Over 400 IPs Exploiting Multiple SSRF Vulnerabilities in Coordinated Cyber Attack

Over 400 IPs Exploiting Multiple SSRF Vulnerabilities in Coordinated Cyber Attack

Mar 12, 2025Ravie LakshmananCloud Safety / Vulnerability

Risk intelligence agency GreyNoise is warning of a “coordinated surge” within the exploitation of Server-Facet Request Forgery (SSRF) vulnerabilities spanning a number of platforms.

“At the very least 400 IPs have been seen actively exploiting a number of SSRF CVEs concurrently, with notable overlap between assault makes an attempt,” the corporate said, including it noticed the exercise on March 9, 2025.

The nations which have emerged because the goal of SSRF exploitation makes an attempt embody america, Germany, Singapore, India, Lithuania, and Japan. One other notable nation is Israel, which has witnessed a surge on March 11, 2025.

Cybersecurity

The checklist of SSRF vulnerabilities being exploited are listed beneath –

Cybersecurity

GreyNoise stated that lots of the similar IP addresses are focusing on a number of SSRF flaws directly somewhat than specializing in one specific weak point, noting the sample of exercise suggests structured exploitation, automation, or pre-compromise intelligence gathering.

In mild of energetic exploitation makes an attempt, it is important that customers apply the newest patches, restrict outbound connections to vital endpoints, and monitor for suspicious outbound requests.

“Many trendy cloud providers depend on inside metadata APIs, which SSRF can entry if exploited,” GreyNoise stated. “SSRF can be utilized to map inside networks, find susceptible providers, and steal cloud credentials.”

Discovered this text fascinating? Comply with us on Twitter and LinkedIn to learn extra unique content material we publish.

Leave a Reply