Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Kids ‘picked last in gym class’ prepare for Super Bowl

NBA star Giannis Antetokounmpo joins Calci as an investor

New York state lawmaker proposes three-year moratorium on new data centers

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » RondoDox exploits unpatched XWiki servers to draw more devices into botnet
Identity

RondoDox exploits unpatched XWiki servers to draw more devices into botnet

userBy userNovember 15, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 15, 2025Ravi LakshmananMalware/vulnerabilities

XWiki server

Botnet malware known as RondoDox has been observed targeting unpatched XWiki instances for critical security flaws that could allow attackers to execute arbitrary code.

The vulnerability in question is CVE-2025-24893 (CVSS score: 9.8), which allows a guest user to execute arbitrary remote code via a request to the “/bin/get/Main/SolrSearch” endpoint due to a reputation injection bug. Patched by maintainers of XWiki 15.10.11, 16.4.1, and 16.5.0RC1 in late February 2025.

Although there has been evidence that this flaw has been in the wild since at least March, it wasn’t until late October that VulnCheck revealed that it had observed new attempts to weaponize this flaw as part of a two-step attack chain that deployed cryptocurrency miners.

DFIR retainer service

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) subsequently added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and gave federal agencies until November 20th to apply the required mitigations.

In its latest report released Friday, VulnCheck revealed that exploitation attempts have since spiked, reaching a high on November 7th, before spiking again on November 11th. This is indicative of a broader scanning activity, likely driven by multiple threat actors participating in this effort.

This includes RondoDox, a botnet that is rapidly adding new exploitation vectors to connect susceptible devices to a botnet that uses HTTP, UDP, and TCP protocols to perform distributed denial of service (DDoS) attacks. According to the cybersecurity firm, the first RondoDox exploit was observed on November 3, 2025.

We have also observed attacks exploiting this vulnerability to deliver cryptocurrency miners, as well as other attacks attempting to establish reverse shells and general probing operations using the Nuclei template for CVE-2025-24893.

This finding reiterates the need to employ robust patch management practices to ensure optimal protection.

“CVE-2025-24893 is a familiar story: one attacker moves first, and many others follow,” said Jacob Baines of VulnCheck. “Within days of the initial exploitation, we saw botnets, miners, and opportunistic scanners all exploiting the same vulnerability.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleMedieval Hungarian duke was murdered in a brutal and systematic attack, forensic analysis reveals
Next Article Disney and YouTube TV reach agreement to resolve power outages
user
  • Website

Related Posts

Warning of signal phishing targeting German government agencies, politicians, military personnel and journalists

February 7, 2026

The Legal Revolution is Digital: Meet TwinH, Your AI Partner in the Courtroom of the Future

February 6, 2026

China-linked DKnife AitM framework, routers targeted for traffic hijacking and malware distribution

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Kids ‘picked last in gym class’ prepare for Super Bowl

NBA star Giannis Antetokounmpo joins Calci as an investor

New York state lawmaker proposes three-year moratorium on new data centers

This week’s science news: Anomalies inside Earth, the Artemis II leak and how psychedelics can help treat PTSD

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.