon as possible, but the exploit has already jumped to the big pages of ‘advisories,’ and massive attempts to exploit the Internet have already been observed.” Read 8 remaining paragraphs | Comments

Originally posted here:
Critical vulnerability under “massive” attack imperils high-impact sites [Updated]

March 9, 2017 by kenmay – Leave a comment
Posted in reader – Tags: already-jumped, apache, apache-struts, exploits, hack, internet, kevin-beaumont, over-the-past, post-published, source-project, vicente-motos, vulnerability

Recent Posts

  • National Cybersecurity Awareness Month: 4 Simple Steps to Staying Secure
  • New Paper Confirms Near-Room-Temperature Superconductivity in Wild, Hydrogen-Rich Material
  • How the World’s First Digital Circuit Breaker Could Completely Change Our Powered World
  • Getting Scammed Through Social Media
  • Apple pledges to notify users of potential iPhone slowdowns

Search

Calendar

October 2025
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031  
« Oct    

© 2025 Tech Today w/ Ken May. All rights reserved. Skewart Theme by Photricity Web Design.