Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

US federal agency breached by hackers using GeoServer exploit, CISA says

Tech Wavo by Tech Wavo
September 24, 2025
in Computers
0




  • Attackers exploited a critical GeoServer flaw to breach a US federal agency in July 2024
  • China Chopper web shell enabled remote access and lateral movement across compromised systems
  • CISA urges timely patching, tested response plans, and continuous alert monitoring

In mid-July 2024, a threat actor managed to break into a US Federal Civilian Executive Branch (FCEB) agency by exploiting a critical remote code execution (RCE) vulnerability in GeoServer, the government has confirmed.

In an in-depth report detailing the incident, the US Cybersecurity and Infrastructure Security Agency (CISA) outlined how the attackers leveraged CVE-2024-36401, a 9.8/10 vulnerability that granted RCE capabilities through specially crafted input against a default GeoServer installation.

GeoServer is an open source server platform that enables users to share, edit, and publish geospatial data using open standards.


You may like

Lessons learned

The vulnerability was disclosed on June 30, and added to CISA’s Known Exploited Vulnerabilities (KEV) catalog by July 15, but by that time, it was already too late since the miscreants established persistence on compromised endpoints.

The damage could have been reduced with timely patching, though, as a second GeoServer instance was breached on July 24.

Once inside, the attackers conducted extensive reconnaissance using tools like Burp Suite, fscan, and linux-exploit-suggester2.pl.

They moved laterally across the network, compromising a web server and an SQL server, and deploying web shells on each system.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Among them was China Chopper, a lightweight web shell used for remote access and control over compromised servers. Once installed, it allows attackers to execute commands, upload files, and pivot within networks.

CISA did not attribute this attack to any known threat actor, but from previously reported incidents it is known that China Chopper is widely used by advanced persistent threat (APT) groups, particularly those linked to Chinese state-sponsored operations such as APT41.

The goal of CISA’s report was to share lessons learned from the incident, and apparently those lessons are: patch your systems on time, make sure to have an incident response plan (and test/exercise it!), and continuously review alerts.

Via BleepingComputer

You might also like

Previous Post

Step into the future: The full AI Stage at Disrupt 2025

Next Post

Emergent raises $23M from Lightspeed to let consumers build apps

Next Post
Emergent raises $23M from Lightspeed to let consumers build apps

Emergent raises $23M from Lightspeed to let consumers build apps

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Best Backpacking Stove (2025): MSR, Jetboil, Firebox

by Tech Wavo
September 24, 2025
0
Best Backpacking Stove (2025): MSR, Jetboil, Firebox
Computers

Top 6 Backpacking Stoves ComparedHonorable MentionsThere are a ton of tiny stoves out there. Here are a couple of stoves...

Read more

Kevin Rose on Digg, reinvention, and startup investing

by Tech Wavo
September 24, 2025
0
Kevin Rose on Digg, reinvention, and startup investing
Computers

Kevin Rose last spoke at Disrupt in 2012, when Digg was in the middle of one of tech’s most talked-about...

Read more

Libraseva urges users to patch now as it issues emergency fix following attacks

by Tech Wavo
September 24, 2025
0
Emails are getting a fresh look thanks to the European Accessibility Act
Computers

Libraesva patched CVE-2025-59689, a medium-severity remote command execution vulnerabilityAttack exploited compressed email attachments; threat actor likely a hostile foreign stateVersions...

Read more

Google’s AI Search Live is now available to all US app users

by Tech Wavo
September 24, 2025
0
Google faces its first AI Overviews lawsuit from a major US publisher
Computers

Search Live is now available for Google app users in the US, offering real-time, multimodal search, powered by AI. This...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock