Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Imunify360 Vulnerability Could Expose Millions of Sites to Hacking

Imunify360 Vulnerability Could Expose Millions of Sites to Hacking

Posted on November 14, 2025November 14, 2025 By CWS

Imunify360 web site safety merchandise are affected by a critical vulnerability that would expose hundreds of thousands of websites to hacking. 

Imunify360 is designed for Linux-based hosting environments. In accordance with October 2024 information from the seller, Imunify360 had been used to guard 56 million websites.

In accordance with web site safety firm Patchstack, the Imunify360 antivirus is impacted by a flaw that may be exploited to execute arbitrary code and probably absolutely compromise the internet hosting surroundings. An attacker can use a specifically crafted file that triggers the vulnerability when the product scans it. 

The vulnerability was lately patched, however Imunify360 developer Cloud Linux Software program has not assigned a CVE identifier. 

In an advisory printed on November 4, Cloud Linux Software program knowledgeable clients that the Ai-Bolit malware scanner utilized in Imunify360, ImunifyAV+, and ImunifyAV is impacted by a “crucial safety vulnerability”. A patch has been out there since October 21. 

Patchstack reported that details about the flaw has been spreading since late October, however the safety agency can not say whether or not it has been exploited within the wild.

Oliver Sild, co-founder and CEO of Patchstack, advised SecurityWeek that hackers may join shared internet hosting accounts at suppliers that use Imunify360 and deliberately add malware designed to set off the vulnerability. 

Code planted contained in the bait malware file could be executed with the elevated privileges of the malware scanner. Commercial. Scroll to proceed studying.

“Shared hosting servers usually service tons of of websites on the similar time, which must be fastidiously remoted from one another as they belong to completely different clients. For the reason that weak malware scanner runs with root privileges, this might doubtlessly give the attacker entry to all websites within the shared server,” Sild defined.

Patchstack has made public technical particulars and a proof-of-concept (PoC) exploit. The safety agency has suggested internet hosting suppliers to test their programs for indicators of compromise.

Associated: New HTTP Request Smuggling Assaults Impacted CDNs, Main Orgs, Hundreds of thousands of Web sites

Associated: Reflectiz Raises $22 Million for Web site Safety Resolution

Associated: 12 months-Outdated WordPress Plugin Flaws Exploited to Hack Web sites

Security Week News Tags:Expose, Hacking, Imunify360, Millions, Sites, Vulnerability

Post navigation

Previous Post: Critical Imunify360 AV Vulnerability Exposes 56 Million Linux-hosted Websites to RCE Attacks
Next Post: Chinese Hackers Use Anthropic’s AI to Launch Automated Cyber Espionage Campaign

Related Posts

DragonForce Ransomware Hackers Exploiting SimpleHelp Vulnerabilities DragonForce Ransomware Hackers Exploiting SimpleHelp Vulnerabilities Security Week News
OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks Security Week News
US and Allies Sanction Russian Bulletproof Hosting Service Providers US and Allies Sanction Russian Bulletproof Hosting Service Providers Security Week News
Chrome 145 Fixes Critical Browser Vulnerabilities Chrome 145 Fixes Critical Browser Vulnerabilities Security Week News
US Links Handala Hackers to Iranian Government US Links Handala Hackers to Iranian Government Security Week News
Several Code Execution Flaws Patched in Veeam Backup & Replication Several Code Execution Flaws Patched in Veeam Backup & Replication Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Group Star Blizzard Utilizes DarkSword iOS Exploit
  • Secrets Sprawl Expands in 2026: Key Insights for CISOs
  • Urgent Patches Address Critical Grafana Security Flaws
  • Telnyx Python SDK Faces Supply Chain Attack
  • Russian Toolkit Exploits RDP via Malicious LNK Files

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Group Star Blizzard Utilizes DarkSword iOS Exploit
  • Secrets Sprawl Expands in 2026: Key Insights for CISOs
  • Urgent Patches Address Critical Grafana Security Flaws
  • Telnyx Python SDK Faces Supply Chain Attack
  • Russian Toolkit Exploits RDP via Malicious LNK Files

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark