Security Stuff

MetInfo, Weaver E-cology Vulnerabilities in Attackers’ Crosshairs


Listen Later

Attackers are actively exploiting two critical vulnerabilities in enterprise software widely used in China. The first flaw in MetInfo, a content management system, allows remote code execution through unauthenticated PHP code injection, with exploitation surging over the weekend primarily targeting servers in Singapore. Separately, threat actors are exploiting a vulnerability in Weaver E-cology, an office automation platform, using exposed debug functionality as a persistent shell to execute arbitrary commands without needing authentication.
...more
View all episodesView all episodes
Download on the App Store

Security StuffBy David