Skip to main content
institutional access

You are connecting from
Lake Geneva Public Library,
please login or register to take advantage of your institution's Ground News Plan.

Published loading...Updated

Hackers exploited Sitecore zero-day flaw to deploy backdoors

Threat actors exploit a ViewState deserialization flaw in legacy Sitecore deployments to deploy reconnaissance malware and escalate privileges, urging immediate key rotation and patching.

Summary by BleepingComputer
Threat actors have been exploiting a zero-day vulnerability in legacy Sitecore deployments to deploy WeepSteel reconnaissance malware.

7 Articles

Cybersecurity DiveCybersecurity Dive
Reposted by
IT Security News - cybersecurity, infosecurity newsIT Security News - cybersecurity, infosecurity news
Center

Researchers warn of zero-day vulnerability in SiteCore products

Mandiant said it was able to disarm a ViewState deserialization attack leveraging exposed ASP.NET keys.

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality 

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

GBHackers On Security broke the news in on Thursday, September 4, 2025.
Sources are mostly out of (0)

Similar News Topics

News
For You
Search
BlindspotLocal