Confluence Exploit Leads to LockBit Ransomware
23 de Fevereiro de 2025, 21:06
Key Takeaways Case Summary The intrusion started with the exploitation of CVE-2023-22527, a critical remote code execution vulnerability in Confluence, against a Windows server. The first indication of threat actor activity was the execution of system discovery commands, including net user and whoami. Shortly after, the threat actor attempted to download AnyDesk via curl, but […]
The post Confluence Exploit Leads to LockBit Ransomware appeared first on The DFIR Report.