Federal Agency Hacked Through Critical GeoServer Flaw Despite Available Patch
A U.S. federal agency was breached through an unpatched GeoServer vulnerability (CVE-2024-36401) that allowed remote code execution. Attackers gained initial access on July 11, 2024, deployed web shells and malware, performed lateral movement to compromise additional servers, and used brut...
