Get a Pentest and security assessment of your IT network.

News

Elasticsearch clusters face attacks from multiple hacker groups

At least six different groups of attackers are looking for and exploiting insecure Elasticsearch deployments to abuse servers. Elasticsearch is a distributed search engine platform written in Java designed for processing large data sets. The exploits affect Elasticsearch 1.4.2 and lower, and the malicious scripts deliver different payloads depending on the actor using them. The attacks leverage CVE-2014-3120 and CVE-2015-1427, both of which are only present in old versions of Elasticsearch and exploit the ability to pass scripts to search queries.”]

Source: https://www.csoonline.com/article/3345959/elasticsearch-clusters-face-attacks-from-multiple-hacker-groups.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months