/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Attackers are mass-exploiting a vBulletin 5 vulnerability, now patched, allowing remote code execution, after an exploit was anonymously published Monday

Dan Goodin / Ars Technica :

Ars Technica Dan Goodin

Discussion

  • @notdan @notdan on x
    If you're not testing every single company on @Hacker0x01 and @Bugcrowd for this vBulletin 0day RCE, you're missing out on free money. *make sure its in scope tho
  • @x0rz @x0rz on x
    Someone making sure he's the only one capable to exploit the vBulletin vulnerability by patching the code and adding a password to the condition, smart move https://www.bleepingcomputer.com/ ... (misleading title if you ask me)
  • @ilyasu Ilya Sukhar on x
    If you seek intriguing startup opportunities, I think the continued prevalence of vBulletin and phpBB is a good path to explore. https://arstechnica.com/...
  • @campuscodi Catalin Cimpanu on x
    @dangoodin001 More info on what that botnet is doing. Took a while to decipher their code, but there's good coverage on Bleeping. Basically, attackers are hacking vBulletin sites, semi-patching the vulnerable code, and adding a password to run malicious commands https://www.bleep…
  • @campuscodi Catalin Cimpanu on x
    I've also confirmed active exploitation coming from a pretty large botnet with Bad Packets, BinaryEdge, and GreyNoise. Was supposed to write a follow-up piece on all of this, but I see @dangoodin001 covered the attacks and patch already: https://arstechnica.com/...
  • @campuscodi Catalin Cimpanu on x
    Anonymous researcher publishes proof-of-concept code for vBulletin zero-day -zero-day is a pre-auth RCE -impacts vBulletin 5.x only -estimated impact is in the tens of thousands -PoC verified by multiple sources https://www.zdnet.com/... pic.twitter.com/ecsbv2QIyN
  • @campuscodi Catalin Cimpanu on x
    If this guy was smart, he would have sold the zero-day to Zerodium and got $10k for it... Instead, he dumped it on SecLists, out of all places: https://seclists.org/... https://twitter.com/...