Mmastodon TechnologyCybersecurity first seen 13 h ago, last 13 h ago, peak #12
Jakarta IP flagged for exploiting known CVEs
Original: ๐ต๏ธ ๐๐ฃ ๐ฐ๐ต๐ฒ๐น๐ผ๐ ๐ฑ๐ ๐ท๐ผ๐๐ฟ ๐ต๏ธ **Fiche : "Le Brocanteur de CVEs de Jakarta"** ๐ 103.63.101.24 | AS150273 ๐ฎ๐ฉ ๐ซ 5 frappes : Think
A cybersecurity observer has published a profile of IP address 103.63.101.24, hosted on Indonesian network AS150273 in Jakarta, dubbing it 'the CVE broker of Jakarta'. The address is said to have launched five attacks targeting known flaws in ThinkPHP, PHPUnit's eval-stdin, and Apache path traversal vulnerabilities CVE-2021-41773 and CVE-2021-42013, using the libredtail-http user agent and encoded traversal sequences seeking a shell.
Why now: Security communities regularly share threat intelligence about actively scanning and exploiting IP addresses to help defenders block them.
103.63.101.24AS150273JakartaApacheThinkPHP
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/449136