A new wave of attacks has been detected, leveraging seven exploited flaws identified by CISA. The US Cybersecurity and Infrastructure Security Agency (CISA) has added these vulnerabilities to its list of actively exploited issues, sparking concerns among security experts that attackers are gaining a foothold in networks.
The exploitation is primarily occurring through the use of reverse shells and cryptocurrency miners. Reverse shells are malicious tools used by hackers to gain unauthorized access to targeted systems, while crypto miners are designed to secretly extract valuable cryptocurrencies from compromised devices. These tactics often go undetected for extended periods due to their stealthy nature. The affected flaws include vulnerabilities in widely used software such as Apache Struts and Spring Framework.
The exploitation of these vulnerabilities underscores the ongoing threat posed by attackers who target software weaknesses rather than exploiting user behavior. In essence, attackers are using these vulnerabilities as backdoors into networks. Once inside, they can install more malicious tools or steal sensitive data without being detected. CISA’s added flaws bring the total number of actively exploited vulnerabilities to 19.
The affected organizations range from small businesses to multinational corporations, with various industries impacted by these attacks. The fact that attackers are not targeting specific software but rather a broad set of vulnerabilities suggests that they are casting a wide net in search of vulnerable systems. This approach can result in compromised networks going undetected for extended periods.
Security experts warn that the exploitation of these flaws is not limited to technical vulnerabilities alone, but also involves the misuse of system privileges. The concept of identity exposure refers to the unauthorized access of sensitive information or privileged accounts, which attackers use as an entry point into systems. This highlights the importance of maintaining robust security measures, including limiting user permissions and monitoring for suspicious activity.
To stay ahead of these threats, it is crucial that organizations prioritize patching and software updates, implement strict access controls, and regularly monitor their networks for signs of unauthorized activity. Furthermore, users should be cautious when interacting with potentially malicious emails or attachments, as these can serve as the starting point for a series of attacks exploiting vulnerabilities in network systems.
Source: The Hacker News — 2026-09-03