Wednesday, March 12, 2025

Over 400 IPs Exploiting A number of SSRF Vulnerabilities in Coordinated Cyber Assault

Mar 12, 2025Ravie LakshmananCloud Safety / Vulnerability

Over 400 IPs Exploiting A number of SSRF Vulnerabilities in Coordinated Cyber Assault

Menace intelligence agency GreyNoise is warning of a “coordinated surge” within the exploitation of Server-Facet Request Forgery (SSRF) vulnerabilities spanning a number of platforms.

“A minimum of 400 IPs have been seen actively exploiting a number of SSRF CVEs concurrently, with notable overlap between assault makes an attempt,” the corporate stated, including it noticed the exercise on March 9, 2025.

The international locations which have emerged because the goal of SSRF exploitation makes an attempt embrace america, Germany, Singapore, India, Lithuania, and Japan. One other notable nation is Israel, which has witnessed a surge on March 11, 2025.

Cybersecurity

The checklist of SSRF vulnerabilities being exploited are listed under –

Cybersecurity

GreyNoise stated that lots of the identical IP addresses are focusing on a number of SSRF flaws without delay reasonably than specializing in one specific weak point, noting the sample of exercise suggests structured exploitation, automation, or pre-compromise intelligence gathering.

In gentle of lively exploitation makes an attempt, it is important that customers apply the most recent patches, restrict outbound connections to obligatory endpoints, and monitor for suspicious outbound requests.

“Many fashionable cloud providers depend on inside metadata APIs, which SSRF can entry if exploited,” GreyNoise stated. “SSRF can be utilized to map inside networks, find weak providers, and steal cloud credentials.”

Discovered this text fascinating? Observe us on Twitter and LinkedIn to learn extra unique content material we put up.


Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles