Rewterz

Rewterz Threat Alert – Masad Stealer

October 8, 2019
Rewterz

Rewterz Threat Alert – Lazarus – IOC’s

October 8, 2019

Rewterz Threat Advisory – Zero-day for old Joomla CMS versions

Severity

Medium

Analysis Summary

A vulnerability in older versions of the Joomla content management system (CMS), a popular web-based application for building and managing websites.

It’s a PHP object injection that can lead to remote code execution (RCE) under certain scenarios. For example, it can be exploited via the Joomla CMS’ login form and can allow attackers to execute code on the site’s underlying server.

The vulnerability is trivial to exploit, and proof-of-concept exploit code has been published online.

Impact

Remote code execution

Affected Vendors

Joomla

Affected Products

Joomla content management system (CMS) from versions 3.0.0 to 3.4.6.

Remediation

Update to version of 3.4.7 or later.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.