Over 400 IPs Exploiting Multiple SSRF Vulnerabilities in Coordinated Cyber Attack

2 Min Read
2 Min Read

Risk intelligence agency GreyNoise is warning of a “coordinated surge” within the exploitation of Server-Facet Request Forgery (SSRF) vulnerabilities spanning a number of platforms.

“At the least 400 IPs have been seen actively exploiting a number of SSRF CVEs concurrently, with notable overlap between assault makes an attempt,” the corporate stated, including it noticed the exercise on March 9, 2025.

The nations which have emerged because the goal of SSRF exploitation makes an attempt embrace america, Germany, Singapore, India, Lithuania, and Japan. One other notable nation is Israel, which has witnessed a surge on March 11, 2025.

The listing of SSRF vulnerabilities being exploited are listed beneath –

GreyNoise stated that most of the identical IP addresses are concentrating on a number of SSRF flaws without delay slightly than specializing in one specific weak spot, noting the sample of exercise suggests structured exploitation, automation, or pre-compromise intelligence gathering.

In gentle of energetic exploitation makes an attempt, it is important that customers apply the newest patches, restrict outbound connections to obligatory endpoints, and monitor for suspicious outbound requests.

“Many trendy cloud providers depend on inside metadata APIs, which SSRF can entry if exploited,” GreyNoise stated. “SSRF can be utilized to map inside networks, find weak providers, and steal cloud credentials.”

See also  Researchers Expose New Polymorphic Attack That Clones Browser Extensions to Steal Credentials
Share This Article
Leave a comment