Zero-Day Exploits Used in Craft CMS Attacks, Orange Cyberdefense Warns
158/68 Tuesday, April 29, 2025 The CSIRT team at Orange Cyberdefense has reported that attackers exploited two vulnerabilities—one of them a zero-day—in Craft CMS to compromise servers and steal data. The vulnerabilities, which were actively exploited in the wild, were discovered during an incident response investigation involving a compromised client server. The two flaws include: […]
