Hackers Exploiting Spring4Shell Vulnerability to Deploy Mirai Botnet Malware
Apr 09, 2022
 The recently disclosed critical Spring4Shell  vulnerability is being actively exploited by threat actors to execute the Mirai  botnet malware , particularly in the Singapore region since the start of April 2022.  "The exploitation allows threat actors to download the Mirai sample to the '/tmp' folder and execute them after permission change using 'chmod ,'" Trend Micro researchers Deep Patel, Nitesh Surana, Ashish Verma said  in a report published Friday.  Tracked as CVE-2022-22965  (CVSS score: 9.8), the vulnerability could allow malicious actors to achieve remote code execution in Spring Core applications under non-default circumstances, granting the attackers full control over the compromised devices.   The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) earlier this week added  the Spring4Shell vulnerability to its Known Exploited Vulnerabilities Catalog based on "evidence of active exploitation."   This is ...