Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Riot’s Anthropic Deal Shows Bitcoin Miners Are Moving Deeper Into AI Compute

August 12, 2026

Bitcoin miners earn under 0.7% of revenue from fees in new 10-year low

August 12, 2026

Harmony’s ONE Plunges 30% After Attacker Mints 4 Billion Tokens

August 12, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Cryptojackers Exploit Critical Apache Struts Flaw
Cryptojackers Exploit Critical Apache Struts Flaw
Security and Privacy

Cryptojackers Exploit Critical Apache Struts Flaw

August 20, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

A critical Apache Struts vulnerability disclosed last week is being actively exploited in the wild to maliciously install a popular cryptocurrency miner on victim systems, according to researchers.

Experts at security vendor Volexity warned earlier this week that they spotted the activity shortly after a proof-of-concept exploit was made public.

“The in-the-wild attacks observed thus far appear to have been taken directly from the publicly posted PoC code. In this instance, Apache Struts is vulnerable due to a improper validation of namespace input data, and the flaw is trivial to exploit,” the firm explained.

“Volexity has observed at least one threat actor attempting to exploit CVE-2018-11776 en masse in order to install the CNRig cryptocurrency miner. The initial observed scanning originated from the Russian and French IP addresses 95.161.225.94 and 167.114.171.27.”

The CVSS 10.0 vulnerability was revealed last week, with experts urging admins to patch as soon as possible to protect their systems. A flaw in the popular web application framework was exploited infamously last year when Equifax failed to apply an available update, resulting in a data breach though to have affected nearly half of all Americans.

Advice from the Apache Software Foundation is to upgrade to Struts 2.3.35 or Struts 2.5.17.

There could be more danger ahead for organizations which fail to patch promptly, as the flaw itself enables remote code execution and could theoretically allow attackers to access a targeted system.

Recorded Future revealed it had “detected chatter in a number of Chinese and Russian underground forums around the exploitation of this vulnerability,” while Volexity claimed it has “observed multiple APT groups leveraging Apache Struts vulnerabilities to gain access to target networks.”

See also  US Warns Critical Sectors Against North Korean Ransomware Attacks

Trend Micro revealed in its midyear roundup report this week that detections for cryptocurrency miners rocketed 956% from the first half of 2017 to the first six months of this year.

Source link

Apache Critical Cryptojackers exploit Flaw Struts
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Harmony’s ONE Plunges 30% After Attacker Mints 4 Billion Tokens

August 12, 2026

Sui Co-Founder Is Building Quantum-Safe Hardware Wallets For $10

August 12, 2026

Six npm Packages Read C2 Addresses From Ethereum Wallet

August 11, 2026

Ravencoin could roll back four days of transactions after critical block flaw

August 11, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Horizon Launches Crypto and NFT Integration Tool for Game Developers

December 1, 2023

Immutable Leads Web3 Gaming Evolution at Gamescom 2023

August 23, 2023

We’re Not Saying Web3 Gaming and Social Is the Future…but This Is a Positive Indicator

June 12, 2023

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Riot’s Anthropic Deal Shows Bitcoin Miners Are Moving Deeper Into AI Compute

August 12, 2026

Bitcoin miners earn under 0.7% of revenue from fees in new 10-year low

August 12, 2026

Harmony’s ONE Plunges 30% After Attacker Mints 4 Billion Tokens

August 12, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$63,495.00-0.60%
  • ethereumEthereum(ETH)$1,892.461.00%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$610.380.40%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.011.60%
  • solanaSolana(SOL)$75.680.70%
  • tronTRON(TRX)$0.3355990.30%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.043.60%
  • HyperliquidHyperliquid(HYPE)$56.343.80%