hackers-exploit-critical-craft-cms-flaws;-hundreds-of-servers-likely-compromised

Threat agents have been noted taking advantage of two recently revealed significant security vulnerabilities in Craft CMS in zero-day assaults to infiltrate servers and obtain unauthorized entry.
The assaults, initially detected by Orange Cyberdefense SensePost on February 14, 2025, consist of combining the vulnerabilities listed below –

CVE-2024-58136 (CVSS score: 9.0) – An inadequate safeguarding of alternate path issue in the Yii PHP


Leave a Reply

Your email address will not be published. Required fields are marked *

Share This