Vulnerability Management, Threat Intelligence, Network Security

Multiple SSRF vulnerabilities leveraged in far-reaching coordinated attack

Red glowing word cyberattack on a black wall surrounded by green random letters cybersecurity concept 3D illustration

Attacks exploiting a dozen server-side request forgery vulnerabilities across widely used platforms to target the U.S., Germany, Singapore, India, Japan, and Lithuania have spiked on Sunday, with Israel also experiencing a wave of such intrusions on Tuesday, The Hacker News reports.

Several SSRF flaws — the most severe of which are the critical ColumbiaSoft DocumentLocator, GitLab CE/EE, and Zimbra Collaboration Suite bugs, tracked as CVE-2023-5830, CVE-2021-22175, and CVE-2020-7796, respectively — have been concurrently abused by over 400 IP addresses, according to an investigation from GreyNoise.

Also targeted by the IP addresses were other security issues in VMware vCenter and VMware Workspace ONE UEM, Ivanti Connect Secure, DotNetNuke, OpenBMCS, and BerriAI LiteLLM, indicating threat actors' intent of conducting pre-compromise intelligence collection, automation, or structured exploitation, said GreyNoise researchers.

Organizations and other users have been urged to not only remediate vulnerable software but also restrict outbound connections and remain vigilant on atypical outbound requests.

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds