Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Hack at Vercel sends crypto developers scrambling to lock down API keys

April 20, 2026

Bitcoin difficulty falls to 135.59T – But THESE 3 miner signals warn of stress

April 20, 2026

SEC charges Donald Basile in $16M crypto fraud tied to ‘insured’ token

April 20, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Adobe ColdFusion Critical Vulnerabilities Exploited Despite Patches
Adobe ColdFusion Critical Vulnerabilities Exploited Despite Patches
Security and Privacy

Adobe ColdFusion Critical Vulnerabilities Exploited Despite Patches

September 1, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Fortinet has observed significant threat exploitation targeting Adobe ColdFusion, a web development computing platform.

This is despite a series of security updates (APSB23-40, APSB23-41, and APSB23-47) released by Adobe in July following reports of several critical vulnerabilities in its platform.

Since those updates, however, Fortinet’s FortiGuard Labs IPS telemetry data has continued to detect numerous efforts to exploit one of these vulnerabilities, the deserialization of untrusted data by the Web Distributed Data eXchange (WDDX) data that forms part of some requests to ColdFusion.

This vulnerability is critical because it poses a significant risk of arbitrary code execution.

The observed attacks include probing, using an interactsh tool that can generate specific domain names to help researchers test whether an exploit is successful but can also be used by attackers, and establishing reverse shells, often called remote shells or connect-back shells, to attempt to exploit vulnerabilities within a target system by initiating a shell session, thereby enabling access to the victim’s computer.

In the report, FortiGuard Labs has identified four malware variants used by attackers trying to exploit ColdFusion’s deserialization vulnerability:

  • XMRig Miner, which leverages computer processing cycles to mine for the Monero cryptocurrency
  • Satan DDoS/Lucifer, a hybrid bot that combines cryptojacking and distributed denial of service (DDoS) functionalities
  • RudeMiner/SpreadMiner, with similar functionalities as Lucifer
  • BillGates/Setag, a backdoor known for hijacking systems, communicating with command and control servers and initiating attacks

“Although the patches for these vulnerabilities have already been released, public attacks are still occurring. We strongly urge users to upgrade affected systems immediately and apply FortiGuard protection to avoid threat probing,” FortiGuard Labs warned.

See also  FTX: Over $400m Was Stolen from Bankrupt Exchange

Source link

Adobe ColdFusion Critical exploited Patches Vulnerabilities
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Critical Withdrawal Window Opens as NFT Layer 2 Service Ends

April 19, 2026

Kelp DAO exploited for $292 million with wrapped ether stranded across 20 chains

April 18, 2026

Cookeville Hospital Discloses Rhysida Breach Hitting 337,917

April 16, 2026

BNB Chain Flags Critical Update Ahead of April 28 Hard Fork

April 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Crypto Wallet Provider Exodus’ NYSE American Stock Listing Postponed for SEC Review

May 9, 2024

How US SEC And Court To Deliver Legal Papers To Binance And CEO “CZ”?

June 11, 2023

How Bitdeer is navigating Bitcoin mining and AI integration

July 4, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Hack at Vercel sends crypto developers scrambling to lock down API keys

April 20, 2026

Bitcoin difficulty falls to 135.59T – But THESE 3 miner signals warn of stress

April 20, 2026

SEC charges Donald Basile in $16M crypto fraud tied to ‘insured’ token

April 20, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$74,653.00-1.25%
  • ethereumEthereum(ETH)$2,286.92-2.35%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$1.41-1.31%
  • binancecoinBNB(BNB)$621.92-0.24%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$84.58-1.23%
  • tronTRON(TRX)$0.3326611.41%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.00%
  • dogecoinDogecoin(DOGE)$0.094310-0.44%