Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Adobe ColdFusion Servers Targeted in Coordinated Campaign

Adobe ColdFusion Servers Targeted in Coordinated Campaign

Posted on January 2, 2026January 2, 2026 By CWS

A menace actor has been focusing on roughly a dozen vulnerabilities in Adobe ColdFusion as a part of an enormous preliminary entry marketing campaign, GreyNoise warns.

Throughout the Christmas 2025 vacation, the menace intelligence agency noticed hundreds of requests focusing on ColdFusion servers globally, apparently a part of a single, coordinated intrusion effort.

The requests primarily originated from Japan-based infrastructure (related to CTG Server Restricted), with two IP addresses accounting for a lot of the noticed site visitors.

GreyNoise noticed roughly 6,000 requests focusing on ColdFusion vulnerabilities that have been publicly disclosed in 2023 and 2024, with the exercise peaking on December 25.

“The marketing campaign leveraged ProjectDiscovery Interactsh for out-of-band callback verification, with JNDI/LDAP injection as the first assault vector. The deliberate timing throughout Christmas Day (68% of site visitors) suggests intentional focusing on throughout diminished safety monitoring intervals,” GreyNoise notes.

Many of the requests focused servers within the US (4,044), Spain (753), India (128), and Canada, Chile, Germany, and Pakistan (100 every).

The 2 main IP addresses concerned within the Adobe ColdFusion exploitation have been seen working concurrently 41% of the time, sending requests at intervals of 1-5 seconds, to cycle via 11 distinct assault varieties per goal.

GreyNoise’s investigation revealed that the ColdFusion assaults characterize solely a small fraction of the malicious exercise related to the 2 IP addresses.Commercial. Scroll to proceed studying.

Utilized in an enormous exploitation marketing campaign, seemingly operated by an preliminary entry dealer, the IPs have generated over 2.5 million requests focusing on greater than 700 safety defects in dozens of safety stacks, the menace intelligence agency says.

GreyNoise additionally notes that the ISP internet hosting the infrastructure was beforehand concerned in malicious operations resembling phishing and spam.

Working AS152194, the internet hosting supplier is registered in Hong Kong, controls over 200,000 IPv4 addresses, and sure operates with restricted abuse enforcement, GreyNoise notes.

Associated: Shai-Hulud Provide Chain Assault Led to $8.5 Million Belief Pockets Heist

Associated: Fortinet Warns of New Assaults Exploiting Previous Vulnerability

Associated: Recent MongoDB Vulnerability Exploited in Assaults

Associated: Rising Tides: When Cybersecurity Turns into Private – Contained in the Work of an OSINT Investigator

Security Week News Tags:Adobe, Campaign, ColdFusion, Coordinated, Servers, Targeted

Post navigation

Previous Post: Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign
Next Post: Covenant Health Data Breach Impacts 478,000 Individuals

Related Posts

CISA Warns of Exploited Apple, Kentico, Microsoft Vulnerabilities CISA Warns of Exploited Apple, Kentico, Microsoft Vulnerabilities Security Week News
700,000 Records Compromised in Askul Ransomware Attack 700,000 Records Compromised in Askul Ransomware Attack Security Week News
Cisco Firewall Zero-Days Exploited in China-Linked ArcaneDoor Attacks Cisco Firewall Zero-Days Exploited in China-Linked ArcaneDoor Attacks Security Week News
Photo-Stealing Spyware Sneaks Into Apple App Store, Google Play Photo-Stealing Spyware Sneaks Into Apple App Store, Google Play Security Week News
Hackers Earn Over 0,000 on First Day of Pwn2Own Ireland 2025 Hackers Earn Over $520,000 on First Day of Pwn2Own Ireland 2025 Security Week News
In Other News: Iranian Ships Hacked, Verified Android Developers, AI Used in Attacks In Other News: Iranian Ships Hacked, Verified Android Developers, AI Used in Attacks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages
  • DragonForce Ransomware Group’s Expanding Cartel Operations
  • North Korean Hackers Exploit AI for Enhanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages
  • DragonForce Ransomware Group’s Expanding Cartel Operations
  • North Korean Hackers Exploit AI for Enhanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News