Mmastodon TechnologyCybersecurity first seen 8 h ago, last 8 h ago, peak #8
JPCERT/CC updates warning on Japan breach wave
Original: JPCERT/CC updated its warning on Japan's breach wave (Oct 9): - New Case D: WAR files planted on Java app servers reacha
Japan's computer emergency response team JPCERT/CC issued an updated warning on October 9 about an ongoing wave of security breaches in Japan. A newly reported attack pattern involves WAR files planted on Java application servers exposed to the public internet, with a JSP file acting as a web shell that executes commands via a query parameter. The update also added new attacker IP addresses linked to previously reported cases, including one used around October 7.
Why now: Active exploitation of Japanese servers is ongoing and defenders need the new indicators to detect and block attacks.
Evidence
- JPCERT/CC updated its warning on Japan's breach wave (Oct 9): - New Case D: WAR files planted on Java app servers reachable from public web servers; the JSP inside acts as a web shell running commands from a query parameter - New IPs for Case A (one used ~Oct 7) and Case B -… · japancyberwatch@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/1563852