Report
Unpatched AhsayCBS flaws reportedly exploited to run code remotely
SecurityWeek reports, citing Huntress, that version 10.3.4 was affected and at least five organizations had been targeted by October 8.
TLDR
SecurityWeek reports, citing Huntress, that attackers chained two unpatched AhsayCBS flaws to run code remotely without authentication and deploy webshells. Huntress said version 10.3.4 was also affected and at least five organizations had been targeted as of October 8. It recommended restricting access to the management interface and checking for signs of compromise while awaiting a patch.
Combined views
478
1 Source, first seen ago
1 likes1 comments