Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

JP Morgan doesn’t want to pay Frank founder Charlie Jarvis’ legal costs

Jury claims Apple owes Masimo $634 million for patent infringement

Disney and YouTube TV reach agreement to resolve power outages

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » RondoDox exploits unpatched XWiki servers to draw more devices into botnet
Identity

RondoDox exploits unpatched XWiki servers to draw more devices into botnet

userBy userNovember 15, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 15, 2025Ravi LakshmananMalware/vulnerabilities

XWiki server

Botnet malware known as RondoDox has been observed targeting unpatched XWiki instances for critical security flaws that could allow attackers to execute arbitrary code.

The vulnerability in question is CVE-2025-24893 (CVSS score: 9.8), which allows a guest user to execute arbitrary remote code via a request to the “/bin/get/Main/SolrSearch” endpoint due to a reputation injection bug. Patched by maintainers of XWiki 15.10.11, 16.4.1, and 16.5.0RC1 in late February 2025.

Although there has been evidence that this flaw has been in the wild since at least March, it wasn’t until late October that VulnCheck revealed that it had observed new attempts to weaponize this flaw as part of a two-step attack chain that deployed cryptocurrency miners.

DFIR retainer service

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) subsequently added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and gave federal agencies until November 20th to apply the required mitigations.

In its latest report released Friday, VulnCheck revealed that exploitation attempts have since spiked, reaching a high on November 7th, before spiking again on November 11th. This is indicative of a broader scanning activity, likely driven by multiple threat actors participating in this effort.

This includes RondoDox, a botnet that is rapidly adding new exploitation vectors to connect susceptible devices to a botnet that uses HTTP, UDP, and TCP protocols to perform distributed denial of service (DDoS) attacks. According to the cybersecurity firm, the first RondoDox exploit was observed on November 3, 2025.

We have also observed attacks exploiting this vulnerability to deliver cryptocurrency miners, as well as other attacks attempting to establish reverse shells and general probing operations using the Nuclei template for CVE-2025-24893.

This finding reiterates the need to employ robust patch management practices to ensure optimal protection.

“CVE-2025-24893 is a familiar story: one attacker moves first, and many others follow,” said Jacob Baines of VulnCheck. “Within days of the initial exploitation, we saw botnets, miners, and opportunistic scanners all exploiting the same vulnerability.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleScientists invent a way to create and dye rainbow-colored fabric in the lab using E. coli
Next Article Disney and YouTube TV reach agreement to resolve power outages
user
  • Website

Related Posts

Five Americans plead guilty to helping North Korean IT workers break into 136 companies

November 15, 2025

North Korean hackers turn JSON service into covert malware delivery channel

November 14, 2025

Researchers discover serious AI bug exposing Meta, Nvidia, and Microsoft inference frameworks

November 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

JP Morgan doesn’t want to pay Frank founder Charlie Jarvis’ legal costs

Jury claims Apple owes Masimo $634 million for patent infringement

Disney and YouTube TV reach agreement to resolve power outages

RondoDox exploits unpatched XWiki servers to draw more devices into botnet

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meet Your Digital Twin: Europe’s Cutting-Edge AI is Personalizing Medicine

TwinH: The AI Game-Changer for Faster, More Accessible Legal Services

Immortality is No Longer Science Fiction: TwinH’s AI Breakthrough Could Change Everything

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.