Visualização normal

Antes de ontemThe DFIR Report
  • ✇The DFIR Report
  • Apache ActiveMQ Exploit Leads to LockBit Ransomware editor
    Key Takeaways An audio version of this report can be found on Spotify, Apple, YouTube, Audible, & Amazon.  This intrusion began in mid-February 2024 after a threat actor exploited a vulnerability (CVE-2023-46604) on an exposed Apache ActiveMQ server. The threat actor was able to perform remote code execution (RCE) by using a Java Spring class and a custom Java Spring […] The post Apache ActiveMQ Exploit Leads to LockBit Ransomware appeared first on The DFIR Report.
     

Apache ActiveMQ Exploit Leads to LockBit Ransomware

Por:editor
23 de Fevereiro de 2026, 11:09

Key Takeaways An audio version of this report can be found on Spotify, Apple, YouTube, Audible, & Amazon.  This intrusion began in mid-February 2024 after a threat actor exploited a vulnerability (CVE-2023-46604) on an exposed Apache ActiveMQ server. The threat actor was able to perform remote code execution (RCE) by using a Java Spring class and a custom Java Spring […]

The post Apache ActiveMQ Exploit Leads to LockBit Ransomware appeared first on The DFIR Report.

  • ✇The DFIR Report
  • Confluence Exploit Leads to LockBit Ransomware editor
    Key Takeaways Case Summary The intrusion started with the exploitation of CVE-2023-22527, a critical remote code execution vulnerability in Confluence, against a Windows server. The first indication of threat actor activity was the execution of system discovery commands, including net user and whoami. Shortly after, the threat actor attempted to download AnyDesk via curl, but […] The post Confluence Exploit Leads to LockBit Ransomware appeared first on The DFIR Report.
     

Confluence Exploit Leads to LockBit Ransomware

Por:editor
23 de Fevereiro de 2025, 21:06

Key Takeaways Case Summary The intrusion started with the exploitation of CVE-2023-22527, a critical remote code execution vulnerability in Confluence, against a Windows server. The first indication of threat actor activity was the execution of system discovery commands, including net user and whoami. Shortly after, the threat actor attempted to download AnyDesk via curl, but […]

The post Confluence Exploit Leads to LockBit Ransomware appeared first on The DFIR Report.

❌
❌