Get a Pentest and security assessment of your IT network.

Cyber Security

Sodinokibi Ransomware Being Installed on Exploited WebLogic Servers

A deserialization vulnerability (CVE-2019-2725) was discovered in Oracle WebLogic Server that allows attackers to gain full access to the server in order to install malware or use it as a launchpad for further attacks. Oracle released a patch that should be immediately installed so that you become protected. Sodinokibi Ransomware will issue commands to delete shadow volume copies and disable Windows startup repair. When encrypting files, it will utilize a random extension that is unique for each infected machine. When a victim visits the site, they will be shown a page that displays the ransom amount and a bitcoin address.

Source: https://www.bleepingcomputer.com/news/security/sodinokibi-ransomware-being-installed-on-exploited-weblogic-servers/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security