vulnerability GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE A newly discovered zero-day SQL injection vulnerability in GeoServer is currently being actively exploited. The vulnerability, which has been assigned a GitHub security advisory identifier (GHSA-mqjf-5f49-2fjh), allows for remote code execution and has been observed with hundreds of exploitation attempts originating fr… The Hacker News · Aug 13, 2026 Critical CVE-2024-36401CVE-2023-25158CVE-2023-25157sql injectionzero-dayremote code execution
threat-intel Rondo Meets Geoserver, (Wed, Jul 22nd) A Rondo botnet attack targeting Geoserver, a geographic information system tool, is being observed. The attack leverages a vulnerability (CVE-2024-36401) to execute arbitrary shell commands, delivering a Rondo payload. T… SANS Internet Storm Center · Jul 22, 2026 Medium CVE-2024-36401vulnerabilitybotnetgeoserver
malware New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks A new cyberattack campaign, dubbed StrikeShark, is utilizing a previously undocumented malware family called SharkLoader to deploy Cobalt Strike Beacon. The campaign has targeted diplomatic organizations in Indonesia and… The Hacker News · Jun 26, 2026 High CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikedll hijackingexploit
threat-intel StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader A new malware family, named SharkLoader, has been identified as part of a broader campaign targeting organizations globally, including diplomatic entities, government organizations, and software development companies. Th… Securelist · Jun 24, 2026 Medium CVE-2021-26855CVE-2023-32315CVE-2024-36401IDTWHKcobalt strikeexploitloader