Cyberoon

About Cookies On This Site

We use cookies to analyze site usage and improve our website and services. Click &quotCookie Settings &quot to manage your preferences. For more information, read our Cookies Policy.

Cyberoon

Offense is the best defense for your brands

Cyberoon on the first encounter, destroys the attacks.
Country
Select country
  • Afghanistan
  • Albania
  • Algeria
  • American Samoa
  • Andorra
  • Angola
  • Anguilla
  • Antarctica
  • Antigua and Barbuda
  • Argentina
  • Armenia
  • Aruba
  • Australia
  • Austria
  • Azerbaijan
  • Bahamas (the)
  • Bahrain
  • Bangladesh
  • Barbados
  • Belarus
  • Belgium
  • Belize
  • Benin
  • Bermuda
  • Bhutan
  • Bolivia (Plurinational State of)
  • Bonaire, Sint Eustatius and Saba
  • Bosnia and Herzegovina
  • Botswana
  • Bouvet Island
  • Brazil
  • British Indian Ocean Territory (the)
  • Brunei Darussalam
  • Bulgaria
  • Burkina Faso
  • Burundi
  • Cabo Verde
  • Cambodia
  • Cameroon
  • Canada
  • Cayman Islands (the)
  • Central African Republic (the)
  • Chad
  • Chile
  • China
  • Christmas Island
  • Cocos (Keeling) Islands (the)
  • Colombia
  • Comoros (the)
  • Congo (the Democratic Republic of the)
  • Congo (the)
  • Cook Islands (the)
  • Costa Rica
  • Croatia
  • Cuba
  • Curaçao
  • Cyprus
  • Czechia
  • Côte d'Ivoire
  • Denmark
  • Djibouti
  • Dominica
  • Dominican Republic (the)
  • Ecuador
  • Egypt
  • El Salvador
  • Equatorial Guinea
  • Eritrea
  • Estonia
  • Eswatini
  • Ethiopia
  • Falkland Islands (the) [Malvinas]
  • Faroe Islands (the)
  • Fiji
  • Finland
  • France
  • French Guiana
  • French Polynesia
  • French Southern Territories (the)
  • Gabon
  • Gambia (the)
  • Georgia
  • Germany
  • Ghana
  • Gibraltar
  • Greece
  • Greenland
  • Grenada
  • Guadeloupe
  • Guam
  • Guatemala
  • Guernsey
  • Guinea
  • Guinea-Bissau
  • Guyana
  • Haiti
  • Heard Island and McDonald Islands
  • Holy See (the)
  • Honduras
  • Hong Kong
  • Hungary
  • Iceland
  • India
  • Indonesia
  • Iran (Islamic Republic of)
  • Iraq
  • Ireland
  • Isle of Man
  • Israel
  • Italy
  • Jamaica
  • Japan
  • Jersey
  • Jordan
  • Kazakhstan
  • Kenya
  • Kiribati
  • Korea (the Democratic People's Republic of)
  • Korea (the Republic of)
  • Kuwait
  • Kyrgyzstan
  • Lao People's Democratic Republic (the)
  • Latvia
  • Lebanon
  • Lesotho
  • Liberia
  • Libya
  • Liechtenstein
  • Lithuania
  • Luxembourg
  • Macao
  • Madagascar
  • Malawi
  • Malaysia
  • Maldives
  • Mali
  • Malta
  • Marshall Islands (the)
  • Martinique
  • Mauritania
  • Mauritius
  • Mayotte
  • Mexico
  • Micronesia (Federated States of)
  • Moldova (the Republic of)
  • Monaco
  • Pakistan
  • Mongolia
  • Palestine, State of
  • Montenegro
  • Papua New Guinea
  • Montserrat
  • Peru
  • Morocco
  • Pitcairn
  • Mozambique
  • Portugal
  • Myanmar
  • Qatar
  • Namibia
  • Romania
  • Nauru
  • Rwanda
  • Nepal
  • Saint Barthélemy
  • Netherlands (the)
  • Saint Kitts and Nevis
  • New Caledonia
  • Saint Martin (French part)
  • New Zealand
  • Saint Vincent and the Grenadines
  • Nicaragua
  • San Marino
  • Niger (the)
  • Saudi Arabia
  • Nigeria
  • Serbia
  • Niue
  • Sierra Leone
  • Norfolk Island
  • Sint Maarten (Dutch part)
  • Northern Mariana Islands (the)
  • Slovenia
  • Norway
  • Somalia
  • Oman
  • South Georgia and the South Sandwich Islands
  • Palau
  • Spain
  • Panama
  • Sudan (the)
  • Paraguay
  • Svalbard and Jan Mayen
  • Philippines (the)
  • Switzerland
  • Poland
  • Taiwan
  • Puerto Rico
  • Tanzania, United Republic of
  • Republic of North Macedonia
  • Timor-Leste
  • Russian Federation (the)
  • Tokelau
  • Réunion
  • Trinidad and Tobago
  • Saint Helena, Ascension and Tristan da Cunha
  • Turkey
  • Saint Lucia
  • Turks and Caicos Islands (the)
  • Saint Pierre and Miquelon
  • Uganda
  • Samoa
  • United Arab Emirates (the)
  • Sao Tome and Principe
  • United States Minor Outlying Islands (the)
  • Senegal
  • Uruguay
  • Seychelles
  • Vanuatu
  • Singapore
  • Viet Nam
  • Slovakia
  • Virgin Islands (U.S.)
  • Solomon Islands
  • Western Sahara
  • South Africa
  • Zambia
  • South Sudan
  • Åland Islands
  • Sri Lanka
  • Suriname
  • Sweden
  • Syrian Arab Republic
  • Tajikistan
  • Thailand
  • Togo
  • Tonga
  • Tunisia
  • Turkmenistan
  • Tuvalu
  • Ukraine
  • United Kingdom of Great Britain and Northern Ireland (the)
  • United States of America (the)
  • Uzbekistan
  • Venezuela (Bolivarian Republic of)
  • Virgin Islands (British)
  • Wallis and Futuna
  • Yemen
  • Zimbabwe
Company size
Company size
  • 50 employees or fewer
  • 51 to 250 employees
  • 251 to 500 employees
  • 501 to 1,000 employees
  • 501 to 1,000 employees
  • 1,001 to 5,000 employees
  • More than 5,000 employees
Cyberoon
Cyberoon

Offense is the best defense for your brands

Cyberoon on the first encounter, destroys the attacks.
Gender
Select Gender
  • Male
  • Female
Education level
Select Education Level
  • Bachelor
  • Master
  • Doctoral
Languages
Select Languages
  • English
  • Turkish
  • French
Country
Select Country
  • Afghanistan
  • Albania
  • Algeria
  • American Samoa
  • Andorra
  • Angola
  • Anguilla
  • Antarctica
  • Antigua and Barbuda
  • Argentina
  • Armenia
  • Aruba
  • Australia
  • Austria
  • Azerbaijan
  • Bahamas (the)
  • Bahrain
  • Bangladesh
  • Barbados
  • Belarus
  • Belgium
  • Belize
  • Benin
  • Bermuda
  • Bhutan
  • Bolivia (Plurinational State of)
  • Bonaire, Sint Eustatius and Saba
  • Bosnia and Herzegovina
  • Botswana
  • Bouvet Island
  • Brazil
  • British Indian Ocean Territory (the)
  • Brunei Darussalam
  • Bulgaria
  • Burkina Faso
  • Burundi
  • Cabo Verde
  • Cambodia
  • Cameroon
  • Canada
  • Cayman Islands (the)
  • Central African Republic (the)
  • Chad
  • Chile
  • China
  • Christmas Island
  • Cocos (Keeling) Islands (the)
  • Colombia
  • Comoros (the)
  • Congo (the Democratic Republic of the)
  • Congo (the)
  • Cook Islands (the)
  • Costa Rica
  • Croatia
  • Cuba
  • Curaçao
  • Cyprus
  • Czechia
  • Côte d'Ivoire
  • Denmark
  • Djibouti
  • Dominica
  • Dominican Republic (the)
  • Ecuador
  • Egypt
  • El Salvador
  • Equatorial Guinea
  • Eritrea
  • Estonia
  • Eswatini
  • Ethiopia
  • Falkland Islands (the) [Malvinas]
  • Faroe Islands (the)
  • Fiji
  • Finland
  • France
  • French Guiana
  • French Polynesia
  • French Southern Territories (the)
  • Gabon
  • Gambia (the)
  • Georgia
  • Germany
  • Ghana
  • Gibraltar
  • Greece
  • Greenland
  • Grenada
  • Guadeloupe
  • Guam
  • Guatemala
  • Guernsey
  • Guinea
  • Guinea-Bissau
  • Guyana
  • Haiti
  • Heard Island and McDonald Islands
  • Holy See (the)
  • Honduras
  • Hong Kong
  • Hungary
  • Iceland
  • India
  • Indonesia
  • Iran (Islamic Republic of)
  • Iraq
  • Ireland
  • Isle of Man
  • Israel
  • Italy
  • Jamaica
  • Japan
  • Jersey
  • Jordan
  • Kazakhstan
  • Kenya
  • Kiribati
  • Korea (the Democratic People's Republic of)
  • Korea (the Republic of)
  • Kuwait
  • Kyrgyzstan
  • Lao People's Democratic Republic (the)
  • Latvia
  • Lebanon
  • Lesotho
  • Liberia
  • Libya
  • Liechtenstein
  • Lithuania
  • Luxembourg
  • Macao
  • Madagascar
  • Malawi
  • Malaysia
  • Maldives
  • Mali
  • Malta
  • Marshall Islands (the)
  • Martinique
  • Mauritania
  • Mauritius
  • Mayotte
  • Mexico
  • Micronesia (Federated States of)
  • Moldova (the Republic of)
  • Monaco
  • Pakistan
  • Mongolia
  • Palestine, State of
  • Montenegro
  • Papua New Guinea
  • Montserrat
  • Peru
  • Morocco
  • Pitcairn
  • Mozambique
  • Portugal
  • Myanmar
  • Qatar
  • Namibia
  • Romania
  • Nauru
  • Rwanda
  • Nepal
  • Saint Barthélemy
  • Netherlands (the)
  • Saint Kitts and Nevis
  • New Caledonia
  • Saint Martin (French part)
  • New Zealand
  • Saint Vincent and the Grenadines
  • Nicaragua
  • San Marino
  • Niger (the)
  • Saudi Arabia
  • Nigeria
  • Serbia
  • Niue
  • Sierra Leone
  • Norfolk Island
  • Sint Maarten (Dutch part)
  • Northern Mariana Islands (the)
  • Slovenia
  • Norway
  • Somalia
  • Oman
  • South Georgia and the South Sandwich Islands
  • Palau
  • Spain
  • Panama
  • Sudan (the)
  • Paraguay
  • Svalbard and Jan Mayen
  • Philippines (the)
  • Switzerland
  • Poland
  • Taiwan
  • Puerto Rico
  • Tanzania, United Republic of
  • Republic of North Macedonia
  • Timor-Leste
  • Russian Federation (the)
  • Tokelau
  • Réunion
  • Trinidad and Tobago
  • Saint Helena, Ascension and Tristan da Cunha
  • Turkey
  • Saint Lucia
  • Turks and Caicos Islands (the)
  • Saint Pierre and Miquelon
  • Uganda
  • Samoa
  • United Arab Emirates (the)
  • Sao Tome and Principe
  • United States Minor Outlying Islands (the)
  • Senegal
  • Uruguay
  • Seychelles
  • Vanuatu
  • Singapore
  • Viet Nam
  • Slovakia
  • Virgin Islands (U.S.)
  • Solomon Islands
  • Western Sahara
  • South Africa
  • Zambia
  • South Sudan
  • Åland Islands
  • Sri Lanka
  • Suriname
  • Sweden
  • Syrian Arab Republic
  • Tajikistan
  • Thailand
  • Togo
  • Tonga
  • Tunisia
  • Turkmenistan
  • Tuvalu
  • Ukraine
  • United Kingdom of Great Britain and Northern Ireland (the)
  • United States of America (the)
  • Uzbekistan
  • Venezuela (Bolivarian Republic of)
  • Virgin Islands (British)
  • Wallis and Futuna
  • Yemen
  • Zimbabwe
Blog
Cyberoon blogNews

Apache Struts CVE-2023-50164: Critical Vulnerability Alert & Exploitation Attempts

December 30, 2023

December 30, 2023

On December 7, 2023, Apache issued a security advisory regarding CVE-2023-50164, a critical vulnerability found in Apache Struts, rated with a CVSS score of 9.8. This flaw affected versions ranging from 2.5.0 to 2.5.32 and 6.0.0 to 6.3.0.

Apache Struts, a widely used open-source framework for developing modern Java web applications across various commercial and open-source projects, has historically been targeted by threat actors. Notably, vulnerabilities in Struts, such as the one in the Equifax breach of 2017, raise substantial concerns due to its extensive use across multiple sectors.

Exploiting this vulnerability enables attackers to manipulate file upload parameters, leading to potential path traversal. This manipulation allows malicious file uploads, creating a gateway for remote code execution (RCE).

In recent days, numerous exploitation attempts have been observed, all of which were successfully blocked. The majority of these attempts originated from IP addresses in the United States and France. These exploit attempts primarily utilized automated hacking tools coded in the Go programming language, targeting web applications from the United States, Australia, the Netherlands, and New Zealand.

During exploitation attempts, attackers craft specific requests to upload malicious web shells—often in formats like .JSP or .WAR files—to unintended locations using path traversal techniques, enabling access to areas not originally meant for user uploads.

Despite existing protection measures, it's strongly recommended that customers remain vigilant and promptly update their systems with the latest security patches. Cyberoon continues to monitor the situation and will provide updates as new information becomes available.

CORE COVERAGE
Email & Attachments
Programming
Hosting, Server and Cloud
Category
Security
Network
Threads
AI Security
Cyber Security
Cloud & Server

Stay ahead
of threats.

Subscribe

Stay up to date on the latest industry news and insights. Right in your inbox.

You can unsubscribe at any time. Privacy Policy
share this article
  • Cyberoon social accounts
  • Cyberoon social accounts
  • Cyberoon social accounts
  • Cyberoon social accounts
  • Cyberoon social accounts

Stay ahead
of threats.

Subscribe

Stay up to date on the latest industry news and insights. Right in your inbox.

You can unsubscribe at any time. Privacy Policy

Advantageous Updates for Your Business,
Challenges for Malignant Actors.